TheIRGurus / Playbooks
Playbooks designed for IBM SOAR developed by The IR Gurus. These playbooks can be used to demonstrate how to design playbooks, perform automations, and expand your SOP library within your environment.
☆14Updated 8 months ago
Alternatives and similar repositories for Playbooks:
Users that are interested in Playbooks are comparing it to the libraries listed below
- ☆58Updated last year
- Pulls IOCs from MISP and adds the to reference sets in QRadar☆33Updated last year
- Practical Orientation Of MVISION EDR Query Language☆34Updated last year
- The Project can be used to integrate QRadar with MISP Threat Sharing Platform☆39Updated 2 years ago
- Source code for IBM SOAR Apps that are available on our App Exchange☆91Updated this week
- ☆53Updated last year
- ☆26Updated 3 years ago
- Repository for SPEED SIEM Use Case Framework☆52Updated 4 years ago
- Example scripts and rules for use in Resilient playbooks.☆34Updated last year
- Resilient Automation Functions and Scripts☆15Updated 3 years ago
- QRadar Export the rule set for printing☆22Updated 7 years ago
- Reflex SOAR☆12Updated 2 years ago
- ☆41Updated 4 years ago
- Incident response teams usually working on the offline data, collecting the evidence, then analyze the data☆44Updated 3 years ago
- ☆21Updated last year
- Unofficial third-party scripts, playbooks, and content for IBM QRadar & QRadar Community Edition.☆79Updated 5 months ago
- ☆42Updated 2 years ago
- ☆4Updated 2 months ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- ☆9Updated 3 years ago
- Convert Sigma rules to LogRhythm searches☆19Updated 2 years ago
- These workflows are provided for sample usage, new submissions and updates from the community, and are NOT supported by IBM.☆47Updated this week
- ☆91Updated 2 years ago
- 2021 SANS DFIR Summit: Greppin' Logs☆21Updated 3 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆146Updated last year
- Cybersecurity Incident Response Plan☆88Updated 4 years ago
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆55Updated last year
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆52Updated 2 months ago
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆115Updated last year