OpenCTI Playbook Library: Pre-Built Automation, One-Click Away
Threat intelligence is only as valuable as your ability to act on it. But acting on it (reviewing, labeling, routing, enriching) can become a time sink in itself, leaving analysts with less time for the investigation work that actually matters.
That’s the problem OpenCTI Playbooks were built to solve: turning a passive intelligence repository into an active, automated engine that enriches, labels, correlates, and routes threat data the moment it enters the system, without requiring an analyst to touch it at every step.
Powerful as they are, building a playbook from scratch can feel like staring at a blank canvas. Getting started and putting together a complex, functioning playbook could be intimidating. The Playbook Library fixes that.
TL;DR:
- Playbooks automate the repetitive manual tasks that slow analysts down, freeing them up for actual investigation.
- Building automation workflows from scratch is daunting: not every team has the time or expertise to design flows.
- The Playbook Library delivers pre-built, community-vetted and configurable templates deployable into OpenCTI in a single click.
- Available now in XTM Hub: register your platform and start automating in minutes.
A Library of Pre-Built Templates
The Playbook Library is a curated catalog of ready-to-use playbook templates, accessible directly from XTM Hub for OpenCTI users.
It covers the most common automation use cases out of the box, with each template designed to give you a working baseline you can deploy and customize, rather than a blank workflow you have to build from scratch.
One-Click Deploy
When you find a playbook you want to use, deploying it takes only a single click.
With your OpenCTI platform registered in XTM Hub, hit ”Deploy in OpenCTI” on any template and your playbook is ready to run.
For teams that have been putting off playbook adoption because the setup felt like a project in itself, that friction is now gone. No JSON export, no manual import, no rebuilding the workflow from scratch. The time between “I want this” and “it’s running” goes from hours to minutes.
Pre-built and Configurable
Every template in the library includes a pre-configured workflow with sensible defaults. It also comes with inline documentation that explains what each component does, why it’s configured that way, and what connectors, notifiers, or capabilities you’ll need before deploying.
Nothing is hidden: all dependencies are made explicit so you know exactly what to check before you go live.

A Practical Example: Blacklist Management with PIR
Take a CTI analyst at a financial services firm.
Their team ingests dozens of new indicators every day — IPs, domains, file hashes flagged across threat feeds and ISACs. Every time a high-confidence indicator comes in, someone has to manually review it, apply the right label, route it to the relevant blocking feed, and log the decision for audit purposes. It works, but it’s slow, repetitive, and one missed step away from a compliance gap.
So they decide to try out an OpenCTI playbook to see if some of this work can be automated.
The CTI analyst opens the Playbook Library in XTM Hub, searches for “blacklist,” and finds the Blacklist Management with Post-Incident Review (PIR) template. The details page walks through exactly what the workflow does: it triggers on new or updated indicators matching defined criteria, applies the appropriate labels, routes them to the relevant case or feed, and logs each action for post-incident review. Prerequisites are listed clearly. Everything looks compatible with their environment.

The analyst hits ”Deploy in OpenCTI”, confirms the setup panel, and the playbook is live. From that point on, the routing and logging happens automatically. The analyst still makes the calls that require judgment, but the mechanical work of tracking, labeling, and documenting every indicator is now handled through the playbook. What used to take up a meaningful chunk of the team’s time now runs quietly in the background.
And this is not just a story. This playbook is in the Library, right now. You can try it today.
See it in the Playbook Library —>
Getting Started on the XTM Hub
The Playbook Library is now available on XTM Hub. Community Edition users can browse the full catalog, learn from the templates, and download playbooks for manual import. Enterprise Edition users get one-click deploy on top of that.
If you have questions about specific templates, want to contribute a playbook to the library, or need help adapting a template to your environment, join the conversation in the Filigran Community. The library will grow over time, and community contributions are part of how it gets better.
If you have any questions or want to contribute to the Library, see you on our the community channel!
Read more
Explore related topics and insights