---
title: "Infoblox Cloud Playbooks"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDwDDICortexXSOAR/1813315623/Infoblox%20Cloud%20Playbooks"
format: markdown
---
The **Infoblox Cloud Playbooks** enable automated enrichment, response, and threat mitigation actions across DNS, DDI, and Threat Intelligence integrations in **Palo Alto Cortex XSOAR**.

Each playbook leverages Infoblox APIs to retrieve contextual data, enrich incidents, or take response actions

# Available Playbooks

| **Playbook Name** | **Trigger / Behavior Description** |
| --- | --- |
| **Incident Response – Infoblox Cloud**  
[https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/edit-v2/1743913670#Incident-Response-%E2%80%93-Infoblox-Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/edit-v2/1743913670#Incident-Response-%E2%80%93-Infoblox-Cloud) | Automatically triggered for **SOC Insight incidents**. Runs when a new incident is created, changes the state from *Pending* to *Active*, retrieves indicators, events, assets, and comments from Infoblox. If severity is *Medium* or higher, it creates a ServiceNow ticket; otherwise, the case is assigned to an analyst. |
| **Indicator Enrichment – Infoblox Cloud**  
[https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#Indicator-Enrichment-%E2%80%93-Infoblox-Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#Indicator-Enrichment-%E2%80%93-Infoblox-Cloud) | Runs automatically and consumes indicators from the associated incident. Enriches IPs, MACs, domains, and URLs using **Dossier**, **TIDE**, **DHCP lease**, and **asset data** from Infoblox Threat Defense with DDI. |
| **Domain Enrichment – Infoblox Cloud**  
[https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#Domain-Enrichment-%E2%80%93-Infoblox-Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#Domain-Enrichment-%E2%80%93-Infoblox-Cloud) | Automatically triggered when domain indicators are present in an incident. Uses Infoblox **Dossier**, **TIDE**, and asset data for enrichment. |
| **IP Enrichment – Infoblox Cloud**  
[https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#IP-Enrichment-%E2%80%93-Infoblox-Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#IP-Enrichment-%E2%80%93-Infoblox-Cloud) | Automatically triggered when IP indicators are found in an incident. Enriches IPs with **Dossier**, **TIDE**, and **asset data** from Infoblox. |
| **URL Enrichment – Infoblox Cloud**  
[https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#URL-Enrichment-%E2%80%93-Infoblox-Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#URL-Enrichment-%E2%80%93-Infoblox-Cloud) | Automatically runs when URL indicators are included in an incident. Fetches threat category, risk score, and DNS/IP associations using Infoblox Threat Defense with DDI. |
| **MAC Enrichment – Infoblox Cloud**  
[https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#MAC-Enrichment-%E2%80%93-Infoblox-Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#MAC-Enrichment-%E2%80%93-Infoblox-Cloud) | Requires manual execution or predefined MAC input. Enriches MAC addresses with **DHCP lease** and asset information using Infoblox Threat Defense with DDI. |
| **Block Indicator – Infoblox Cloud**  
[https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#Block-Indicator-%E2%80%93-Infoblox-Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#Block-Indicator-%E2%80%93-Infoblox-Cloud) | Requires manual input or predefined parameters. Blocks the given IP or domain by adding it to the configured **block-type custom list** in Infoblox Cloud and removes it from the allow list if necessary. |
| **Unblock Indicator – Infoblox Cloud**  
[https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#Unblock-Indicator-%E2%80%93-Infoblox-Cloud](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDICortexXSOAR/pages/1814528014/Playbook+Inputs+Infoblox+Threat+Defense+with+DDI#Unblock-Indicator-%E2%80%93-Infoblox-Cloud) | Requires manual input or predefined parameters. Unblocks the given IP or domain by adding it to the **allow-type custom list**, restoring access or reversing a previous block. |

> ℹ️ - The **Incident Response** playbook is automatically triggered for **SOC Insight incidents**.
> ℹ️ - All **enrichment-based playbooks** (except **MAC Enrichment**) run automatically and consume indicators from the incident in which they are used.
> ℹ️ - All other playbooks require **manual execution** or rely on **predefined input parameters** configured within the playbook.