---
title: "Playbooks"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDDDI4GoogleSecOpsSOAR/1582203050/Playbooks"
format: markdown
---
As part of the Infoblox Threat Defense with DDI Integration, we created **eight **playbooks to help you get started. Users can use and refer to the sample playbook provided in [https://github.com/infobloxopen/infoblox_google_secops](https://github.com/infobloxopen/infoblox_google_secops) 

The Playbooks included are:

1. Block Indicators
2. Unblock Indicators
3. Vulnerability Management Scan
4. IP Lookup
5. Host Lookup
6. URL Lookup
7. MAC Lease Lookup

*Note*

- *.zip file for every playbook contains the playbook along with all the blocks used in that playbook.*
- *Each playbook requires a trigger, which decides when the playbook would be run. For some of the playbooks created, the Trigger is set as All. Users can update the Trigger conditions based on the requirements.*
- *As the trigger of every playbook is set to run on all ingested alerts into SecOps instance, the imported playbooks are disabled by default. User can easily enable any playbook by simply clicking on the toggle button beside the playbook name. (**[Reference](https://cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/whats-on-the-playbooks-screen#:~:text=At%20the%20top%20segment%20of%20the%20playbook%20designer%20pane%2C%20you%20can%20use%20the%20horizontal%20toggling%20button%20to%20enable%20or%20disable%20the%20playbook.)**)*