Incident-Playbook
GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]
파일 탐색기
최종 버전 다운로드 (.zip)- incident-response-process-suggestion.md
- new-playbook.md
- playbook-tuning.md
- question.md
- codespell.yml
- gitlabsync.yml
- FUNDING.yml
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- T1486-Ransomware.md
- A research finding has gone outside of our disclosure process.md
- An adversary has bypassed our rate limiting capability.md
- An adversary has exploited an indirect object reference vulnerability.md
- An adversary has queried our database directly through our application.md
- An adversary has remotely executed code through our application.md
- An XSS vulnerability has been used against another user on our application.md
- Credentials are exposed to an adversary.md
- Payment instruments are exposed to an adversary.md
- AWS - An adversary has gained access to our AWS account.md
- AWS - An IAM secret key has exposed to the internet.md
- AWS - An S3 bucket has exposed to the internet.md
- AWS - CloudTrail logs have been deleted or modified.md
- AWS - Security groups and ACL's have exposed a high risk server.md
- An adversary has elevated privilege on an endpoint.md
- An adversary has exploited unpatched software on an endpoint.md
- An adversary has implanted malware on an endpoint.md
- An adversary has moved laterally in the environment.md
- Endpoint malware is remotely beaconing to a C2.md
- An incident has sustained for more than two days.md
- IT - An employee was not off-boarded correctly.md
- IT - A social engineer has received sensitive documents data.md
- IT - An employee laptop has been stolen and was not encrypted.md
- IT - An employee's email has been accessed by an outsider.md
- IT - Employee communications were compromised.md
- IT - Internal documentation has been exposed to, and indexed by, a search engine.md
- IT - Removable storage containing sensitive data has been lost.md
- IT - We have opened an incident to deal with a vendor compromise.md
- Company property over $X has been lost.md
- README.md
- Active Directory.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- 365-1.0_Account-Authorization.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.MD
- README.md
- Network.md
- README.md
- After Action Review (AAR).md
- README.md
- Host-Based Artifacts.md
- Information to Review for Host Analysis.md
- Network-Based Artifacts.md
- Account Takeover (ATO) Checklist.md
- Best Practices Prior to an Incident.md
- Log Review Checklist for Security Incidents.md
- Mitigations.md
- Analyze Evidence.md
- Collect Evidence.md
- Collect Leads.md
- Create and Deploy Indicators of Compromise (IOCs).md
- create-incident-file.md
- Investigation Plan.md
- README.md
- Update Investigative Plan and Incident File.md
- README.md
- Update Remediation Plan.md
- Communicate Externally.md
- Communicate Internally.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- Common Mistakes in Incident Handling.md
- Incident-Metrics.md
- Incident-Tracking.md
- PE01 - Cyber Security User Awareness.md
- PE02 - Set Up Data Collection.md
- PE03 - Set up a centralized long-term log storage.md
- PE04 - Develop a communication map.md
- PE05 - Make sure there are both online and offline backups.md
- PE06 - Get network architecture map.md
- PE07 - Get Access Control Matrix.md
- PE08 - Develop assets knowledge base.md
- PE09 - Toolset for analysis and management.md
- PE10 - Access vulnerability management system logs.md
- PE11 - Connect with trusted communities for information exchange.md
- PE12 - Able to Acquire external Network Flow logs.md
- PE13 - Able to Acquire internal Network Flow logs.md
- PE14 - Able to Acquire external Network Flow logs.md
- PE15 - Able to Acquire internal Network Flow logs.md
- PE16 - Able to Acquire internal HTTP logs.md
- PE17 - Able to Acquire external HTTP logs.md
- PE17 - Able to Acquire internal DNS logs.md
- PE18 - Able to Acquire external DNS logs.md
- PE19 - Able to Acquire VPN logs.md
- PE20 - Able to Acquire DHCP logs.md
- PE21 - Able to Acquire internal Packet Capture data.md
- PE22 - Able to Acquire internal Packet Capture data.md
- PE23 - Ability to block an external IP address from being accessed by corporate assets.md
- PE24 - Ability to block an internal IP address from being accessed by corporate assets.md
- PE25 - Ability to block an external domain name from being accessed by corporate assets.md
- PE26 - Ability to block an internal domain name from being accessed by corporate assets.md
- PE27 - Ability to block an external URL from being accessed by corporate assets.md
- PE28 - Ability to block an internal URL from being accessed by corporate assets.md
- PE29 - Ability to block a network port for external communications.md
- PE30 - Ability to block a network port for internal communications.md
- PE31 - Ability to block a user for external communications.md
- PE32 - Ability to block a user for internal communications.md
- PE33 - Ability to find data transferred at a particular time in the past by its content pattern.md
- PE34 - Ability to block data transferring by its content pattern.md
- PE35 - Ability to list the data that is being transferred at the moment or at a particular time in the past.md
- PE36 - Ability to collect the data that is being transferred at the moment or at a particular time in the past.md
- PE37 - Ability to identify the data that is being transferred at the moment or at a particular time in the past.md
- PE38 - Ability to find the data that is being transferred at the moment or at a particular time in the past by its content pattern.md
- PE39 - Ability to analyse an User-Agent request header.md
- PE40 - Ability to list firewall rules.md
- PE41 - Ability to list users who opened a particular email message.md
- PE42 - Ability to list receivers of a particular email message.md
- PE43 - Ability to block an email domain.md
- PE44 - Ability to block an email sender.md
- PE45 - Ability to delete an email message.md
- PE46 - Ability to quarantine an email message.md
- PE47 - Ability to collect an email message.md
- PE48 - Ability to analyse an email address.md
- PE49 - Ability to list files that have been modified at a particular time in the past.md
- PE50 - Ability to list files that have been deleted at a particular time in the past.md
- PE51 - Ability to list files that have been downloaded from the internet at a particular time in the past.md
- PE52 - Ability to list files with a tampered timestamp.md
- PE53 - Ability to find a file by its path.md
- PE54 - Ability to find file by its metadata.md
- PE55 - Ability to find a file by its hash.md
- PE56 - Ability to find a file by its format.md
- PE57 - Ability to find a file by its content pattern.md
- PE58 - Ability to quarantine file by path.md
- PE59 - Ability to quarantine file by hash.md
- PE60 - Ability to quarantine file by format.md
- PE61 - Ability to quarantine file by content pattern.md
- PE62 - Ability to remove file.md
- PE63 - Ability to to analyse file hash.md
- PE64 - Ability to analyse Windows PE.md
- PE65 - Ability to analyse macOS Mach-O file.md
- PE66 - Ability to analyse Unix Elf.md
- PE67 - Ability to Analyse MS Office File.md
- PE68 - Ability to Analyse PDF File.md
- PE69 - Ability to Analyse Script.md
- PE70 - Ability to Analyse Jar.md
- PE71 - Able to Find Process by Executable Path, Metadata,Hash, Format, Content Pattern.md
- PE72 - Able to Block by Executable Path, Metadata,Hash, Format, Content Pattern.md
- PE73 - Able to List Registry Keys Modified.md
- PE74 - Able to List Registry Keys Deleted.md
- PE75 - Able to List Registry Keys Accessed.md
- PE76 - Able to List Registry Keys Created.md
- PE77 - Able to List Services Created.md
- PE78 - Able to List Services Modified.md
- PE79 - Able to List Services Deleted.md
- PE80 - Able to Remove Registry Keys.md
