Build incident response timelines and report packs from event logs. Use for detection-to-recovery reporting, phase tracking, and stakeholder-ready incident s...
从事件日志构建事件响应时间线和报告包,用于检测到恢复的报告、阶段跟踪以及面向利益相关者的汇报。
0x-professor
开发者工具clawhubv0.1.01 版本100000Key: 无需
★ 0
Stars
📥 610
下载
💾 8
安装
1
版本
#latest
概述
Cyber IR Playbook
Overview
Convert incident events into a standardized response timeline and phase-based report.
Workflow
Ingest incident events with timestamps.
Classify events into detection, containment, eradication, recovery, or post-incident phases.
Build ordered timeline and summarize current phase completion.
Produce a report artifact for internal and executive audiences.
Use Bundled Resources
Run scripts/ir_timeline_report.py to generate a deterministic timeline report.
Read references/ir-phase-guide.md for phase mapping guidance.
Guardrails
Focus on defensive incident handling and post-incident learning.
Do not provide offensive exploitation instructions.