{"adoption": {"forks": 290, "observed_at": "2026-08-28T04:05:08.605203+00:00", "stars": 1591}, "canonical_url": "https://ross.abutalabs.com/products/incident-playbook", "card": {"archived": false, "artifact_type": "learning-resource", "description": "GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]", "domain": ["security", "developer-tools"], "enriched": true, "function": ["documentation", "security"], "health_score": 20, "homepage": null, "language": null, "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["austinsonger/Incident-Playbook"], "name": "austinsonger/Incident-Playbook", "platform": ["cross-platform"], "pushed_at": "2024-07-28T04:19:40+00:00", "repo": "austinsonger/Incident-Playbook", "stars": 1591, "tags": ["incident-response", "mitre-attack", "playbooks", "soc", "cybersecurity", "checklists", "battle-cards"], "topics": ["cybersecurity", "playbook", "cybersecurity-playbook", "incident-response", "incident-management", "incidents", "mitre-attack", "mitre", "contributions-welcome", "contributors-welcome", "catalog"], "urls": [], "use_cases": ["find an incident response playbook for a MITRE technique like phishing or ransomware", "build an incident response program with roles and checklists", "prepare tabletop exercise scenarios for SOC training", "reference battle cards during an active security incident", "catalog SIEM event codes and detection actions"], "what_it_is": "A community-driven catalog of incident response playbooks mapped to MITRE ATT&CK tactics and techniques, along with checklists, exercise scenarios, tool reviews, and role definitions for SOC teams. It is a documentation/resource collection rather than executable software.", "when_to_avoid": ["you need executable tooling or automation code rather than documentation", "you require complete coverage of every MITRE technique (catalog is partial)", "you need vendor-specific or compliance-certified IR procedures"], "when_to_choose": ["you need ready-made IR playbooks aligned to MITRE ATT&CK", "you are building or maturing a SOC incident response program", "you want community-contributed training and exercise scenarios"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/incident-playbook", "repo": "austinsonger/Incident-Playbook", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:08.605203+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:54:43.758259+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "25f1164580717edd5e9afa1aafa4a853cb49e820af24aba16bec5bcd20acc18e", "fetched_at": "2026-08-28T04:05:08.605203+00:00", "kind": "readme", "missing": false, "url": "https://github.com/austinsonger/Incident-Playbook"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1935, "days_push": 766, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}