How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
Phantom Community Playbooks
The main features of phantomcyber/playbooks are: Incident Response Playbooks, Automation Frameworks.
Open-source alternatives to phantomcyber/playbooks include: otrf/threathunter-playbook — ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to… certsocietegenerale/irm — Incident Response Methodologies 2022. aws-samples/aws-incident-response-runbooks — These playbooks are provided as templates for organizations building incident response capability on AWS. They should… counteractive/incident-response-plan-template — A concise, directive, specific, flexible, and free incident response plan template. ayehu/custom-workflows — This is a public workflows repository for Ayehu users to share their content. azure/azure-sentinel — This repository is a community-driven collection of security content for Azure Sentinel, the cloud-native security…
Incident Response Methodologies 2022
A concise, directive, specific, flexible, and free incident response plan template
These playbooks are provided as templates for organizations building incident response capability on AWS. They should be customized to suit your specific needs, risks, available tools, and work processes. These guides are not official AWS documentation and are provided as-is.
ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to standardize the security detection lifecycle. It functions as a community-driven repository for adversary tradecraft and detection logic, using interactive notebooks to combine technical documentation with executable analytics. The project provides a validation suite for testing security hypotheses against pre-recorded telemetry datasets. This ensures that detection logic is verified in local or cloud environments before being deployed to production. The framework covers security detec