🌙

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

Network Proactive Response Example Playbook

managedxdr

Important

When configuring playbooks for Proactive Response, the playbook name must match the trigger name and follow the Proactive Response Naming Convention.

NDR IP Blocking and IP Block Removal Playbook Configurations

Note

When IP blocks (shuns) are applied to NDR Devices as a Proactive Response Action, the block is deployed to all of the tenant’s healthy NDR Devices. To remove an IP block, clients can leverage the NDR Unblock playbook and target the relevant NDR Device(s).

  1. Configure an NDR Block playbook for the IP Block action using the trigger parameters shown below. For more information about adding a new playbook, see Create a New Playbook.

Note

The NDR Block playbook does not have actions listed in the dropdown, it must be executed manually.

Playbook for deploying IP blocks to the NDR Device

Playbook for deploying IP blocks to the NDR Device

Note

Each playbook has built-in documentation that walks through the steps to create a new playbook. Select Documentation from a playbook template or configured playbook in XDR to open this in a new tab and follow the guidance there.

  1. Configure an NDR Unblock playbook for the IP Block Removal action using the trigger parameters shown below. For more information about adding a new playbook, see Create a New Playbook.

Note

The NDR Unblock playbook does not have actions listed in the dropdown, it must be executed manually.

Playbook for removing IP blocks from the NDR Device

Playbook for removing IP blocks from the NDR Device

Note

Each playbook has built-in documentation that walks through the steps to create a new playbook. Select Documentation from a playbook template or configured playbook in XDR to open this in a new tab and follow the guidance there.

 

On this page: