Cymph Logo

Cymph

0
Commercial
Visit Website

Cymph is a playbook management platform designed for cybersecurity and privacy operations that enables teams to create, manage, and share security playbooks. The platform features a no-code playbook editor that allows users to build and customize security procedures without requiring programming knowledge. It includes a knowledge management system for centralized storage and organization of playbooks, making them easily retrievable through search functionality. The system maintains a library of approximately 200 pre-existing playbooks sourced from public repositories that can serve as templates or reference material. These playbooks are based on open standards to ensure interoperability across different security tools and platforms. Key functionalities include: - Playbook creation through a visual studio interface - Centralized playbook storage and organization - Search capabilities for quick playbook retrieval - Permission-based sharing controls for collaboration - Integration with SOARCA and StackStorm (enterprise version) - Template library access for reference and customization The platform supports both cloud-based deployment and on-premises installation for enterprise users, with different tiers of access based on subscription level.

FEATURES

Playbook sharing

No-code playbook editor

Based on CACAO open standard

Integration with StackStorm for executing playbooks

Commenting

Versioning

Revocation and marking as draft

Role-based access control

ALTERNATIVES

Detailed analysis of the event-stream incident and actions taken by npm Security.

Dispatch helps manage security incidents by integrating with existing tools and automating incident response tasks.

A report on detecting lateral movement through tracking event logs, updated to include analysis of various tools and commands used by attackers.

A set of scripts for collecting forensic data from Windows and Unix systems respecting the order of volatility.

DFIRTrack is an open source web application focused on incident response for handling major incidents with many affected systems, tracking system status, tasks, and artifacts.

Automated Digital Forensics and Incident Response (DFIR) software for rapid incident response and intrusion investigations.

An open-source, drag-and-drop security workflow builder with integrated case management for automating security workflows and tackling alert fatigue.

Tool to bypass endpoint solutions blocking known 'malicious' signed applications by obtaining valid signed files with different hashes.

PINNED