Playbook All on Content Hub
Set alert severity from AbuseIPDB score
Checks an alert's source IP against AbuseIPDB and raises severity when the abuse score is high.
@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Sep 5, 2026
Download JSON · 15 KB
abuseipdb-severity.json
sha256:962814f3585c76634388129e8ab204aed6463245a009fc677e384fa3ec7e706b
Sanitized by the pipeline and shipped inactive. Follow the before turning it on.
Runs against the selected alert, looks up its source IP on AbuseIPDB and sets severity to Critical when the abuse confidence score is 50 or more, otherwise Low.
Tune the threshold in the decision step to match your tolerance.
Something wrong with this item? Sign in to report