TheIRGurus / PlaybooksLinks
Playbooks designed for IBM SOAR developed by The IR Gurus. These playbooks can be used to demonstrate how to design playbooks, perform automations, and expand your SOP library within your environment.
☆15Updated last year
Alternatives and similar repositories for Playbooks
Users that are interested in Playbooks are comparing it to the libraries listed below
Sorting:
- ☆58Updated 2 years ago
- ☆65Updated 2 years ago
- List of custom developed KQL queries to help proactive security teams hunt for opportunistic and sophisticated threat activity by develop…☆27Updated 4 years ago
- OSSEM Detection Model☆178Updated 2 years ago
- Source code for IBM SOAR Apps that are available on our App Exchange☆92Updated 3 weeks ago
- Example scripts and rules for use in Resilient playbooks.☆35Updated last year
- SIEGMA - Transform Sigma rules into SIEM consumables☆155Updated 6 months ago
- Real-time Response scripts and schema☆117Updated last year
- Repository for SPEED SIEM Use Case Framework☆55Updated 5 years ago
- Repository of public reference frameworks for the DFIR community.☆118Updated 2 years ago
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆208Updated 2 weeks ago
- Cybersecurity Incident Response Plan☆105Updated 4 years ago
- A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon☆209Updated 5 years ago
- A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.☆231Updated 5 months ago
- The Infosec Community Definitive Guide to Jupyter Notebooks☆125Updated 4 years ago
- Splunk code (SPL) for serious threat hunters and detection engineers.☆287Updated last year
- LogRhythm PowerShell Toolkit☆50Updated 3 weeks ago
- The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Of…☆262Updated 4 years ago
- ☆28Updated 5 months ago
- Reflex SOAR☆12Updated 3 years ago
- Repository of SentinelOne Deep Visibility queries.☆132Updated 4 years ago
- Tools for simulating threats☆193Updated last year
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆55Updated 2 years ago
- SentinelOne STAR Rules☆69Updated 7 months ago
- Dettectinator - The Python library to your DeTT&CT YAML files.☆116Updated 5 months ago
- Unofficial third-party scripts, playbooks, and content for IBM QRadar & QRadar Community Edition.☆83Updated 4 months ago
- ☆87Updated 6 months ago
- Pulls IOCs from MISP and adds the to reference sets in QRadar☆34Updated 2 years ago
- Notes on responding to security breaches relating to Azure AD☆116Updated 3 years ago
- PowerShell module for Office 365 and Azure log collection☆275Updated 2 weeks ago