Ross ROSS = Recommend OSS · open-source software intelligence for agents

austinsonger/Incident-Playbook resource

GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly] observed · 2026-08-28

github.com/austinsonger/Incident-Playbook · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1935
  • days_rel: n/a
  • days_push: 766
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1591 stars · 290 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A community-driven catalog of incident response playbooks mapped to MITRE ATT&CK tactics and techniques, along with checklists, exercise scenarios, tool reviews, and role definitions for SOC teams. It is a documentation/resource collection rather than executable software.

Use cases

  • find an incident response playbook for a MITRE technique like phishing or ransomware
  • build an incident response program with roles and checklists
  • prepare tabletop exercise scenarios for SOC training
  • reference battle cards during an active security incident
  • catalog SIEM event codes and detection actions

When to choose

  • you need ready-made IR playbooks aligned to MITRE ATT&CK
  • you are building or maturing a SOC incident response program
  • you want community-contributed training and exercise scenarios

When to avoid

  • you need executable tooling or automation code rather than documentation
  • you require complete coverage of every MITRE technique (catalog is partial)
  • you need vendor-specific or compliance-certified IR procedures

Facets

learning-resource · maturity active

documentation security security developer-tools cross-platform incident-response mitre-attack playbooks soc cybersecurity checklists battle-cards

1 source

Member repositories

RepositoryRoleHealth v2
austinsonger/Incident-Playbookmain32

For agents

markdown · JSON · MCP: product_card(name="austinsonger/Incident-Playbook")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem