Automation Mode

Automation Mode

Engine runs every 5 minutes. Each module's mode is read fresh from this page on every tick.

Tenant: (…)
0 enforcing7 notify-only
You need Senior Analyst, SOC Manager, or Admin role to change automation mode.
Zscaler — Auto URL blockNotify only
Auto-block URLs flagged as malicious by VirusTotal (VT ≥ 5)
Last changed: never (defaults to notify-only)
Zscaler — Sandbox auto-actionNotify only
Auto-quarantine MALICIOUS sandbox verdicts
Last changed: never (defaults to notify-only)
CrowdStrike — IOC auto-pushNotify only
Push high-confidence IOCs (≥70) to CrowdStrike
Last changed: never (defaults to notify-only)
Tenable — Auto ticket creationNotify only
Auto-create ServiceNow tickets for CVSS ≥ 9
Last changed: never (defaults to notify-only)
Email — Auto quarantineNotify only
Auto-quarantine MALICIOUS emails on detection
Last changed: never (defaults to notify-only)
Email — DLP outbound blockNotify only
Block outbound emails violating DLP policy
Last changed: never (defaults to notify-only)
Threat Intel — IOC ingestionNotify only
Pull IOCs from MISP/OTX/CISA every tick
Last changed: never (defaults to notify-only)
Recent engine runs
No runs yet — click "Run engine now" or wait 5 min.
Loading module...
CyberOps · Encrypted