---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Playbook for Automated Phishing

# Playbook for Automated Phishing {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Automated Phishing playbook helps you resolve certain types of security
threats in a step-by-step manner. With the flow designer templates, you can automate
the steps in the phishing response playbook and resolve incidents quickly and
efficiently.

You can use templates authored with flow designer to automate the tasks in the
[Phishing Response
Playbook](https://servicenow-prod.fluidtopics.net/B1Y~oT8n4QdXCgnQXK7UXw#use-the-playbook "Use the Playbook to resolve certain types of security threats in a step-by-step manner. For example, you can resolve phishing attacks and threats caused by malicious code activity using playbooks.") to analyze and resolve phishing attacks in your
organization.  
The phishing response playbook includes the following flows and subflows:

* Security Incident - Automated Phishing Response Template: This template is designed to automate the phishing response tasks and contains a sequence of actions including a trigger.
* Security Incident - Phishing Manual Template: This template is the existing manual phishing response workflow. Set the category to Phishing to activate the flow.
{#flow-designer-and-phishing-response__ul_k4y_smk_tgb}  
These templates contain a sequence of reusable actions designed to respond to phishing attacks. Each flow has a trigger (condition), a sequence of actions and subflows that you can annotate for readability. To access these flows, you must install the [Security Operations spoke](https://www.servicenow.com/docs/access?context=secops-spoke&version=australia&pubname=australia-build-workflows&ft:locale=en-US).  
Note:  
Activate these templates before you can use them. See [Activate a Security Incident Response flow](https://servicenow-prod.fluidtopics.net/zd8dhEwVzoxKo5rJ_GDPIg "Security administrators and flow designers can use the Security Incident Response flows to automate the process of resolving security incidents in the organization.") for details.

* Run Threat Lookups for Observables: Performs threat lookups of selected observables.
* Enrich Observables: Allows you to enrich observables with additional information from various sources.
* Assess Phishing Email Impact: Allows you to assess the impact of the phishing email. When you receive an email at the phishing email address, this subflow parses the .EML attachment and compares the information to the email matching rules.
* Eradicate Phishing Emails: Allows you to delete or eradicate phishing emails to help reduce exposure to a specific attack.
* Run Sighting Search on Observables: Determines the prevalence of a threat over time or test remediation or eradication efforts.
* Create Block Requests: Blocks communication with observables associated with the incident.

{#flow-designer-and-phishing-response__ul_e5q_jk1_5gb}

These subflows represent a set of reusable operations that you can use in
multiple playbooks. You can use these subflows to define custom templates
(flows) according to your requirements.

To create custom templates (flows), follow the instructions in [Flows](https://www.servicenow.com/docs/access?context=flows&version=australia&pubname=australia-build-workflows&ft:locale=en-US).
* **[Run the automated phishing response playbook flow](https://servicenow-prod.fluidtopics.net/MGxLbH0RZWBvMxfLOTg7zQ)**   
  Using the flow designer, you can define and automate tasks in the playbook to analyze and resolve phishing attacks against your organization.

