---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Activate the Threat Hunting Playbook

# Activate the Threat Hunting Playbook {#ariaid-title1}

* Release version: Australia
* 
* Updated May 20, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

By default, the Threat Hunting playbook is deactivated. Activate it in Workflow Studio to initiate the playbook automatically for the applicable Case records.

## Before you begin

Role required: admin

## About this task

Activate the playbook to initiate it for the applicable Case records.

## Procedure

1. Navigate to AllWorkflow Studio.
2. In Playbooks, open the Threat Hunting playbook.
3. **Optional:** To test run the playbook, select Test and enter a case record.
4. Select Activate.
**Related concepts**   

* [Threat Hunting Playbook](https://servicenow-prod.fluidtopics.net/GtI0yd~gKqu7478zSss2aQ "The Threat Hunting playbook is a guided workflow for a TISC Case record that helps analysts move a threat hunt from an initial hypothesis to a final outcome.")  
**Related tasks**   

* [Use the Threat Hunting Playbook](https://servicenow-prod.fluidtopics.net/n2yAquNl9roiQ0pbDZmnNg "Run threat hunt on a Case record — from capturing the hunt hypothesis through to creating a Security incident or reporting.")

*[\>]: and then


