---
title: "Infoblox NIOS Playbook"
canonical: "https://docs.infoblox.com/space/DeploymentGuideNIOSDDIforCortexXSOAR/1878884371/Infoblox%20NIOS%20Playbook"
format: markdown
---
Each playbook automates a specific workflow using **Infoblox NIOS** APIs for DNS, DHCP, and IPAM operations.

| **Playbook Name** | **Trigger / Behavior Description** |
| --- | --- |
| **Block Indicator – Infoblox NIOS** | Blocks a malicious IP or domain by creating or updating RPZ rules in Infoblox NIOS. Typically used for DNS-based threat containment or security automation. |
| **Unblock Indicator – Infoblox NIOS** | Removes previously blocked IPs or domains from RPZ zones, restoring resolution. Often used for false-positive corrections or post-incident recovery. |
| **IP Lookup – Infoblox NIOS** | Retrieves detailed IP information (host associations, leases, and network context) from Infoblox IPAM. Useful for SOC investigations and enrichment. |
| **Host Lookup – Infoblox NIOS** | Fetches DNS host information and associated IPs (A/AAAA records). Enables analysts to validate host resolution and ownership. |
| **MAC Lease Lookup – Infoblox NIOS** | Retrieves DHCP lease data for a given MAC address. Helps identify connected devices or trace endpoint activity. |
| **Bring Back Asset Data – Infoblox NIOS** | Creates host records in Infoblox NIOS using asset information. Commonly used in asset onboarding, discovery, or reconciliation workflows. |