Configure Enrichment and Mitigation Playbooks
Playbooks in FortiSOAR allow you to automate security processes across external systems while aligning with your organization's business processes. You can customize the included playbooks to match your organization's procedures and take advantage of FortiSOAR's automation capabilities.
The SOAR Framework Solution Pack includes extraction and enrichment playbooks that are automatically triggered on indicator creation. Ensure that you configure the required threat intelligence integrations such as VirusTotal and IBM X-Force, for automatic enrichment. Similarly, the SOAR Solution pack also contains mitigation playbooks that should be configured to mitigate threats, such as blocking specific types of indicators, disabling specific users, and isolating hosts, based on your containment strategies.