Skip to content

Guide

Using what you download

Everything here is an export file you bring into your own SOAR platform (compatible with FortiSOAR 7.4 and later unless an item says otherwise). This guide covers the general flow; each item's Setup tab lists the exact steps for that item.

Before you import

  • Open the item's Dependencies tab. Every connector shows whether it's on the Content Hub.
  • If a connector is marked Not on Content Hub, the playbook was built with a custom connector. You'll need that connector, or one that offers the same operations, before those steps can run.
  • Check the platform version. Items list the minimum version they were built for.
  • Try it in a non-production instance first. Treat community content like any third-party code.

Install connectors from the Content Hub

  1. Open Content Hub and search for the connector by name.
  2. Install the version listed in the item's dependencies, or the latest if it says "On Content Hub".
  3. If an item shows Version differs, it was built against another version. It usually still works; check that the listed operations exist in your version.

Configure connectors

Downloads never include connector configurations or credentials: they're stripped during publishing. Add a configuration with your own credentials and mark it as the default so connector steps pick it up without editing each step.

Import a playbook

  1. Download the .json file from the item page. Optionally verify its SHA-256 shown under the download button.
  2. Go to Settings → Import Wizard and upload the file.
  3. Review the collections and playbooks being added. If a collection with the same name exists, choose whether to merge or replace.
  4. Finish the import.

Install a solution pack

Solution packs bundle playbooks with modules, picklists or dashboards. Upload the .zip from Content Hub → Manage → Upload (or the Import Wizard for configuration exports). If the pack depends on other packs, install those first: they're listed under Dependencies.

Review and activate

Every download is shipped inactive on purpose, so nothing fires the moment you import it. Open each playbook, check the trigger conditions and any record it updates, run it manually on a test record, then activate it.

Pay particular attention to items marked Contains code. A maintainer reviewed them, but read code steps yourself before turning them on.

Contributing

You can share playbook collections, solution packs, connectors and widgets you wrote yourself. The easiest way is the upload page:

  1. Sign in with GitHub. Only your public profile is used, to credit you and to limit spam.
  2. Drop in your export, give it a title, a one-line summary and a use case or two.
  3. The checks run within about a minute and you see the full report on your submissions page. Your file sits in a private quarantine until then; nothing is public before it passes.
  4. Clean submissions from established contributors publish automatically. Everything else gets a quick review by a maintainer.

Prefer git?

You can also open a pull request. Fork the repository, add a folder content/<type>s/<slug>/ (for example content/playbooks/ip-enrichment/) with a meta.yaml and the cleaned export from soarshelf check --clean-out (see below), then open the pull request. The author must be your GitHub handle and author_id your numeric GitHub id (gh api users/<handle> --jq .id); CI checks both.

title: Enrich source IPs with threat intel
summary: Scores alerts by source IP reputation and skips private addresses.
use_cases: [triage, enrichment]
tags: [enrichment, ip]
author: your-github-handle
author_id: 12345678
version: 1.0.0
min_version: 7.4.0
description: |
  Longer markdown description shown on the item page.

Please don't upload:

  • Content you didn't write, including official solution packs or anything copied from a vendor or customer.
  • Customer names, internal hostnames, real IPs or email addresses. Use example.com and documentation IP ranges.
  • Credentials of any kind, even expired ones.
  • Logos or vendor branding. Product names are fine when they describe what the item works with.

By submitting you confirm you have the right to share the content and license it under the MIT license.

What we check

Every submission runs through the same pipeline. Downloads are rebuilt from the parsed content, never served as the bytes you uploaded.

CheckWhat it looks forOutcome
FormatThe file must be a playbook collection export, a solution pack zip, or a connector or widget manifest (info.json). Anything else is rejected.Block
SizePlaybook JSON up to 2.0 MB, solution pack zip up to 20.0 MB. Zips are checked for path traversal, symlinks, nested archives and decompression bombs.Block
SecretsAPI keys, tokens, passwords, private keys, JWTs and credentials in URLs.Block
Private network detailsRFC 1918 and other internal IP addresses, internal hostnames, and real email addresses. Documentation ranges and example.com are fine.Review
Ownership referencesUsers, teams, owners and connector configuration IDs are stripped automatically. You don’t need to clean them yourself.Auto-fixed
Official contentExports that match published solution pack content are rejected: only share what you wrote.Block
TrademarksTitles and descriptions can name products to describe compatibility, but can’t claim to be official or endorsed.Review
CodeCode-snippet steps, connectors and widgets are flagged and always reviewed by a person. Connector and widget code is never hosted here: items link to their source.Review
Content Hub dependenciesEach connector and operation is checked against the current Content Hub index so users see what they need before importing.Info

Trust tiers

Clean submissions from established contributors can publish automatically. Everything else waits for a maintainer.

TierHow you get therePublishes automatically
NewAny GitHub account at least 30 days old. Up to 3 submissions a day.Nothing. Every submission is reviewed by a maintainer.
Contributor3 approved submissions and no strikes.Playbooks that pass every check and have no code steps.
TrustedPromoted by a maintainer.Playbooks and solution packs that pass every check. Connectors are still reviewed.
MaintainerRuns the project.Reviews the queue. Connector code is always reviewed, even from maintainers.

Check locally before you submit

The pipeline is a small Python CLI in the repository. Run it on your export to see exactly what CI will report:

cd pipeline
uv run soarshelf check path/to/your-export.json

Anything marked block must be fixed. Review findings are fine if they're intended; a maintainer will look at them.