A curated repository of incident response playbooks
☆138Jul 17, 2023Updated 3 years ago
Alternatives and similar repositories for awesome-playbooks
Users that are interested in awesome-playbooks are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Security Operations playbook to assist blue teamers from day-to-day tasks to Digital Forensics and Incident Response (DFIR) activities.☆30Aug 5, 2026Updated last month
- ☆203Mar 11, 2024Updated 2 years ago
- Cyber Incident Response Team Playbook Battle Cards☆435May 10, 2024Updated 2 years ago
- SOARCA - The Open Source CACAO-based Security Orchestrator!☆108Jul 21, 2026Updated 2 months ago
- This is a repository of vendor-agnostic workflows provided for those interested in deploying Security Orchestration, Automation, and Resp…☆97Mar 2, 2021Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Playbooks for SOC Analysts☆757Dec 11, 2022Updated 3 years ago
- Menu for Thor scanner lite☆20Oct 24, 2025Updated 10 months ago
- simple webapp for converting sigma rules into siem queries using the pySigma library☆50Sep 1, 2023Updated 3 years ago
- TheHiveIRPlaybook is a collection of TheHive case templates used for Incident Response☆13Jul 13, 2020Updated 6 years ago
- A preconfigured Velociraptor triage collector☆78Aug 10, 2026Updated last month
- Sightings Ecosystem gives cyber defenders visibility into what adversaries actually do in the wild. With your help, we are tracking MITRE…☆38May 28, 2025Updated last year
- A Python script for extracting IP addresses, URLs, headers, and attachments from .eml files. Additional functionalities include defanging…☆53Oct 10, 2024Updated last year
- GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]☆1,600Jul 28, 2024Updated 2 years ago
- SkillAegis is a platform to design, run, and monitor exercise scenarios, enhancing skills in applications like MISP and training users in…☆39Jul 20, 2026Updated 2 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Sigma is Generic Signature Format for SIEM Systems written by Florian Roth @Neo23x0 and Thomas Patzke. This repository is providing sprea…☆33Oct 16, 2019Updated 6 years ago
- Sample SecOps scripts and Utilities☆12Jun 19, 2024Updated 2 years ago
- Cyber Threats Detection Rules☆14Sep 16, 2025Updated last year
- Automate forensic traige package collection and evidence parsing with KAPE and Crowdstrike☆15Mar 5, 2022Updated 4 years ago
- Cyber | Cloud Security Checklist | Incident Response | Policy Template | Use cases☆13Nov 24, 2020Updated 5 years ago
- This project consists of an open source library allowing software to connect to data repositories using STIX Patterning, and return resul…☆265Jun 26, 2026Updated 2 months ago
- On-Premises Open Cyber Threat Intelligence Platform☆11Oct 29, 2024Updated last year
- A web application for generating, parsing and validating, manipulating, visualizing and executing CACAO v2.0 playbooks.☆43Jun 6, 2026Updated 3 months ago
- GenAI-STIX2.1-Generator is a tool that leverages Azure OpenAI capabilities to transform threat intelligence reports from unstructured web…☆24Mar 24, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆78Apr 3, 2025Updated last year
- SIEM USE Case Selection Methodology☆17Sep 18, 2020Updated 6 years ago
- We want to create a Repo which can provide different Malwares wrote by Python.☆27May 26, 2025Updated last year
- ⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident…☆536Jul 18, 2026Updated 2 months ago
- A repository for all resources related to malware analysis, reverse engineering, and system internals. This collection is tailored for pr…☆32Mar 14, 2026Updated 6 months ago
- Phantom Community Playbooks☆554Updated this week
- This is the repository for AI for SOC short video series☆19Sep 12, 2025Updated last year
- CRUSOE: A Toolset for Cyber Situational Awareness and Decision Support in Incident Handling Inspired by the OODA Loop☆15Dec 11, 2024Updated last year
- GoLang package for creating Mythic Payload Types, C2 Profiles, Translation Services, WebHook listeners, and Loggers☆25Updated this week
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆443May 21, 2026Updated 4 months ago
- Extracts IoCs, TTPs and the relationships between them. Outputs a STIX 2.1 bundle.☆85Updated this week
- Awesome Incident Response☆296Sep 27, 2025Updated 11 months ago
- 🛡️ SIGMA Detection Engineering Platform A comprehensive AI-powered detection engineering platform for security teams to explore MITRE AT…☆46Jun 28, 2025Updated last year
- Sigma detection rules for hunting with the threathunting-keywords project☆60Mar 2, 2025Updated last year
- Intel Retrieval Augmented Generation (RAG) Utilities☆91Jan 29, 2024Updated 2 years ago
- This project aims to compare and evaluate the telemetry of various EDR products.☆1,986Sep 2, 2026Updated 3 weeks ago