---
title: "Invoking Playbooks in Cortex XSOAR"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDwDDICortexXSOAR/1813807133/Invoking%20Playbooks%20in%20Cortex%20XSOAR"
format: markdown
---
Playbooks in Cortex XSOAR help automate investigation, enrichment, and response workflows.  
For Infoblox integrations such as **Threat Defense with DDI**, playbooks can be triggered automatically (based on incidents) or invoked manually during investigation.

# Steps to Invoke a Playbook Manually

Follow the steps below to run any Infoblox playbook (for example, *Block Indicator – DNS Security* or *Incident Response – Infoblox Cloud*).

### Step 1: Navigate to Incidents

1. From the Cortex XSOAR navigation pane, click **Incidents**.
2. Select the incident you want to investigate.

*This will open the detailed incident view.*

### Step 2: Open the  Work Plan

1. Inside the incident, select the **Work Plan** tab.
2. The Work Plan displays the automation and playbooks associated with the current incident.

### Step 3: Search for a Playbook

1. At the top of the Work Plan view, click the **Playbook Search Bar**.
2. Type the desired playbook name — for example:
  - `Block Indicator – Infoblox Cloud`
  - `Incident Response – Infoblox Cloud`
  - `Indicator Enrichment – Infoblox Cloud`
3. Select the playbook from the dropdown list.

### Step 4: Initiate the Playbook

1. Once selected, click **Playbook Triggered** to start execution.
2. Depending on the playbook type:
  - **Automatic Playbooks** (e.g., *Incident Response*, *Indicator Enrichment*) will immediately consume indicators or incidents.
  - **Manual Playbooks** (e.g., *Block Indicator*, *Unblock Indicator*) will prompt for parameters such as IP address, domain, or list type.

*Ensure that all mandatory input fields (like Service API Key or Indicator values) are provided.*

### Step 5: Monitor Execution Flow

- The playbook flowchart will appear on the right panel showing tasks, scripts, and conditional logic.
- Each node displays:
  - **Green:** Task executed successfully.
  - **Yellow:** Task in progress.
  - **Red:** Error or input required.

 *You can click each node to view script logs or outputs for validation.*

![Block_Indicator_-_Infoblox_Cloud_Wed_Oct_22_2025.png](media://a2061291-4413-43c1-80b0-4a6293812d8c)