Soar Playbook Design

Design safe security automation playbooks for a SOAR platform (Microsoft Sentinel automation rules and Logic Apps, Splunk SOAR, Cortex XSOAR, Tines, Shuffle): triggers, enrichment, decision logic, containment behind human-approval gates, idempotency, rate limits, rollback, error handling, dry-run testing, and metrics, expressed in a vendor-agnostic JSON definition that a bundled linter checks. Use this whenever someone wants to "automate" an alert response, asks for a playbook, workflow, automation rule, Logic App, story, or runbook-as-code, wants to auto-block, auto-isolate, auto-disable, or auto-close anything, asks "is this automation safe", or wants an existing playbook reviewed or translated between platforms. Design and review only; it never executes actions.

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/soar-playbook-design commit 096e08b5ff

Frequently asked questions

npx skillmds@latest add ftrout/soar-playbook-design