{"id":51952297,"url":"https://github.com/benjitrapp/incident-response-playbooks","last_synced_at":"2026-07-29T07:00:59.913Z","repository":{"id":361441619,"uuid":"1254384923","full_name":"BenjiTrapp/incident-response-playbooks","owner":"BenjiTrapp","description":null,"archived":false,"fork":false,"pushed_at":"2026-05-30T16:06:21.000Z","size":1887,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-30T18:06:12.823Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/BenjiTrapp.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-30T13:52:51.000Z","updated_at":"2026-05-30T16:06:24.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/BenjiTrapp/incident-response-playbooks","commit_stats":null,"previous_names":["benjitrapp/incident-response-playbooks"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/BenjiTrapp/incident-response-playbooks","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2Fincident-response-playbooks","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2Fincident-response-playbooks/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2Fincident-response-playbooks/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2Fincident-response-playbooks/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/BenjiTrapp","download_url":"https://codeload.github.com/BenjiTrapp/incident-response-playbooks/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BenjiTrapp%2Fincident-response-playbooks/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36022278,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-29T02:00:04.910Z","response_time":95,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-07-29T07:00:58.832Z","updated_at":"2026-07-29T07:00:59.905Z","avatar_url":"https://github.com/BenjiTrapp.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"raccoon-ir-logo.png\" alt=\"RaccoonIR\" width=\"300\"\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\u003cem\u003e// Purple Team Incident Response Playbook Planner\u003c/em\u003e\u003c/p\u003e\n\nA browser-based modelling tool for designing, analysing, and executing **operations-informed incident response playbooks** with full **MITRE ATT\u0026CK** and **D3FEND** mapping support. Built on the RaccoonIR metamodel (based on FRIPP, Shaked et al. 2023), combining PROVE artifact-centric process modelling with dependency models and CiO-based operational metrics.\n\n**Zero dependencies. Runs entirely in the browser. GitHub Pages compatible.**\n\n---\n\n## Features\n\n### Core Modelling\n- **Dependency Models** — hierarchical AND/OR/UNCONTROLLABLE paragon trees with probability propagation\n- **Playbook Editor** — hierarchical incident response process modelling with drill-down navigation\n- **Artifact Flow** — track evidence and data products through the playbook lifecycle\n- **Roles \u0026 Actuators** — assign human and machine resources to activities\n\n### Analysis \u0026 Simulation\n- **Impact View** — side-by-side playbook + DM with ActivityImpact arrows and step-through simulation\n- **Metrics Engine** — CiO (Change in Operations) computation with scope filtering\n- **Critical Thresholds** — stakeholder notification system with breach detection\n- **Snapshots** — capture and replay model state at any milestone\n\n### MITRE Integration\n- **MITRE ATT\u0026CK Mapping** — link playbook activities to ATT\u0026CK techniques (T-codes) with direct links\n- **MITRE D3FEND Mapping** — map defensive countermeasures to containment/eradication activities\n- **MITRE View** — dedicated tab showing all TTPs grouped by tactic with navigation to linked activities\n- **Paragon-level TTP display** — see which ATT\u0026CK/D3FEND techniques relate to each dependency model node\n\n### Additional\n- **Cross-DM References** — link paragons across multiple dependency models\n- **SYMBIOSIS Module** — GQM-based security measurement framework\n- **Example Library** — 13 real-world IR playbooks mapped to ATT\u0026CK + D3FEND\n\n---\n\n## Quick Start\n\n```bash\n# Serve locally (any static file server works)\npython -m http.server 8080\n# Open http://localhost:8080\n```\n\nOr deploy directly to **GitHub Pages** — no build step required.