Ross ROSS = Recommend OSS · open-source software intelligence for agents

OTRF/ThreatHunter-Playbook resource

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient. observed · 2026-08-28

github.com/OTRF/ThreatHunter-Playbook · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

60/100

  • Activity 61
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3445
  • days_rel: n/a
  • days_push: 234
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

4643 stars · 860 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A community-driven open-source collection of threat hunting playbooks documenting adversary tradecraft, detection logic, and hunt hypotheses organized by MITRE ATT&CK. Hunts are expressed as interactive Jupyter notebooks that can be executed against pre-recorded security datasets locally or via BinderHub.

Use cases

  • learn how to plan and execute threat hunts
  • find detection logic for specific MITRE ATT&CK techniques
  • practice threat hunting with pre-recorded security datasets
  • build hunt hypotheses based on adversary tradecraft
  • run interactive hunting notebooks in Jupyter or Binder
  • standardize threat hunting workflows across a security team

When to choose

  • you want structured, repeatable threat hunting methodology grounded in MITRE ATT&CK
  • you need executable hunt notebooks paired with sample security datasets for validation
  • you are building detection engineering or DFIR skills and want community-vetted tradecraft examples

When to avoid

  • you need a production SIEM or automated detection deployment tool rather than hunting documentation
  • you require real-time telemetry collection or alerting, which this project does not provide

Facets

learning-resource · maturity active

security documentation analytics security developer-tools tutorials python cross-platform threat-hunting mitre-attack dfir sysmon jupyter-notebooks detection-engineering security-datasets

1 source

Member repositories

RepositoryRoleHealth v2
OTRF/ThreatHunter-Playbookmain60

For agents

markdown · JSON · MCP: product_card(name="OTRF/ThreatHunter-Playbook")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem