Skip to main content
Gamebooks are ContraForce’s automated response engine. Instead of manually logging into multiple consoles to contain a threat, you can execute proven response actions with a single click.
Think of Gamebooks as your incident response playbook—automated. Select the actions you need, click run, and ContraForce handles the execution across your integrated security tools.

Why Gamebooks?

Traditional incident response requires analysts to:
  1. Identify affected entities (users, devices, IPs)
  2. Log into each security tool separately
  3. Manually execute containment actions
  4. Document what was done
Gamebooks compress this into seconds:

One Click

Execute multiple actions across tools instantly

Consistent

Same response every time—no missed steps

Auditable

Complete history of every action taken

Available Gamebook Actions

Gamebook actions are organized by entity type. ContraForce automatically shows relevant actions based on the entities involved in each incident.

User Actions

ActionDescriptionUse Case
Invalidate Existing SessionsTerminates all active sessionsCompromised account, suspicious activity
Lockout UserPrevents user from signing inConfirmed account compromise
Reset User PasswordForces password reset on next loginCredential theft suspected
Unlock UserRe-enables a locked accountAfter remediation is complete

Endpoint Actions

ActionDescriptionUse Case
Isolate EndpointDisconnects device from network (except Defender)Active malware, lateral movement
Scan EndpointTriggers antivirus/EDR scanSuspicious file activity
Release from IsolationRestores network connectivityAfter threat is contained
Quarantine FileMoves malicious file to quarantineKnown malware detected

Network Actions

ActionDescriptionUse Case
Block IPAdds IP to blocklistC2 communication, malicious source

Email Actions

ActionDescriptionUse Case
Delete EmailRemoves malicious email from mailboxPhishing, malware delivery
Available actions depend on your connected integrations. For example, endpoint actions require Microsoft Defender for Endpoint to be onboarded.

How to Access Gamebooks

1

Open an Incident

From the Command Page, click any Incident ID to open the Incident Summary
2

Open the Gamebook Workbench

Click the dropdown next to Edit and select Create New Gamebook
3

Start Building

The Gamebook Workbench opens with the Entity Graph and action carousel
Accessing Gamebook Workbench

Building a Gamebook

Creating a Gamebook is intuitive—select entities, choose actions, and execute.

Step 1: Select an Entity

Click an entity in the Entity Graph (user, device, IP, etc.). The action carousel appears showing available response actions.
Entity selection in Gamebook

Step 2: Add Actions

  • Use the arrows to browse available actions
  • Click the green + icon to add an action to your Gamebook
  • Click the red - icon to remove an action

Step 3: Repeat for Other Entities

Select additional entities and add their actions. You can build comprehensive response workflows targeting multiple entity types.

Step 4: Review & Execute

Your selected actions appear in the Gamebook Card:
Gamebook actions queue
ColumnDescription
ActionThe response action to be performed
EntityTarget of the action
Status”Pending” before execution
Click Run Gamebook to execute all actions.

Gamebook Execution Status

After clicking Run Gamebook, monitor the execution:
StatusMeaning
PendingAction queued, not yet started
RunningAction currently executing
FinishedAction completed successfully
FailedAction encountered an error
Gamebook execution status
If an action fails, check the Gamebook Activity page for error details. Common causes include permission issues or connectivity problems with the target system.

Gamebook Approval Workflow

Some actions are too impactful to execute without oversight. These require approval before running.

How to Identify Approval-Required Actions

Actions requiring approval display a red lock icon in the carousel.
Approval required indicator

Requesting Approval

When your Gamebook includes locked actions:
  1. Build your Gamebook as usual
  2. The button changes to Request Gamebook Approval
  3. Click to submit the request
  4. Status shows Waiting Approval

Approving Gamebooks

Users with approval permissions can approve from:

Incident Summary

Open the incident and approve directly from the Gamebook status

Gamebooks Page

Review all pending approvals in one centralized location
Once approved, the Gamebook executes automatically.

Gamebook History

Track all Gamebook activity across your environment from the dedicated Gamebooks Page.

Accessing Gamebook History

Click the Gamebooks icon (triangle) in the navigation bar—it’s the 2nd icon from the top.
Gamebooks page navigation

What You Can See

The Gamebooks page shows:
FilterDescription
CompletedSuccessfully executed Gamebooks
Waiting ApprovalPending approval requests
FailedGamebooks with errors

Viewing Details

Click the dropdown arrow on any row to expand and see:
  • Individual action results
  • Execution timestamps
  • Error messages (if failed)
  • Entity details
Gamebook history expanded view
Use the workspace filter to view Gamebook history for specific tenants. This is useful when reviewing activity for a particular customer.

Unsupported Entities

Not all entity types support Gamebook actions due to technical limitations with source integrations. If an entity doesn’t support actions, you’ll see an error message:
Unsupported entity message
Common reasons:
  • Integration doesn’t expose response APIs
  • Entity type not yet supported
  • Permissions not configured for response actions
ContraForce continuously adds new integrations and actions. If you need specific response capabilities, contact [email protected] to discuss your requirements.

Best Practices

Prioritize actions that stop the threat from spreading—isolate devices, disable compromised accounts, block malicious IPs.
Configure approval requirements for actions like device isolation that could impact business operations.
Always verify the Gamebook Card shows the correct entities and actions before clicking Run.
Check the Gamebooks page regularly for failed actions that may need manual intervention.
After running a Gamebook, add comments to the incident explaining what actions were taken and why.

Gamebook Actions Quick Reference

EntityActions Available
UserInvalidate Sessions, Lockout, Reset Password, Unlock
EndpointIsolate, Scan, Release from Isolation, Quarantine File
NetworkBlock IP
EmailDelete Email


Questions about Gamebooks? Contact us at [email protected].