TheIRGurus / Playbooks
Playbooks designed for IBM SOAR developed by The IR Gurus. These playbooks can be used to demonstrate how to design playbooks, perform automations, and expand your SOP library within your environment.
☆14Updated 9 months ago
Alternatives and similar repositories for Playbooks:
Users that are interested in Playbooks are comparing it to the libraries listed below
- These workflows are provided for sample usage, new submissions and updates from the community, and are NOT supported by IBM.☆48Updated last month
- ☆58Updated last year
- Resilient Automation Functions and Scripts☆15Updated 3 years ago
- This repository bundles various utilities and scripts I built for use with IBM QRadar SIEM☆16Updated 3 months ago
- Pulls IOCs from MISP and adds the to reference sets in QRadar☆33Updated last year
- Source code for IBM SOAR Apps that are available on our App Exchange☆91Updated this week
- Repository for SPEED SIEM Use Case Framework☆53Updated 4 years ago
- ☆57Updated last year
- Unofficial third-party scripts, playbooks, and content for IBM QRadar & QRadar Community Edition.☆80Updated 6 months ago
- MISP to Sentinel integration☆62Updated 2 months ago
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆116Updated last year
- ☆26Updated 3 years ago
- The Project can be used to integrate QRadar with MISP Threat Sharing Platform☆38Updated 2 years ago
- SPL cheatsheet for Splunk.☆20Updated 2 years ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated last week
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆52Updated last year
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆55Updated 2 weeks ago
- ☆42Updated 2 years ago
- ☆5Updated 3 months ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- ☆14Updated 4 months ago
- This repository contains Splunk queries to hunt some anomalies☆38Updated 2 years ago
- ☆131Updated 11 months ago
- ☆72Updated 4 months ago
- The Infosec Community Definitive Guide to Jupyter Notebooks☆121Updated 4 years ago
- A guide to using Azure Data Explorer and KQL for DFIR☆102Updated 2 years ago
- A dataset containing Office 365 Unified Audit Logs for security research and detection☆50Updated 2 years ago
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆76Updated 9 months ago
- QRadar Export the rule set for printing☆22Updated 7 years ago
- Python Library for the IBM SOAR REST API, a Python SDK for developing Apps for IBM SOAR and more...☆41Updated 2 months ago