Jump to main content
Overview
Automation Parameters and Flowchart
Block attackers upon IPS detection of popular attacks
Block common scanner identified by IPS
Block attacking IP with malicious reputation identified by IPS
Block attacking IP with malicious reputation identified by WAF Application Security
Quarantine compromised Endpoint Security device (enforced by Firewall)
Quarantine potentially infected Endpoint Security device (enforced by Firewall)
Notify on Firewall Traffic Blocked by Check Point SASE
Notify on URL filtering blocked by Check Point SASE
Notify on URL Reputation Identification by Check Point SASE
Notify on Tunnel Down by Check Point SASE
Notify on Malicious File Detection by Check Point SASE
Block malicious file indicator identified by Threat Extraction Endpoint Security
Block malicious file indicator identified by Threat Emulation Endpoint Security
Block malicious file indicator identified by Anti-Bot Endpoint Security
Block malicious URL indicator identified by Anti-Bot Endpoint Security
Block malicious indicator identified by Anti-Bot
Block malicious indicator identified by Anti-Virus
Block malicious indicator identified by Zero Phishing Endpoint Security
Block malicious indicator identified by Zero Phishing
Isolate compromised Endpoint Security device (enforced by Endpoint)
Isolate potentially Infected Endpoint Security device (enforced by Endpoint)
Isolate potentially infected SentinelOne device (enforced by Endpoint)
Isolate potentially infected CrowdStrike device (enforced by Endpoint)
Quarantine potentially infected SentinelOne device (enforced by Firewall)
AI Agent - Management health report
Isolate potentially infected Microsoft Defender device (enforced by Endpoint)
Quarantine potentially infected Microsoft Defender device (enforced by Firewall)
Credentials leakage detected by External Risk Management triggering reset password
Check Point Firewall Cloud Log Ingestion Health Monitor
Repeated Remote Access login failures using password-only
Repeated Remote Access login to expired accounts
Remote Access user login using password-only Authentication
Block DDoS attack detected by DDoS Protector
Quarantine potentially infected CrowdStrike device (enforced by Firewall)
De-isolate potentially clean Microsoft Defender machine
Notify on Failed Gaia Portal Login
Notify on Expert Shell Login
Notify on Run Script execution
Notify on failure of Policy Installation on Check Point Firewall
Notify on degradation in Check Point Firewall Compliance status
Notify on successful Policy Installation on Check Point Firewall
Notify on changes in administrators
Alert on MTA email bypass
Notify on Management validations
Notify on Management High Availability Change-over
Notify on repeated login failures to Management
Notify on high rate of blocked connections
Notify on failure of installation blade updates on Check Point Firewalls
Notify on successful installation of blade updates on Check Point Firewalls
Alert on licenses expiration on Check Point Firewall device
Alert on VPN certificates expiration on Check Point Firewall
Alert if VPN Tunnel is down
Alert if no communication with Check Point Firewall
Notify on non-compliant devices blocked by Identity and Trust
Block external IP
Isolate endpoint device
Enforce Policy on newly discovered IoT Zone
Device is at risk IoT
Notify on Endpoint Security client uninstall password change
Notify on bulk uninstallation of Endpoint Security clients
Reset User Password in Identity Provider
Delete file on Endpoint Security device
IOC Management - New indicator
IOC Management - Delete indicator
Stop and quarantine file via Microsoft Defender
Scan machine via Microsoft Defender
Isolate machine via Microsoft Defender (by XDR)
Release machine from isolation via Microsoft Defender (by XDR)
Stop and quarantine file via Microsoft Defender (by XDR)
Handle SD-WAN Link Swap ISP Down
Open ticket
Close ticket
Get ticket
Open ticket and notify
Spark Management event
Alert on ransomware attack detected by Endpoint Security
Alert on Generative AI Risky Session
Alert on a phishing attempt detected by Endpoint Security
Alert on malicious file detected by Endpoint Security
Alert on access to malicious site detected by Endpoint Security
Alert on password reuse attempt detected by Endpoint Security
Alert on exploit attempt detected by Endpoint Security
Alert on the outdated Endpoint Security Static Analysis capability
Alert on the outdated Endpoint Security Offline Reputation capability
Alert on outdated Endpoint Security Behavioral Guard capability
Alert on disconnected Endpoint Security clients
Alert on Endpoint Security Compliance warnings
Alert on device restrictions by Endpoint Security
Alert on outdated Endpoint Security Anti-Malware
Alert if the device is not scanned by the Endpoint Security Anti-Malware capability
Alert on Endpoint Security Anti-Malware license expiration
Alert on Endpoint Security deployment failure
Alert if Endpoint Security client capabilities stop running
Add malicious file indicator Identified by CrowdStrike to IOC feed
Add malicious file indicator Identified by SentinelOne to IOC feed
Add malicious file indicator Identified by Microsoft Defender to IOC feed
Notify on AIOps alert
Configuring the Automation Parameters
Running the Automation
Enabling the Automation
Approving, Rejecting or Reverting an Automation Execution
Customization in Playblocks
Playblocks provides flexible customization options to tailor automations according to your organization's needs.
Creating Automation from Blank
Creating an automation from blank allows you to build fully customized flows from scratch and tailor every step to your specific use case.
Log Trigger
Configure a Log Trigger to monitor logs, define conditions, and create example outputs for automation workflows.
Schedule Trigger
Configure a schedule trigger to run automation at recurring intervals. The task explains how to select the repetition frequency and create the trigger.
Managing Trigger
Learn how to manage a trigger by adding notifications, enrichments, conditions, or actions.
Notifications
Configure notification actions including Notify, Ask, and Open Ticket options. This task explains how to create and customize notification messages and ticket actions.
Alert Steps
Alert steps let an automation drive an incident through its full on-call lifecycle in PagerDuty and other alerting platforms behind the same vendor-neutral steps.
Trigger Alert
The Trigger Alert step opens a new incident in PagerDuty. If an open incident with the same Alert ID already exists, PagerDuty returns the existing incident and does not create a duplicate.
Get Alert
The Get Alert step reads the current state of an existing incident in PagerDuty.
Acknowledge Alert
The Acknowledge Alert step pauses escalation on an open incident in PagerDuty.
Add Note to Alert
The Add Note to Alert step posts a free-text note to an existing incident in PagerDuty.
Resolve Alert
The Resolve Alert step closes an incident in PagerDuty.
Enrichments
Use enrichment steps to query the Reputation Service for IP addresses, URLs, or file hashes from previous step outputs. The enrichments provide threat intelligence data about the selected value.
Conditions
Use conditions to create branches in the automation flow based on logical evaluations. This task explains how to configure condition expressions and operations.
Actions
Action steps perform operational tasks such as running automations, managing indicators, and sending external API requests.
Run Automation
Run an automation action and configure automation parameters and inputs for supported automation types.
Add to List
Use the Add to List procedure to add IPs, URLs, domains, or hashes to a list with optional conditions and duration settings.
Create IoC Management Indicators
Create IoC Management indicators by specifying indicator values and expiration settings in the Create IoC Management Indicators window.
API Request
Configure an API Request action in an automation and define the example output structure for API responses.
AI Request
Use the AI Request step to send a prompt to a connected AI provider and use the model's response in subsequent steps.
Isolate Endpoint Device
Configure and create an isolation action for an endpoint device. Specify the endpoint product, device details, isolation duration, and reason for isolation.
Scan Endpoint Security Device
Scan an Endpoint Security device by configuring target identification, scan options, and scheduling parameters.
Terminate Process on Endpoint Security Device
Delete File on Endpoint Security Device
Exporting/Importing Automation
You can export and import an automation in JSON format. This task explains how to export an automation and import an automation file.
Cloning Existing Automation
You can clone an existing automation for editing and customization. This task explains how to clone an automation from the card view and table view.
Creating Automation by AI Copilot
AI Copilot allows you to create custom Playblocks automations using natural language prompts. This topic explains the supported capabilities, limitations, and steps to create an automation.
Automation Capabilities
This topic describes the different automation capability types, their use cases, abilities, and editing restrictions.
Replace Trigger
Replace Trigger allows you to change the current trigger type in your automation to a different one. This topic explains how to replace a trigger, configure the new trigger, and resolve validation errors.
Adding a Step to the Middle of an Automation
Monitor
Executions
Check Point Firewall Logs
Email
SMS
Jira Ticketing
Slack
Microsoft Teams
ServiceNow Ticketing
Configure a ServiceNow Ticketing connector to receive incident details and responsive actions through ServiceNow Ticketing.
Freshdesk Ticketing
The Freshdesk Ticketing connector enables Playblocks to create, retrieve, and close tickets in Freshdesk.
PagerDuty Alerting
AI Connectors
This topic describes how to connect an AI provider to Playblocks and how to use the AI Request step in custom automations.
Microsoft Defender
CrowdStrike
Microsoft Entra ID
Okta
SentinelOne
IOC Enforcement