-
Notifications
You must be signed in to change notification settings - Fork 3
Overview
Security Playbooks is a comprehensive collection of cybersecurity playbooks, MITRE ATT&CK–aligned attack scenarios, detection rules, threat‑hunting workflows, and incident‑response labs designed for SOC analysts, detection engineers, threat hunters, and cybersecurity learners.
This documentation provides an overview of the project structure, usage guidelines, and the purpose of each component within the repository.
Security Playbooks aims to:
- Provide structured, repeatable security playbooks
- Support MITRE ATT&CK–based analysis and detection
- Offer high‑quality Sigma, YARA, and Suricata rules
- Enable hands‑on threat‑hunting and IR practice
- Serve as a reference for detection engineering workflows
The repository is designed to be both educational and operational, supporting real‑world SOC environments as well as training labs.
/playbooks/ → MITRE ATT&CK–based security playbooks
/detection-rules/ → Sigma, YARA, Suricata detection rules
/labs/ → Incident response & threat‑hunting labs
/docs/ → Documentation files
/tools/ → Utility scripts and helper tools
/examples/ → Sample logs, datasets, and scenarios
Each directory includes its own README for easier navigation.
Step‑by‑step workflows for detection, investigation, and response.
Each playbook includes:
- MITRE ATT&CK mappings
- Required data sources
- Hunting queries
- Validation steps
A curated set of:
- Sigma rules
- YARA signatures
- Suricata IDS rules
All rules include descriptions, references, and ATT&CK technique IDs.
Hands‑on exercises covering:
- Log analysis
- Malware behavior
- Lateral movement
- Persistence detection
- Incident response workflows
Security Playbooks is ideal for:
- SOC Analysts
- Threat Hunters
- Incident Responders
- Detection Engineers
- Cybersecurity Students
- Blue/Red/Purple Teamers
Copyright © 2026 secwexen. Security Playbooks is licensed under the MIT License.
Maintained by Secwexen
GitHub Repository Source Code
Version: v0.2.1
This project is intended exclusively for authorized security validation, controlled research environments, and defensive analysis.
Any use of this project against systems without explicit written permission is strictly prohibited and may violate local, national, or international laws.
The maintainers and contributors assume no responsibility or liability for misuse, damages, or legal consequences resulting from unauthorized or improper deployment of this project.