- PE81 - Able to Remove Service.md
- PE82 - Able to Analyse Registry Keys.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- README.md
- 0Day-vulnerability.md
- IAM.md
- Information-Leakage.md
- Insider-Abuse.md
- Linux-Intrusion-Detection.md
- Malicious-Network-Behaviour.md
- Malware.md
- Windows-Intrusion-Detection.md
- README.md
- T1114-Cloud-Email-Compromise.md
- README.md
- README.md
- T1110.003-Password Spraying.md
- README.md
- T1055-Process-Injection.md
- README.md
- T1059 - Command and Scripting Interpreter.md
- T1059.001 - PowerShell.md
- README.md
- T1011 - Exfiltration Over Other Network Medium (T1011.001).md
- T1020 - Automated Exfiltration (T1020.001).md
- T1029 - Scheduled Transfer.md
- T1030 - Data Transfer Size Limits.md
- T1041 - Exfiltration Over C2 Channel.md
- T1048 - Exfiltration Over Alternative Protocol-(T1048.001.T1048.002,T1048.003).md
- T1052 - Exfiltration Over Physical Medium.md
- T1052.001 - Exfiltration over USB.md
- T1537 - Transfer Data to Cloud Account.md
- T1567 - Exfiltration Over Web Service.md
- T1567.001 - Exfiltration to Code Repository.md
- T1567.002 - Exfiltration to Cloud Storage.md
- README.md
- T1485-Data-Destruction.md
- T1486-Data-Encrypted-for-Impact-Ransomware.md
- T1489-Service-Stop.md
- T1490-Inhibit-System-Recovery.md
- T1491-Defacement-(T1491.001,T1491.002).md
- T1495-Firmware-Corruption.md
- T1496-Resource-Hijacking.md
- T1498-Network-Denial-of-Service-(T4198.001,T1498.002)).md
- T1499-Endpoint-Denial-of-Service-(T1499.001,T1499.002,T1499.003,T1499.004).md
- T1529-System-Shutdown-Reboot.md
- T1531-Account-Access-Removal.md
- T1561-Disk-Wipe-(T1561.001,T1561.002).md
- T1565-Data-Manipulation-(T1565.001,T1565.002,T1565.003).md
- README.md
- T1133-Unauthorized-VPN-and-VDI-Access.md
- T1189-Drive-By-Compromise.md
- T1566-Phishing-(T1566.001-T1566.002-T1566.003).md
- README.md
- T1550.002-Lateral Movement - Pass the Hash.md
- README.md
- T1053-Scheduled-Task-Job.md
- T1505.003-Web-shells.md
- README.md
- T1134-Access-Token-Manipulation.md
- T1484.001-Group-Policy-Modification.md
- T1548-Abuse-Elevation-Control-Mechanism.md
- T1548.001-Setuid-and-Setgid.md
- T1548.002-Bypass-User-Account-Control.md
- T1548.003-Sudo-and-Sudo-Caching.md
- T1548.004-Elevated-Execution-with-Prompt.md
- README.md
- cloudtrail.md
- README.md
- Microsoft Authorization API.md
- README.md
- ASA.md
- README.md
- README.md
- Linux-Events.md
- Linux-Field-Dictionary.md
- Linux-Message-Dictionary.md
- README.md
- SysmonForLinux.md
- Library Directory Structure.md
- Private Directory Structure.md
- README.md
- System Directory Structure.md
- Usr Directory Structure.md
- README.md
- README.md
- README.md
- README.md
- README.md
- principalappid.md
- README.md
- README.md
- README.md
- README.md
- Domain-Event-Codes.md
- Login-Types.md
- README.md
- README.MD
- README.md
- attack_events_mapping.csv
- AUTORUNS.md
- Event-Codes.md
- NTSTATUS.md
- PermsFlags.md
- set-audit-information.md
- SID.md
- Status-Codes.md
- WindowsAccountSID.md
- ServicePorts.md
- TCP-Flags.md
- README.md
- Alarm Drives Decision.png
- Review Data Sources.png
- SOC.png
- README.md
- Alarm-Types.md
- README.md
- 4624_4625.TH.mmap.png
- 4648.TH.mmap.png
- 5143_susp_NewSD_values.png
- 5145.TH.mmap.png
- avivore.th.map.png
- Gamaredon.png
- Hunting_Security_Log.png
- MM_WinEoP_PrivManips.png
- OilRig_TH.map.png
- README.md
- sednit_apt28.map.png
- STasks_MM_4698_4702.map.png
- sysmon_10_calltrace_howto_read.png
- Sysmon_KernelMode_Telemetry_MindMap_v1.0.png
- ta505_th.map.png
- Windows Processes TH.map.png
- Windows.Services.TH.map.png
- README.md
- Action-Template.md
- ADS-Framework.md
- Discovering-Risks.md
- Incident Management Flowchart for JIRA.png
- LICENSE
- Mitigation-Categories.md
- Playbook-Template.md
- README.md
- Response_template.yaml
- Responses.md
- Threat_Catalogue.md
- TO-DO.md
// repository documentation
Was this content helpful?
(0 ratings)
