Skip to content
Discussion options

You must be logged in to vote

The plays you would run in your environment will differ from the plays another person / org would run in their environment. We include a handful of detections from https://github.com/SigmaHQ/sigma that can be enabled / disabled at your discretion.

Here are some great free resources for you learn a bit more about playbook
https://www.youtube.com/watch?v=IS2SOlDedPc
https://docs.securityonion.net/en/2.3/playbook.html?highlight=playbook

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@bn641243
Comment options

Answer selected by bn641243
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants