Skip to main content
Gamebooks are incident response workflows guided by your operating procedures and powered by ContraForce’s response engine, IRIS. Instead of manually logging into multiple consoles to contain a threat, you can execute proven response actions with a single-click across any workspace.
Think of Gamebooks as your incident response playbook—automated. No API mapping, no coding, no scripting. Select the response actions you need, click run, and ContraForce handles the execution across your integrated security tools. AI agents can autonomously choose the correct response actions based on entity types and the classification of the incident.

Why Gamebooks?

Traditional incident response requires analysts to:
  1. Identify affected entities (users, devices)
  2. Log into each security tool separately
  3. Manually execute containment actions
  4. Document what was done
Gamebooks compress this into seconds:

One Click

Execute multiple actions across tools instantly

Consistent

The right response every time

Auditable

Complete history of every action taken

Compiled Automatically by Your AI Agents

You don’t have to assemble the response yourself. When a Security Delivery Agent investigates an incident, it builds an investigation graph — the same Entity Context Graph you see in the Workbench — to determine exactly which entities the incident impacted. The agent then compiles the Gamebook for you, mapping the appropriate response actions to each impacted entity based on entity type and the incident’s classification. You can still add or remove actions before it runs.
What happens to a compiled Gamebook depends on the agent’s mode. In manual runs it waits for you to review and run it; with Allow Agent to run gamebooks enabled, the agent executes it once its confidence threshold is met. See Configuring Security Delivery Agents.

Available Gamebook Actions

Gamebook actions are organized by entity type. ContraForce automatically shows relevant actions based on the entities involved in each incident.

User Actions

Reset MFA vs. Reset User Password. These are complementary, not interchangeable. Reset User Password invalidates the credential the user types; Reset MFA deletes the second factors they present (Microsoft Authenticator, phone/SMS, FIDO2 security keys, software OATH tokens, Windows Hello for Business, Temporary Access Pass, and email/platform methods). It does not change the password. When you suspect an attacker has enrolled their own authenticator on a compromised account, a password reset alone leaves that rogue factor in place: run Reset MFA to strip it, and pair it with Reset User Password for full credential containment. After the reset the user re-registers MFA on their next sign in, so confirm an enrollment path (and any Conditional Access / registration-campaign policies) is in place before running it.

Endpoint Actions

Network Actions

Email Actions

Available actions depend on your connected modules. For example, endpoint actions require Microsoft Defender for Endpoint module to be configured.

How to Access Gamebooks

1

Open an Incident

From the Incidents page, open an incident and select View full details
2

Open the Gamebook Workbench

Select the Gamebooks Workbench icon next to Actions. You can also build a response plan in the incident’s Response → Gamebook builder.
3

Start Building

The Gamebook Workbench opens with the Entity Context Graph
Accessing Gamebook Workbench

Building a Gamebook

Creating a Gamebook is intuitive—select entities, choose response actions, and execute.

Step 1: Select an Entity

Left-click an entity in the Entity Context Graph (user, device, IP, etc.). The response action menu appears showing available response actions.
Entity selection in Gamebook

Step 2: Add Actions

  • With the left-click menu open, select available response actions
  • Click a response action to load it into the Gamebook
  • Click the red - icon to remove an action

Step 3: Repeat for Other Entities

Select additional entities and add their actions. You can build comprehensive response workflows targeting multiple entity types.

Step 4: Review & Execute

Your selected actions appear in the Gamebook Card:
Gamebook actions queue
Click Run Gamebook to execute all actions.

Gamebook Execution Status

After clicking Run Gamebook, monitor the execution:
If an action fails, check the Gamebook Activity page for error details. Common causes include permission issues or connectivity problems with the target system.

Gamebook Approval Workflow

Manage the team members responsible for approving Gamebooks that require manual authorization. Only users with the Workspace Owner role can be assigned as Gamebook approvers.

Gamebook Approval Configuration

Open Workspaces → [workspace] → Gamebooks and configure the Gamebook configuration based on your operating procedures for that workspace:
  • Allow service providers to run gamebooks — lets the service providers that manage the workspace run Gamebooks on its behalf
  • Approvers — the Workspace Owners who approve Gamebooks that require manual authorization
  • Run policies — ordered rules, checked top to bottom, that block an action, allow it, or send it to an approver first; if none match, the action is allowed
Approval required indicator
Some response actions (Reset user password) require the end user of the workspace to have the Global Administrator or Privileged Role Administrator role — enabling the add-on assigns an Entra directory role, which only those two roles can do. As a Service Provider, you can approve this action on your end without the end user consent.

Approving Gamebooks

Users with approval permissions can approve from:

Incident Summary

Open the incident and approve directly from the Gamebook status

Gamebooks Page

Review all pending approvals in one centralized queue
Once approved, the Gamebook executes automatically.

Gamebook History

Track all Gamebook activity across your environment from the dedicated Gamebooks Page.

Accessing Gamebook History

Click the Gamebooks icon (triangle) in the navigation bar—it’s the 2nd icon from the top.
Gamebooks page navigation

What You Can See

The Gamebooks page shows:

Viewing Details

Click the dropdown arrow on any row to expand and see:
  • Individual action results
  • Execution timestamps
  • Error messages (if failed)
  • Entity details
Gamebook history expanded view
Use the workspace filter to view Gamebook history for specific tenants. This is useful when reviewing activity for a particular customer.

Unsupported Entities

Not all entity types support Gamebook actions due to technical limitations with module integrations. Common reasons:
  • Integration doesn’t expose response APIs
  • Entity type not yet supported
  • Permissions not configured for response actions
If you need specific response capabilities, contact support@contraforce.com to discuss your requirements.

Best Practices

Prioritize actions that stop the threat from spreading—isolate devices, disable compromised accounts, block malicious IPs.
Configure approval requirements for actions like device isolation that could impact business operations.
Always verify the Gamebook Card shows the correct entities and actions before clicking Run.
Check the Gamebooks page regularly for failed actions that may need manual intervention.
After running a Gamebook, add comments to the incident explaining what actions were taken and why.

Gamebook Actions Quick Reference

Workbench Overview

Your toolset for security delivery

Incident Management

Complete incident workflow guide

Incident Classifications

Classify incidents after response

User Management

Configure approval permissions

Questions about Gamebooks? Contact us at support@contraforce.com.