---
title: "Playbooks"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDwDDIforSplunkSOAR/1688600686/Playbooks"
format: markdown
---
As part of this integration we have designed the following playbooks:

1. Block Indicators
  - Automates adding domains or IPs to Infoblox default block lists.
  - Ensures policy consistency by removing them from allow lists.
2. Unblock Indicators
  - Automates adding domains or IPs to Infoblox default allow lists.
  - Ensures policy consistency by removing them from block lists.
3. IP Lookup
  - Enriches IP addresses with Infoblox threat intelligence and asset data for rapid security analysis.
4. Host Lookup
  - Provides detailed host enrichment using Infoblox threat intelligence and asset information.
5. URL Lookup
  - Performs deep context gathering and threat assessment for URLs using Infoblox Dossier and TIDE APIs.
6. MAC Lease Lookup
  - Retrieves MAC lease information from Infoblox to add network context to security incidents.
7. Vulnerability Management Scan
  - Triggers vulnerability scans based on security events enriched with Infoblox data.
  - Adds a note in the event if the threat level > 80.
8. Incident Response
  - Automates SOC workflows with severity-based notifications and ServiceNow ticket creation.
  - If threat level is low, updates the event severity in SOAR accordingly.