The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Selecting a playbook to execute

Prev Next

You can select a playbook from the full list of playbooks instead of executing a response action, or when no response actions are available to execute.

To select a playbook to execute:

  1. Navigate to the Correlations Details or Threat Details page.

  2. Click Actions > Trigger Playbook. The full list of playbooks is displayed.

  3. Select a playbook and select the "I confirm" checkbox. Then click Trigger.

    If you select a playbook with indicators that are not present in the correlation or threat, a message informs you that no matching values are available. The playbook is not relevant for the threat and cannot be triggered.

  4. If matching indicators are present, a dialog box opens. No indicators are selected by default. Specify that the playbook should take all indicators or select individual indicators.

  5. Select the "I understand" checkbox.

  6. Click Confirm.