awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
OTRF avatar

OTRF/ThreatHunter-Playbook

0
View on GitHub↗
4,591 stele·853 fork-uri·Python·MIT·8 vizualizări

ThreatHunter Playbook

ThreatHunter-Playbook este un framework de playbook-uri de threat hunting și un flux de lucru de inginerie a detecției conceput pentru a standardiza ciclul de viață al detecției de securitate. Funcționează ca un depozit condus de comunitate pentru tradecraft-ul adversarului și logica de detecție, folosind notebook-uri interactive pentru a combina documentația tehnică cu analizele executabile.

Proiectul oferă o suită de validare pentru testarea ipotezelor de securitate împotriva seturilor de date de telemetrie pre-înregistrate. Acest lucru asigură că logica de detecție este verificată în medii locale sau cloud înainte de a fi implementată în producție.

Framework-ul acoperă ingineria detecției de securitate, standardizarea threat hunting-ului și formalizarea planificării vânătorii. Utilizează template-uri structurate și modelare bazată pe componente pentru a ghida procesul de la ipoteza inițială până la validarea finală.

Features

  • Detection Engineering - Provides a framework for the formal planning and implementation of security detection logic and telemetry requirements.
  • Tradecraft Notebooks - Documents adversary behaviors and detection logic using interactive notebooks for repeatable hunting.
  • Tradecraft Repositories - Functions as a community-driven repository for adversary tradecraft and detection logic.
  • Detection Engineering Workflows - Implements a standardized workflow for planning and validating security detections using telemetry datasets.
  • Detection Logic Libraries - Provides a community-driven library of curated detection rules and hypotheses for identifying malicious behavior.
  • Detection Logic Verification - Includes a validation suite to test security hypotheses and analytics against pre-recorded telemetry datasets.
  • Interactive Threat Hunt Notebooks - Uses interactive notebooks to combine executable analytics with documentation for repeatable security hunting procedures.
  • Threat Hunting Workflows - Standardizes proactive processes for searching forensic data using custom detection logic and ordered hunting steps.
  • Hunt Blueprinting - Formalizes the planning phase of threat hunting by defining adversary tradecraft and telemetry requirements.
  • Hypothesis Validation Telemetry - Implements methods for validating threat hypotheses by matching expected event data against recorded security telemetry.
  • Security Detection Test Suites - Ships a validation suite for testing security hypotheses against recorded datasets to verify detection effectiveness.
  • Workflow Standard Templates - Provides structured templates that guide analysts through a consistent detection lifecycle from hypothesis to validation.
  • Detection Component Modeling - Provides a component-based modeling approach to decompose complex adversary behaviors into structured detection steps.
  • Detection Rules and Analytics - Community project for sharing detection logic and tradecraft.
  • Incident Response Playbooks - Structured playbooks for developing and executing threat hunting campaigns.
  • Incident Response Playbooks - Guides for developing threat hunting hypotheses and techniques.
  • Infrastructure and Network Security - Playbook for developing threat hunting techniques and hypotheses.
  • Security Tools - Listed in the “Security Tools” section of the Awesome Hacking awesome list.

Istoric stele

Graficul istoricului de stele pentru otrf/threathunter-playbookGraficul istoricului de stele pentru otrf/threathunter-playbook

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Alternative open-source pentru ThreatHunter Playbook

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu ThreatHunter Playbook.
  • vvard0g/threathunter-playbookAvatar VVard0g

    VVard0g/ThreatHunter-Playbook

    4,594Vezi pe GitHub↗

    ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed to inform threat hunt planning. It provides a security detection repository of validated queries and hypotheses, alongside an adversary tradecraft guide that details system behaviors and data sources associated with attacker techniques. The project focuses on the development of hunt blueprints and the standardization of detection logic. It integrates the MITRE ATT&CK framework to map detections and hypotheses to adversary tactics and techniques, ensuring coverage analysis is st

    Python
    Vezi pe GitHub↗4,594
  • cyb3rward0g/threathunter-playbookAvatar Cyb3rWard0g

    Cyb3rWard0g/ThreatHunter-Playbook

    4,594Vezi pe GitHub↗

    ThreatHunter-Playbook is a structured framework for managing threat hunting playbooks, detection engineering workflows, and adversary tradecraft modeling. It provides a system for organizing behavioral patterns and detection rules into tactical groups to develop security monitoring hypotheses. The project features an interactive security notebook environment that combines analytics and validation queries to test threat hypotheses against telemetry datasets. It includes a mapping tool for organizing these patterns based on the MITRE ATT&CK security framework. The framework covers the full thr

    Python
    Vezi pe GitHub↗4,594
  • certsocietegenerale/irmAvatar certsocietegenerale

    certsocietegenerale/IRM

    1,120Vezi pe GitHub↗

    Incident Response Methodologies 2022

    Vezi pe GitHub↗1,120
  • aws-samples/aws-incident-response-runbooksAvatar aws-samples

    aws-samples/aws-incident-response-runbooks

    1,061Vezi pe GitHub↗

    These playbooks are provided as templates for organizations building incident response capability on AWS. They should be customized to suit your specific needs, risks, available tools, and work processes. These guides are not official AWS documentation and are provided as-is.

    Vezi pe GitHub↗1,061
Vezi toate cele 30 alternative pentru ThreatHunter Playbook→

Întrebări frecvente

Ce face otrf/threathunter-playbook?

ThreatHunter-Playbook este un framework de playbook-uri de threat hunting și un flux de lucru de inginerie a detecției conceput pentru a standardiza ciclul de viață al detecției de securitate. Funcționează ca un depozit condus de comunitate pentru tradecraft-ul adversarului și logica de detecție, folosind notebook-uri interactive pentru a combina documentația tehnică cu analizele executabile.

Care sunt principalele funcționalități ale otrf/threathunter-playbook?

Principalele funcționalități ale otrf/threathunter-playbook sunt: Detection Engineering, Tradecraft Notebooks, Tradecraft Repositories, Detection Engineering Workflows, Detection Logic Libraries, Detection Logic Verification, Interactive Threat Hunt Notebooks, Threat Hunting Workflows.

Care sunt câteva alternative open-source pentru otrf/threathunter-playbook?

Alternativele open-source pentru otrf/threathunter-playbook includ: vvard0g/threathunter-playbook — ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed… cyb3rward0g/threathunter-playbook — ThreatHunter-Playbook is a structured framework for managing threat hunting playbooks, detection engineering… counteractive/incident-response-plan-template — A concise, directive, specific, flexible, and free incident response plan template. certsocietegenerale/irm — Incident Response Methodologies 2022. aws-samples/aws-incident-response-runbooks — These playbooks are provided as templates for organizations building incident response capability on AWS. They should… phantomcyber/playbooks — Phantom Community Playbooks.