Playbook for Repeat Detection
This playbook helps you determine if the incident response has been provided on an exact or similar phishing report in the past and automatically works on the new report similarly.
The Repeat Detection playbook checks if the newly reported phishing incident resembles a past incident. When the repeat detection is identified, the matched security incident and the resolution details are provided to the analyst, who can use it on the newly reported incident, resulting in a quick remediation of the security incident.
- Set up the Repeat Detection playbook
Use the following steps to set up the Repeat Detection playbook. - Use the Repeat Detection playbook
Use this playbook to investigate if the incident response has been provided on an exact or similar phishing report in the past and automatically works on the new report similarly. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Repeat Detection playbook.
Parent Topic:Flow-based Playbooks