This playbook enables the ArcSight SOAR platform to query the reputation of a domain using the APIVoid integration. It is particularly useful when a domain is identified in a security event (e.g., phishing email, C2 callback, suspicious redirection) but lacks contextual reputation data.
The workflow includes a human validation step before triggering enrichment from APIVoid and helps the SOC team decide whether to investigate further or close the case. This reduces false positives while maintaining rapid response capability.
This playbook enables the ArcSight SOAR platform to query the reputation of a domain using the APIVoid integration. It is particularly useful when a domain is identified in a security event (e.g., phishing email, C2 callback, suspicious redirection) but lacks contextual reputation data.
The workflow includes a human validation step before triggering enrichment from APIVoid and helps the SOC team decide whether to investigate further or close the case. This reduces false positives while maintaining rapid response capability.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox