Cyber Incident Response Playbook Battle Cards Logo

Cyber Incident Response Playbook Battle Cards

0
Free
Visit Website

A collection of Cyber Incident Response Playbook Battle Cards (PBC) which are recipes for preparing and applying countermeasures against cyber threats and attacks. PBC follow a prescriptive approach to combat various TTP deployed by cyber threat actors, aiding the kinetic activities conducted by humans prior to, during, and after cybersecurity incident response. Inspired by CERT Societe Generale's IRM, these cards are valuable resources for incident response teams. For more information, visit: - CERT Societe Generale's IRM: https://github.com/certsocietegenerale/IRM/ - GuardSight's Cybersecurity Incident Response Plan: https://github.com/guardsight/gsvsoc_cybersecurity-incident-response-plan - Incident Response Playbooks: https://www.incidentresponse.com/playbooks/ - NIST Cybersecurity Framework: https://www.nist.gov/cyberframework - NIST Special Publication 800-184: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-184.pdf - NIST Special Publication 800-61 Rev. 2: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final - MITRE Cyber Exercise Playbook: https://www.mitre.org/sites/default/files/publications/pr_14-3929-cyber-exercise-playbook.pdf

FEATURES

ALTERNATIVES

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

A Live Response collection script for Incident Response that automates the collection of artifacts from various Unix-like operating systems.

An AI-powered SOC automation platform that performs autonomous alert triage, investigation, and incident response while augmenting human analyst capabilities.

TheHive is a case management platform for security operations teams that facilitates incident response, threat analysis, and team collaboration.

Malware allows attackers to execute Windows commands from a remote environment

A Security Orchestration, Automation and Response (SOAR) platform for incident response and threat hunting.

A compilation of suggested tools for each component in a detection and response pipeline, with real-world examples, to design effective threat detection and response pipelines.

A public incident response process documentation used at PagerDuty