A device provides a usable instance of a plug-in and its commands. A playbook runs the commands to exchange data with upstream and downstream systems and services. For example, the VirusTotal - Indicator Enrichment playbook uses the Virustotal device to extract indicators from a threat and uses the VirusTotal service to enrich those indicators.
The Devices page (Response > Devices) provides details about each device, such as the plug-in it uses, its status, whether the device is configured, and the playbook that uses it.
.png)
There are two types of devices:
The Datastore device is used by every playbook. It writes playbook execution results to a data store so the results can be displayed as playbook activity in the Trellix Helix Web UI. Authentication for this device is handled implicitly so it requires no configuration.
The other devices are specific to the provided playbooks. A single device can be used by more than one playbook. For example, the Microsoft Azure - Disable Users and Microsoft Azure - Users Enrichment playbooks both use the Azure device. You must configure authentication credentials for these devices.
Important
Playbooks cannot be executed if the devices they use are not configured. Warnings are displayed on the Devices page for devices that are not configured.
Note
Devices are enabled by default.