The Splunk SOAR Community Playbooks repository contains default initial playbooks and custom functions for each Splunk SOAR instance, with content migration to Splunk's GitHub in progress. External submissions are paused until migration completion to ensure no content interruption for Splunk SOAR customers. The platform automatically links to the branch matching the running Splunk SOAR version.
FEATURES
SIMILAR TOOLS
A collection of incident response methodologies for various security incidents, providing easy-to-use operational best practices.
DFIRTrack is an open source web application focused on incident response for handling major incidents with many affected systems, tracking system status, tasks, and artifacts.
A DFIR Playbook Spec based on YAML for collaborative incident response processes.
A project that uses Athena and EventBridge to investigate API activity and notify of actions for incident response and misconfiguration detection.
Fast Intercept is a security automation platform that empowers users to maximize their existing security products and automate routine tasks.
Templates for incident response run-books tailored for AWS environments based on NIST guidelines.
A Sysmon configuration file template with detailed explanations and tutorial-like features.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.