{"adoption": {"forks": 860, "observed_at": "2026-08-28T04:08:55.511613+00:00", "stars": 4643}, "canonical_url": "https://ross.abutalabs.com/products/threathunter-playbook", "card": {"archived": false, "artifact_type": "learning-resource", "description": "A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.", "domain": ["security", "developer-tools", "tutorials"], "enriched": true, "function": ["security", "documentation", "analytics"], "health_score": 57, "homepage": null, "language": "Python", "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["OTRF/ThreatHunter-Playbook"], "name": "OTRF/ThreatHunter-Playbook", "platform": ["python", "cross-platform"], "pushed_at": "2026-01-12T00:17:37+00:00", "repo": "OTRF/ThreatHunter-Playbook", "stars": 4643, "tags": ["threat-hunting", "mitre-attack", "dfir", "sysmon", "jupyter-notebooks", "detection-engineering", "security-datasets"], "topics": ["threat-hunting", "sysmon", "hunting-campaigns", "hypothesis", "hunting", "dfir", "hunter", "mitre-attack-db", "mitre"], "urls": [], "use_cases": ["learn how to plan and execute threat hunts", "find detection logic for specific MITRE ATT&CK techniques", "practice threat hunting with pre-recorded security datasets", "build hunt hypotheses based on adversary tradecraft", "run interactive hunting notebooks in Jupyter or Binder", "standardize threat hunting workflows across a security team"], "what_it_is": "A community-driven open-source collection of threat hunting playbooks documenting adversary tradecraft, detection logic, and hunt hypotheses organized by MITRE ATT&CK. Hunts are expressed as interactive Jupyter notebooks that can be executed against pre-recorded security datasets locally or via BinderHub.", "when_to_avoid": ["you need a production SIEM or automated detection deployment tool rather than hunting documentation", "you require real-time telemetry collection or alerting, which this project does not provide"], "when_to_choose": ["you want structured, repeatable threat hunting methodology grounded in MITRE ATT&CK", "you need executable hunt notebooks paired with sample security datasets for validation", "you are building detection engineering or DFIR skills and want community-vetted tradecraft examples"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/threathunter-playbook", "repo": "OTRF/ThreatHunter-Playbook", "role": "main", "score": 60}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:08:55.511613+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T18:19:32.897356+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "7c0da53e207865f6f5a6b16b9a16429bc39f2b88efa6d39c9cdff2d06acaaf96", "fetched_at": "2026-08-28T04:08:55.511613+00:00", "kind": "readme", "missing": false, "url": "https://github.com/OTRF/ThreatHunter-Playbook"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 61, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3445, "days_push": 234, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 60, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}