Operational Security · Full Library

Security playbooks for modern operators.

Two field-ready collections from the GreyNOC detection-engineering team — eighteen detection & response playbooks spanning initial access to impact, and twenty covering the post-quantum / E2EE cryptographic transition and AI-system security — structured for operators responsible for detection, investigation, containment, and recovery.

Built for operators accountable for the outcome.

Every playbook follows the same 13-section format: overview, MITRE ATT&CK mapping, detection strategy, key indicators, sample logic, example data, investigation steps, false positives, tuning, response actions, escalation criteria, analyst-notes template, and summary.

Behavior over signature

Detections are framed by what the attacker actually does — fan-out, periodicity, sequence — not by IOCs that rotate.

Portable logic

Sample rules are JSON-shaped pseudocode, ready to translate to KQL, SPL, EQL, Sigma, or your platform of choice.

Operationally honest

False positives, tuning paths, and escalation criteria sit alongside the detection logic. Nothing ships without them.