Add the Threat Hunting Playbook to a Case
If a Case does not meet the auto-trigger conditions for the Threat Hunting playbook, you can attach the playbook to the Case manually.
Before you begin
Role required: sn_sec_tisc.analyst
The Case must be open. You can't add the Threat Hunting playbook to a closed Case.
About this task
Use this procedure when the Threat Hunting playbook doesn't auto-trigger but you still want to run a threat hunt. For example, you want to run it when the Case Type is not Threat Hunting.
Procedure
Navigate to Workspaces > Threat Intelligence Security Center.
Select the Threat Analyst Workbench icon.
Go to Case Management > All Cases.
All the cases are displayed.
Open a Case record and select **
More actions** > **Add Playbook**.
Select Threat Hunting from the list of available playbooks.
Review the confirmation dialog and confirm the addition.
Important: Adding a playbook can result in repetition of the activities completed on the Case, for example, MITRE techniques associated or scenarios entered.
Result
The Threat Hunt Playbook is attached to the Case and initiates the Intake stage. For details on each stage, see Use the Threat Hunting Playbook.
Parent Topic:Threat Hunting Playbook
Related topics