---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Using playbooks

# Using playbooks {#ariaid-title1}

* Release version: Australia
* 
* Updated June 5, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Using Playbooks

Playbooks in Threat Intelligence Security Center (TISC) provide structured guidance to analysts for conducting threat investigations through defined stages.
Each stage includes specific activities that must be completed before advancing to the next phase.
When a Case record with the appropriate type and status is created, the relevant playbook starts automatically and is accessible under the Playbooks tab within the Case record.
Show full answer Show less  

## How Playbooks Work

* Playbooks progress through a fixed sequence of stages, each containing activities such as data entry, task completion, or approvals.
* All required activities in a stage must be finished before the case owner can advance to the next stage.
* The Playbooks tab displays the current stage, pending activities, and overall progress, marking completed stages for easy tracking.
* The Threat Hunting playbook runs once per Case and cannot be rerun unless the execution was cancelled and manually re-added by the case owner or administrator.
* At the final stage, analysts typically create a security incident or generate a report to document outcomes, which requires create access on the Security Incident table.

## Analyst Roles and Contributions

* Any analyst with access to the Case can view playbook details and contribute by recording findings, linking entities, selecting MITRE ATT\&CK techniques, and completing tasks.
* Only the case owner (assigned user) can make stage transitions and approval decisions.
* Analysts who are not case owners should complete their assigned activities and notify the case owner when ready to progress.

## Monitoring and Managing Playbooks

* The Playbook card in the right-side context menu allows monitoring of the current stage and provides an option to cancel the playbook if necessary.
* Work notes on the Case record track key playbook events including start, stage transitions, and completion.
* Cancelled playbooks can be re-added manually by the case owner or administrators.

## Threat Hunting Playbook

The Threat Hunting playbook is a guided workflow designed to assist analysts in progressing a threat hunt from an initial hypothesis through to a final outcome within a TISC Case record.

## Practical Benefits for ServiceNow Customers

* Enables structured, repeatable threat investigation workflows to improve consistency and efficiency.
* Facilitates collaboration among analysts by tracking contributions and assigning clear responsibilities.
* Helps ensure thorough case documentation and compliant incident creation at the conclusion of investigations.
* Provides visibility and control over playbook status and progression directly within the Case record interface.  
Playbooks in Threat Intelligence Security Center guide analysts through structured threat investigation stages. Each stage defines the actions to complete before the case advances to the next phase of the response process.

When a Case record is created in Threat Intelligence Security Center with the appropriate Case type and status, a playbook starts automatically. The playbook appears in the Playbooks tab of the Case record and
shows the current stage, pending activities, and overall progress. The Threat Hunting playbook runs once per Case. After the playbook reaches completion, you can't run it on the same Case. You can add the playbook again for
cancelled executions.{#tisc-playbooks-analyst__tisc-playbooks-analyst-p-1}

## How stages work {#tisc-playbooks-analyst__tisc-playbooks-analyst-section-stages}

A playbook moves through a fixed sequence of stages. Each stage contains activities --- such as entering data, completing tasks, or waiting for an approval. You must complete all required activities in a stage before the case owner can advance the playbook to the next stage.{#tisc-playbooks-analyst__tisc-playbooks-analyst-p-2}

The Playbooks tab shows which stage is active and what activities remain. The playbook marks completed stages so you can track progress at a glance.{#tisc-playbooks-analyst__tisc-playbooks-analyst-p-3}

## Analyst contributions {#tisc-playbooks-analyst__tisc-playbooks-analyst-section-contributions}

Any analyst with access to a Case record can read playbook details and contribute information at each stage. Typical analyst activities include recording findings, linking related entities, selecting MITRE ATT\&CK techniques, and completing case tasks.{#tisc-playbooks-analyst__tisc-playbooks-analyst-p-4}

Stage transitions and approval decisions are made by the case owner --- the user in the Assigned to field. If you aren't the case owner, complete your assigned activities
and notify the case owner when the stage is ready to advance.{#tisc-playbooks-analyst__tisc-playbooks-analyst-p-5}

## Monitoring playbook status {#tisc-playbooks-analyst__tisc-playbooks-analyst-section-context-menu}

While you work on other tabs of the Case record, you can monitor playbook status from the Playbook card in the right-side context menu. The card shows the current stage and lets you cancel the playbook if needed.{#tisc-playbooks-analyst__tisc-playbooks-analyst-p-6}

The system adds a work note to the Case record when the playbook starts. Check the work notes for a record of key playbook events, including stage transitions and completion.{#tisc-playbooks-analyst__tisc-playbooks-analyst-p-7}

## Playbook completion {#tisc-playbooks-analyst__tisc-playbooks-analyst-section-completion}

A playbook runs once per Case. After it reaches completion, it can't run again on the same Case. If a playbook execution is cancelled, the case owner or an administrator can attach the
playbook again manually.{#tisc-playbooks-analyst__tisc-playbooks-analyst-p-8}

At the final stage, analysts typically create a security incident or a report to document the outcome. This action requires create access on the Security Incident table. If you don't have this
access, the playbook does not display the option.{#tisc-playbooks-analyst__tisc-playbooks-analyst-p-9}
* **[Threat Hunting Playbook](https://servicenow-prod.fluidtopics.net/GtI0yd~gKqu7478zSss2aQ)**   
  The Threat Hunting playbook is a guided workflow for a TISC Case record that helps analysts move a threat hunt from an initial hypothesis to a final outcome.

**Related concepts**   

* [Workbench Overview](https://servicenow-prod.fluidtopics.net/v09QNspsdgUKsjcssQ44nQ "The Workbench Overview page consists of the Case Tasks and Cases that are under Threat Analysts and their team.")
* [Working with Investigation Canvas](https://servicenow-prod.fluidtopics.net/EprH7pyEqFs2LVQ4KGvJ5w "The Investigation Canvas is a key significant feature, which provides more valuable information for the Threat Intelligence (TI) analysts. It provides a structured framework by mapping one to one or one to many relationships and visualizing information related to observables, indicators of compromise (IOCs), or entities.")
* [Threat Hunting Playbook](https://servicenow-prod.fluidtopics.net/GtI0yd~gKqu7478zSss2aQ "The Threat Hunting playbook is a guided workflow for a TISC Case record that helps analysts move a threat hunt from an initial hypothesis to a final outcome.")  
**Related tasks**   

* [Creating cases using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/Xb8x3ylFD6FijaDvKqX3WA "Cases are used to track information about a campaign or threat actor threatening your organization. After a case is created, you can add artifacts that allow you to review and analyze all related information from a single case or case task.")
* [Summarize a Case using generative AI](https://servicenow-prod.fluidtopics.net/cR_IUVt2~1oWmLQRzSERog "Use to generate a concise summary of a case, including its key findings and recommended next steps.")
* [Creating case task using Threat Analyst Workbench](https://servicenow-prod.fluidtopics.net/QIyOkhiAbQsuKQ~ncYN_TQ "Create case tasks to associate with case(s).")
* [Add artifacts to case(s) or case task(s)](https://servicenow-prod.fluidtopics.net/w7jOBRuuDQT6Qje2vs23wg "After you have created a case, you can view or add artifacts, such as security incidents, CIs, and indicators of compromise, to the case. These artifacts act as clues in solving the case.")
* [Run Enrichment Actions within a case](https://servicenow-prod.fluidtopics.net/Gh87urOsiF~BhNjGZQsVqg "Use this section to understand how enrichments actions are performed on case(s).")
* [Generate a Case Report using generative AI](https://servicenow-prod.fluidtopics.net/1bdvh6WMLeuGwDMntyZLaA "Generate an AI-based, structured, threat intelligence case report from the data in a case and export it for stakeholder distribution.")
* [Generate a Case Report using a template](https://servicenow-prod.fluidtopics.net/6Y9mhLC9aae1X07xvHOfBg "Use a predefined report template to generate case reports. These reports include post investigation report or an executive summary report.")
* [Create a security incident from a TISC case](https://servicenow-prod.fluidtopics.net/7EbUdWlsxwChV5xDotZntQ "Create security incidents and associate observables to the security incidents from a TISC case.")
* [Upload Secure File Attachments](https://servicenow-prod.fluidtopics.net/~1CsuAO80SPkjnX1j_LDpQ "Use this section to understand on how to upload the secure file attachments to the case(s).")
* [Use the Threat Hunting Playbook](https://servicenow-prod.fluidtopics.net/n2yAquNl9roiQ0pbDZmnNg "Run threat hunt on a Case record — from capturing the hunt hypothesis through to creating a Security incident or reporting.")
* [Add the Threat Hunting Playbook to a Case](https://servicenow-prod.fluidtopics.net/iP9HucJ2wUHgDbKW5ol_Yw "If a Case does not meet the auto-trigger conditions for the Threat Hunting playbook, you can attach the playbook to the Case manually.")

