This repo contains sample security playbooks for security automation, orchestration and response (SOAR). Each folder contains a security playbook ARM template that uses Microsoft Sentinel trigger. Instructions for deploying a custom template: After selecting a playbook, in the Azure portal: Search for deploy a custom template Click build your own template in the editor Paste the contents from the GitHub playbook Click Save Fill in needed data and click Purchase Once deployment is complete, you will need to authorize each connection. Click the Microsoft Sentinel connection resource Click edit API connection Click Authorize Click Save Repeat steps for other connections. For Azure Log Analytics Data Collector, you will need to add the workspace ID and Key. You can now edit the playbook in Logic apps. Instructions for templatizing a playbook: Option 1: Azure Logic App/Playbook ARM Template Generator Download tool and run the PowerShell script Extract the folder and open "Playbook_ARM_Template_Generator.ps1" either in Visual Studio Code/Windows PowerShell/PowerShell Core Note The script runs from the user's machine. You must allow PowerShell script execution. To do so, run the
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A web collaborative platform for incident responders to share technical details during investigations, shipped in Docker containers for easy installation and upgrades.
Tool to bypass endpoint solutions blocking known 'malicious' signed applications by obtaining valid signed files with different hashes.
A security analytics platform that integrates with Google Chronicle to deliver Autonomic Security Operations through data engineering, detection engineering, and response engineering.
A Live Response collection script for Incident Response that automates the collection of artifacts from various Unix-like operating systems.
A proof of concept for using the SSM Agent in Fargate for incident response
A comprehensive auditd configuration for Linux systems following best practices.
A module-based AWS response tool for incident response in AWS environments.
An AI-powered SOC automation platform that performs autonomous alert triage, investigation, and incident response while augmenting human analyst capabilities.
A standardized framework for describing and classifying cybersecurity incidents
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.