This playbook enables SOC teams to enrich, assess, and block potentially malicious IP addresses using AbuseIPDB and Checkpoint Firewall integrations. It automates enrichment for the flagged IP, requests analyst confirmation for blocking, and executes the block if approved — while maintaining complete case tracking in ArcSight SOAR.
This workflow supports semi-automated decision-making, where human validation is key to avoid false positives while retaining the power of automation for rapid containment.
This playbook enables SOC teams to enrich, assess, and block potentially malicious IP addresses using AbuseIPDB and Checkpoint Firewall integrations. It automates enrichment for the flagged IP, requests analyst confirmation for blocking, and executes the block if approved — while maintaining complete case tracking in ArcSight SOAR.
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox