SOC and IR professionals are required to use myriad different tools and services to handle alerts and investigate cases, including EDR, Sandboxes, SIEM, pDNS, TIPs and more. Working through all of these GUIs is time consuming and has a learning curve due to the hundreds of different tools and vendors out there - every environment will have different tools. False positives must often be identified manually due to the lack of direct communication between the siloed tools.Security automation playbooks present a solution to this problem. They combine the mature ideas of orchestration IR workflows into a single focal point to improve capabilities for each type of alert the team needs to handle.In this talk we will review the basics of playbook design, describe several simple playbooks and share lessons learned from building playbooks with blue teams protecting Fortune50 companies.