\n\n### First Steps\n\n1. Click **Library** in the toolbar to load an example playbook\n2. Switch between tabs: **Dependency Models**, **Playbooks**, **Impact View**, **MITRE View**\n3. Select any paragon or activity to see its properties, metrics, and MITRE mappings\n\n---\n\n## Example Playbooks\n\n| File | Scenario | ATT\u0026CK | D3FEND |\n|------|----------|--------|--------|\n| `phishing-t1566.json` | Phishing Attack Response | T1566, T1204, T1078 | D3-ER, D3-HD, D3-DNSDL, D3-UBA |\n| `ransomware-t1486.json` | Ransomware Incident Response | T1486, T1490, T1021, T1059, T1562 | D3-NI, D3-BAN, D3-FE, D3-SYSM |\n| `ransomware-pre-catch-t1486.json` | Ransomware Pre-Deployment Catch | T1486, T1566, T1071, T1219, T1547, T1053 | D3-NI, D3-MA, D3-DNSDL, D3-CR, D3-OTF, D3-EAL |\n| `ransomware-post-encryption-t1486.json` | Ransomware Post-Encryption Response | T1486, T1490, T1567, T1219, T1078, T1133 | D3-NI, D3-CR, D3-MFA, D3-EAL, D3-DNSDL, D3-NTA |\n| `password-spraying-t1110.json` | Password Spraying Attack | T1110.003, T1078, T1087, T1021 | D3-AL, D3-MFA, D3-AAORT, D3-CRED |\n| `process-injection-t1055.json` | Process Injection Response | T1055, T1059, T1003 | D3-PSA, D3-MA, D3-EAL, D3-DLIC |\n| `drive-by-compromise-t1189.json` | Drive-by Compromise Response | T1189, T1203, T1071, T1105 | D3-WF, D3-DNSDL, D3-BI, D3-UA |\n| `supply-chain-t1195.json` | Supply Chain Compromise Response | T1195, T1059, T1105 | D3-SV, D3-HV, D3-NTA |\n| `insider-threat-t1078.json` | Insider Threat Response | T1078, T1074, T1530 | D3-UBA, D3-AM, D3-SDA |\n| `data-exfiltration-t1041.json` | Data Exfiltration Response | T1041, T1560, T1048 | D3-NTA, D3-DLP, D3-OTF |\n| `credential-leakage-github-t1552.json` | Credential Leakage via Public GitHub Repository | T1552, T1078, T1213, T1021 | D3-CS, D3-OSM, D3-UGLPA, D3-CRO, D3-AL, D3-CH |\n| `infostealer-rat-t1555.json` | Infostealer with RAT on Developer Workstation | T1555, T1219, T1071, T1539, T1059 | D3-OSM, D3-NTCD, D3-PSA, D3-NI, D3-CRO, D3-EAL |\n| `ad-compromise-t1003.json` | Active Directory On-Premise Compromise | T1003, T1558, T1550, T1482, T1484 | D3-OSM, D3-NTCD, D3-NI, D3-AL, D3-CRO, D3-DAM |\n\n---\n\n## File Format\n\nProjects save as `.raccoon-ir.json` — a single JSON file containing both the information model and representation data (node positions, zoom levels).\n\nAdditionally supports importing:\n- `.raccoon` — SecMoF XML playbook format\n- `.dependencymodel` — SecMoF XML dependency model format\n\n---\n\n## Architecture\n\n```\nindex.html              App shell\ncss/raccoon-ir.css      Purple/dark theme\njs/\n  app.js                Main controller (RaccoonIRApp)\n  models.js             Data model factories \u0026 registry\n  dm-editor.js          SVG dependency model editor\n  pb-editor.js          SVG playbook process editor\n  impact-view.js        Impact simulation view\n  metrics.js            Probability \u0026 CiO computation\n  metamodel-data.js     RACCOON_METAMODEL constant\n  storage.js            Serialization \u0026 import/export\n  help.js               Tutorial \u0026 about content\nexamples/\n  manifest.json         Example library index\n  *.json                Pre-built playbooks\n```\n\n---\n\n## Metamodel\n\nRaccoonIR implements a metamodel combining four packages:\n\n| Package | Source | Purpose |\n|---------|--------|---------|\n| **DependencyModel** | Cherdantseva et al. 2022 | Hierarchical paragon trees with probability propagation |\n| **PROVE** | Shaked et al. 2022 (ICED21) | Artifact-centric process modelling |\n| **RaccoonIR** | Based on FRIPP (Shaked et al. 2023) | PlaybookProcess, ActivityImpact, CiO, MITRE mappings |\n| **SYMBIOSIS** | symbiosisDM.ecore | GQM security measurement framework |\n\n---\n\n## Academic References\n\n- Shaked et al. (2023). *Operations-informed incident response playbooks.* Computers \u0026 Security.\n- Shaked et al. (2022). *FRIPP — A metamodel for formalised response to incidents process playbooks.* ARES 2022.\n- Shaked et al. (2022). *PROVE Tool.* ICED21.\n- Cherdantseva et al. (2022). *SCADA Dependency Model.*\n\n---\n\n## License\n\nMIT\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbenjitrapp%2Fincident-response-playbooks","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbenjitrapp%2Fincident-response-playbooks","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbenjitrapp%2Fincident-response-playbooks/lists"}