If you have an idea for the project please start a discusssion.
That this project will be created by the SOC/Incident Response Community
[Plus Reviews for the different tools]
.[For Before, During, After Incidents]
.For every pull request submitted a issue must also be created.
This project will use a modified Incident Response Process of mixing SANS Incident Response Process and NIST Incident Response Process.
NOTE: The common “preparation” phase will not be part of this Incident Response Process, but on each playbook will include a
(P) Preparation
at the beginning of each playbook.
More than one phase can be running in parallel.
If you have any changes that you think would be good for this incident response process please create a issue description what you want to change to this incident response process.
Just felt like there was something missing for Incident Response and a centrally place for playbooks, SIEM Processes, Forensics and other processes around Incident Response.