---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up the playbook

# Set up the Spoofed Emails playbook {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Use the following steps to set up the Spoofed Emails playbook.

## Antes de Iniciar

Role required:

* sn_si.admin
* flow_designer
{#playbook-setup-spoofed-emails__ul_ub3_m35_xzb}

Make sure you have installed Security Operations Spoke (sn_sec_spoke).

## Procedimento

1. Login as a user with sn_si.user and flow_designer roles.
2. Navigate to AllFlow Designer and select the Spoofed Emails (using the same Display name) playbook.
3. **Opcional:** You can create a copy of the Repeat Detection playbook flow and make the necessary modifications.  
   To create a copy of the playbook's flow, click the ![More actions menu]() icon and select Copy flow. Perform this step only if you plan to customize or make specific changes to the flow.  
   Figura 1. Spoofed Emails playbook
4. Activate the playbooks.  
   * Activate the main flow to use the playbook available in the base system.
   * Activate the copied flows after making the required changes.
   {#playbook-setup-spoofed-emails__ul_qps_ktw_fzb}
5. Set a Trigger Condition for the playbook.  
   This playbook is triggered and associated with the security incident when the Category is Phishing.


