Fix 1 of 2
Automate enrichment and routine responses with playbooks
Playbooks look up IPs, domains and users, check reported phishing emails and close obvious false positives before an analyst sees them.
- 1Pick the alert type that eats the most time, often reported phishing.
- 2Build a playbook in Tines, Torq, Microsoft Sentinel or Google SecOps: enrich, check sandboxes and reputation, decide.
- 3Have it auto-close clear false positives, quarantine clear phish across mailboxes, and reply to the reporter.
- 4Send only unclear cases to an analyst with the evidence attached.
Tools: Tines · Torq · Microsoft Sentinel playbooks · Google SecOps · Microsoft Defender for Office 365 automated investigation