This repo contains sample security playbooks for security automation, orchestration and response (SOAR). Each folder contains a security playbook ARM template that uses Microsoft Sentinel trigger. Instructions for deploying a custom template: After selecting a playbook, in the Azure portal: Search for deploy a custom template Click build your own template in the editor Paste the contents from the GitHub playbook Click Save Fill in needed data and click Purchase Once deployment is complete, you will need to authorize each connection. Click the Microsoft Sentinel connection resource Click edit API connection Click Authorize Click Save Repeat steps for other connections. For Azure Log Analytics Data Collector, you will need to add the workspace ID and Key. You can now edit the playbook in Logic apps. Instructions for templatizing a playbook: Option 1: Azure Logic App/Playbook ARM Template Generator Download tool and run the PowerShell script Extract the folder and open "Playbook_ARM_Template_Generator.ps1" either in Visual Studio Code/Windows PowerShell/PowerShell Core Note The script runs from the user's machine. You must allow PowerShell script execution. To do so, run the
FEATURES
ALTERNATIVES
PacBot is a platform for continuous compliance monitoring, compliance reporting, and security automation for the cloud, with a plugin-based data ingestion architecture.
A project that uses Athena and EventBridge to investigate API activity and notify of actions for incident response and misconfiguration detection.
A compilation of suggested tools for each component in a detection and response pipeline, with real-world examples, to design effective threat detection and response pipelines.
Repository of playbooks, scripts, and templates for automating and orchestrating Security Operations.
Incident response and case management solution for efficient incident response and management.
Incident response platform for automating alert handling and incident response procedures.
A defense-in-depth security automation and monitoring framework utilizing threat intelligence, machine learning, and serverless technologies.
Enhances Windows OS security through system modifications and settings adjustments.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.