awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
OTRF avatar

OTRF/ThreatHunter-Playbook

0
View on GitHub↗
4,591 stars·853 forks·Python·MIT·12 views

ThreatHunter Playbook

ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to standardize the security detection lifecycle. It functions as a community-driven repository for adversary tradecraft and detection logic, using interactive notebooks to combine technical documentation with executable analytics.

The project provides a validation suite for testing security hypotheses against pre-recorded telemetry datasets. This ensures that detection logic is verified in local or cloud environments before being deployed to production.

The framework covers security detection engineering, threat hunting standardization, and the formalization of hunt planning. It utilizes structured templates and component-based modeling to guide the process from initial hypothesis to final validation.

Features

  • Detection Engineering - Provides a framework for the formal planning and implementation of security detection logic and telemetry requirements.
  • Tradecraft Notebooks - Documents adversary behaviors and detection logic using interactive notebooks for repeatable hunting.
  • Tradecraft Repositories - Functions as a community-driven repository for adversary tradecraft and detection logic.
  • Detection Engineering Workflows - Implements a standardized workflow for planning and validating security detections using telemetry datasets.
  • Detection Logic Libraries - Provides a community-driven library of curated detection rules and hypotheses for identifying malicious behavior.
  • Detection Logic Verification - Includes a validation suite to test security hypotheses and analytics against pre-recorded telemetry datasets.
  • Interactive Threat Hunt Notebooks - Uses interactive notebooks to combine executable analytics with documentation for repeatable security hunting procedures.
  • Threat Hunting Workflows - Standardizes proactive processes for searching forensic data using custom detection logic and ordered hunting steps.
  • Hunt Blueprinting - Formalizes the planning phase of threat hunting by defining adversary tradecraft and telemetry requirements.
  • Hypothesis Validation Telemetry - Implements methods for validating threat hypotheses by matching expected event data against recorded security telemetry.
  • Security Detection Test Suites - Ships a validation suite for testing security hypotheses against recorded datasets to verify detection effectiveness.
  • Workflow Standard Templates - Provides structured templates that guide analysts through a consistent detection lifecycle from hypothesis to validation.
  • Detection Component Modeling - Provides a component-based modeling approach to decompose complex adversary behaviors into structured detection steps.
  • Detection Rules and Analytics - Community project for sharing detection logic and tradecraft.
  • Incident Response Playbooks - Structured playbooks for developing and executing threat hunting campaigns.
  • Incident Response Playbooks - Guides for developing threat hunting hypotheses and techniques.
  • Infrastructure and Network Security - Playbook for developing threat hunting techniques and hypotheses.
  • Security Tools - Listed in the “Security Tools” section of the Awesome Hacking awesome list.

Star history

Star history chart for otrf/threathunter-playbookStar history chart for otrf/threathunter-playbook

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does otrf/threathunter-playbook do?

ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to standardize the security detection lifecycle. It functions as a community-driven repository for adversary tradecraft and detection logic, using interactive notebooks to combine technical documentation with executable analytics.

What are the main features of otrf/threathunter-playbook?

The main features of otrf/threathunter-playbook are: Detection Engineering, Tradecraft Notebooks, Tradecraft Repositories, Detection Engineering Workflows, Detection Logic Libraries, Detection Logic Verification, Interactive Threat Hunt Notebooks, Threat Hunting Workflows.

Which projects share features with otrf/threathunter-playbook?

Projects with overlapping indexed features include: vvard0g/threathunter-playbook — ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed… cyb3rward0g/threathunter-playbook — ThreatHunter-Playbook is a structured framework for managing threat hunting playbooks, detection engineering… counteractive/incident-response-plan-template — A concise, directive, specific, flexible, and free incident response plan template. certsocietegenerale/irm — Incident Response Methodologies 2022. aws-samples/aws-incident-response-runbooks — These playbooks are provided as templates for organizations building incident response capability on AWS. They should… phantomcyber/playbooks — Phantom Community Playbooks.

Projects sharing features with ThreatHunter Playbook

These projects share indexed features with ThreatHunter Playbook. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • vvard0g/threathunter-playbookVVard0g avatar

    VVard0g/ThreatHunter-Playbook

    4,594View on GitHub↗

    ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed to inform threat hunt planning. It provides a security detection repository of validated queries and hypotheses, alongside an adversary tradecraft guide that details system behaviors and data sources associated with attacker techniques. The project focuses on the development of hunt blueprints and the standardization of detection logic. It integrates the MITRE ATT&CK framework to map detections and hypotheses to adversary tactics and techniques, ensuring coverage analysis is st

    Python
    View on GitHub↗4,594
  • cyb3rward0g/threathunter-playbookCyb3rWard0g avatar

    Cyb3rWard0g/ThreatHunter-Playbook

    4,594View on GitHub↗

    ThreatHunter-Playbook is a structured framework for managing threat hunting playbooks, detection engineering workflows, and adversary tradecraft modeling. It provides a system for organizing behavioral patterns and detection rules into tactical groups to develop security monitoring hypotheses. The project features an interactive security notebook environment that combines analytics and validation queries to test threat hypotheses against telemetry datasets. It includes a mapping tool for organizing these patterns based on the MITRE ATT&CK security framework. The framework covers the full thr

    Python
    View on GitHub↗4,594
  • certsocietegenerale/irmcertsocietegenerale avatar

    certsocietegenerale/IRM

    1,120View on GitHub↗

    Incident Response Methodologies 2022

    View on GitHub↗1,120
  • aws-samples/aws-incident-response-runbooksaws-samples avatar

    aws-samples/aws-incident-response-runbooks

    1,061View on GitHub↗

    These playbooks are provided as templates for organizations building incident response capability on AWS. They should be customized to suit your specific needs, risks, available tools, and work processes. These guides are not official AWS documentation and are provided as-is.

    View on GitHub↗1,061
  • Compare all 30 related projects→