ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed to inform threat hunt planning. It provides a security detection repository of validated queries and hypotheses, alongside an adversary tradecraft guide that details system behaviors and data sources associated with attacker techniques. The project focuses on the development of hunt blueprints and the standardization of detection logic. It integrates the MITRE ATT&CK framework to map detections and hypotheses to adversary tactics and techniques, ensuring coverage analysis is st
ThreatHunter-Playbook is a structured framework for managing threat hunting playbooks, detection engineering workflows, and adversary tradecraft modeling. It provides a system for organizing behavioral patterns and detection rules into tactical groups to develop security monitoring hypotheses. The project features an interactive security notebook environment that combines analytics and validation queries to test threat hypotheses against telemetry datasets. It includes a mapping tool for organizing these patterns based on the MITRE ATT&CK security framework. The framework covers the full thr
Incident Response Methodologies 2022
These playbooks are provided as templates for organizations building incident response capability on AWS. They should be customized to suit your specific needs, risks, available tools, and work processes. These guides are not official AWS documentation and are provided as-is.
ThreatHunter-Playbook este un framework de playbook-uri de threat hunting și un flux de lucru de inginerie a detecției conceput pentru a standardiza ciclul de viață al detecției de securitate. Funcționează ca un depozit condus de comunitate pentru tradecraft-ul adversarului și logica de detecție, folosind notebook-uri interactive pentru a combina documentația tehnică cu analizele executabile.
Principalele funcționalități ale otrf/threathunter-playbook sunt: Detection Engineering, Tradecraft Notebooks, Tradecraft Repositories, Detection Engineering Workflows, Detection Logic Libraries, Detection Logic Verification, Interactive Threat Hunt Notebooks, Threat Hunting Workflows.
Alternativele open-source pentru otrf/threathunter-playbook includ: vvard0g/threathunter-playbook — ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed… cyb3rward0g/threathunter-playbook — ThreatHunter-Playbook is a structured framework for managing threat hunting playbooks, detection engineering… counteractive/incident-response-plan-template — A concise, directive, specific, flexible, and free incident response plan template. certsocietegenerale/irm — Incident Response Methodologies 2022. aws-samples/aws-incident-response-runbooks — These playbooks are provided as templates for organizations building incident response capability on AWS. They should… phantomcyber/playbooks — Phantom Community Playbooks.