You can select a playbook from the full list of playbooks instead of executing a response action, or when no response actions are available to execute.
To select a playbook to execute:
Navigate to the Correlations Details or Threat Details page.
Click Actions > Trigger Playbook. The full list of playbooks is displayed.
Select a playbook and select the "I confirm" checkbox. Then click Trigger.
If you select a playbook with indicators that are not present in the correlation or threat, a message informs you that no matching values are available. The playbook is not relevant for the threat and cannot be triggered.
If matching indicators are present, a dialog box opens. No indicators are selected by default. Specify that the playbook should take all indicators or select individual indicators.
Select the "I understand" checkbox.
Click Confirm.