{"id":13539224,"url":"https://github.com/austinsonger/Incident-Playbook","last_synced_at":"2025-04-02T06:30:37.339Z","repository":{"id":39858837,"uuid":"367993839","full_name":"austinsonger/Incident-Playbook","owner":"austinsonger","description":"GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]","archived":false,"fork":false,"pushed_at":"2024-07-28T04:19:40.000Z","size":72655,"stargazers_count":1440,"open_issues_count":1,"forks_count":255,"subscribers_count":70,"default_branch":"main","last_synced_at":"2025-03-25T18:46:05.188Z","etag":null,"topics":["catalog","contributions-welcome","contributors-welcome","cybersecurity","cybersecurity-playbook","incident-management","incident-response","incidents","mitre","mitre-attack","playbook"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/austinsonger.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null},"funding":{"github":["austinsonger"]}},"created_at":"2021-05-16T22:02:51.000Z","updated_at":"2025-03-21T09:27:51.000Z","dependencies_parsed_at":"2024-07-28T05:24:40.678Z","dependency_job_id":"4d9b82d8-3e1a-43b5-a944-a25eb720eba2","html_url":"https://github.com/austinsonger/Incident-Playbook","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/austinsonger%2FIncident-Playbook","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/austinsonger%2FIncident-Playbook/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/austinsonger%2FIncident-Playbook/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/austinsonger%2FIncident-Playbook/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/austinsonger","download_url":"https://codeload.github.com/austinsonger/Incident-Playbook/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":246767540,"owners_count":20830508,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["catalog","contributions-welcome","contributors-welcome","cybersecurity","cybersecurity-playbook","incident-management","incident-response","incidents","mitre","mitre-attack","playbook"],"created_at":"2024-08-01T09:01:22.007Z","updated_at":"2025-04-02T06:30:35.771Z","avatar_url":"https://github.com/austinsonger.png","language":null,"funding_links":["https://github.com/sponsors/austinsonger"],"categories":["Nice to read","Others","cybersecurity","红队\u0026渗透测试"],"sub_categories":["Endpoints hardening:"],"readme":"\n[![Join the chat at https://gitter.im/Incident-Playbook/community](https://badges.gitter.im/Incident-Playbook/community.svg)](https://gitter.im/Incident-Playbook/community?utm_source=badge\u0026utm_medium=badge\u0026utm_campaign=pr-badge\u0026utm_content=badge)\n\n\nIf you have an idea for the project please start a [discusssion.](https://github.com/austinsonger/Incident-Playbook/discussions/new)\n\n![](https://i.imgur.com/DLj8Enw.png)\n\n### PURPOSE OF PROJECT\n\nThat this project will be created by the SOC/Incident Response Community\n\n- Develop a Catalog of Incident Response Playbook for every MITRE Technique (Keep in mind it won't work for some tactics). \n- Develop a Catalog of Incident Response Playbook for uncommon incidents.\n- Develop JSON Setup for Playbooks \n- Develop a Catalog of Exercise Scenarios that can be used for training purposes.\n- Develop a Catalog of tools used for Incident Response `[Plus Reviews for the different tools]`.\n- Develop a Catalog of Incident Response Automations. \n- Develop a Catalog of Checklists `[For Before, During, After Incidents]`. \n- Develop a Catalog of Roles that a organization can use, to build their own program.\n- Develop a Catalog of Event Codes and API Actions that you can/will see in a SIEM Detections.\n\u003c!-- - Develop a Card Game based on MITRE Attack and the IR phases that help resolve it. --\u003e\n- Develop a Battle Card Book, that can be reference for immediate help during a incident. \n\n###  MITRE ATTACK\n\n\n\n#### Tactic\n\n##### Intial Access\n\n- [X] [Playbook: T1133 - Unauthorized VPN and VDI Access](/Playbooks/MITRE-ATTACK/Initial%20Access/T1133-Unauthorized-VPN-and-VDI-Access.md)\n- [X] [Playbook: T1189 - Drive By Compromise](/Playbooks/MITRE-ATTACK/Initial%20Access/T1189-Drive-By-Compromise.md)\n- [X] [Playbook: T1566 - Phishing](/Playbooks/MITRE-ATTACK/Initial%20Access/T1566-Phishing-(T1566.001-T1566.002-T1566.003).md)\n\n##### Collection\n\n- [X] [Playbook: T1114 - Cloud Email Compromise](/Playbooks/MITRE-ATTACK/Collection/T1114-Cloud-Email-Compromise.md)\n\n##### Credential Access\n\n- [ ] [Playbook: T1110.003 - Password Spraying](/Playbooks/MITRE-ATTACK/Credential%20Access/T1110.003-Password%20Spraying.md)\n\n##### Defense Evasion\n\n- [X] [Playbook: T1055 - Process Injection](/Playbooks/MITRE-ATTACK/Defense%20Evasion/T1055-Process-Injection.md)\n\n##### Persistence\n\n- [X] [Playbook: T1053 - Scheduled Task/Job](/Playbooks/MITRE-ATTACK/Persistence/T1053-Scheduled-Task-Job.md)\n\n##### Exfiltration\n\n- [X] [Playbook: T1052.001 - Exfiltration over USB](/Playbooks/MITRE-ATTACK/Exfiltration/T1052.001%20-%20Exfiltration%20over%20USB.md)\n\n##### Impact\n\n- [ ] [Playbook: T1485 - Data Destruction](/Playbooks/MITRE-ATTACK/Impact/T1485-Data-Destruction.md)\n- [X] [Playbook: T1486 - Data Encrypted for Impact Ransomware](/Playbooks/MITRE-ATTACK/Impact/T1486-Data-Encrypted-for-Impact-Ransomware.md)\n- [ ] [Playbook: T1489 - Service Stop](/Playbooks/MITRE-ATTACK/Impact/T1489-Service-Stop.md)\n- [X] [Playbook: T1491.002 - External Defacement](/Playbooks/MITRE-ATTACK/Impact/T1491-Defacement-(T1491.001%2CT1491.002).md#playbook-external-defacement)\n\n\n\n---------------------\n**For every pull request submitted a issue must also be created.** \n- Please Read [Creating a New Playbook](https://github.com/austinsonger/Cyber-Incident-Response-Playbooks/wiki/Creating-a-New-Playbook);\n- Check the list of [MITRE Techniques](https://github.com/austinsonger/Cyber-Incident-Response-Playbooks/wiki/MITRE-Techniques) to choose from and create a new issue;\n- Or you can just look at the list of issues that are ready to be worked on.\n\n## Immediate Goals/Projects\n-  Figure out how to Integrate [Atomic Red Team](https://github.com/redcanaryco/atomic-red-team/)\n\n## Wiki\n- [Creating a Playbook](https://github.com/austinsonger/Incident-Playbook/wiki/Creating-a-New-Playbook)\n- [Combining Techniques Into One Playbook](https://github.com/austinsonger/Incident-Playbook/wiki/What-do-if-you-think-combining-techniques-into-one-playbook)\n- [Incident Response Phases](https://github.com/austinsonger/Incident-Playbook/wiki/Incident-Response-Phases)\n\n\n## Contributors\n\u003e Planning on Adding Photos later\n- [Dominik Sigl](https://github.com/sn0b4ll)\n\n## Sponsors\n\n|SPONSORS|\n|---|\n|   |\n|   |\n|   |\n\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faustinsonger%2FIncident-Playbook","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Faustinsonger%2FIncident-Playbook","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faustinsonger%2FIncident-Playbook/lists"}