Use the following steps to set up the Spoofed Emails playbook.
Before you begin
Role required:
- sn_si.admin
- flow_designer
Make sure you have installed Security Operations Spoke (sn_sec_spoke).
Procedure
-
Login as a user with sn_si.user and flow_designer roles.
-
Navigate to and select the Spoofed Emails (using the same Display name) playbook.
- Optional:
You can create a copy of the Repeat Detection playbook flow and make the necessary modifications.
To create a copy of the playbook's flow, select the

icon and select
Copy flow. Perform this step only if you plan to customize or make specific changes to the flow.
-
Activate the playbooks.
- Activate the main flow to use the playbook available in the base system.
- Activate the copied flows after making the required changes.
-
Set a Trigger Condition for the playbook.
This playbook is triggered and associated with the security incident when the Category is Phishing.