This repository contains schema definitions for a DFIR (Digital Forensics Incident Response) Playbook based on YAML, providing written guidance for identifying, containing, eradicating, and recovering from cyber security incidents. The spec promises an open, semi/fully automated, and visible incident response process, allowing analysts to create, share, and contribute in the same language.

FEATURES

This tool is not verified yet and doesn't have listed features.

Did you submit the verified tool? Sign in to add features.

Are you the author? Claim the tool by clicking the icon above. After claiming, you can add features.

ALTERNATIVES

A Sysmon configuration file template with detailed explanations and tutorial-like features.

A framework for improving detection strategies and alert efficacy.

Incident response and digital forensics tool for transforming data sources and logs into graphs.

Fast Intercept is a security automation platform that empowers users to maximize their existing security products and automate routine tasks.

Scumblr is a web application for periodic syncs of data sources and security analysis to streamline proactive security.