otrf/threathunter-playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 40 minutes ago
Type:Curated List / Learning ResourceCategory(s):OSINT & ReconnaissanceAppSec & Supply ChainSecurity & Privacy
Added to GitGenius on September 14th, 2026
Created on March 28th, 2017
Open Issues & Pull Requests: 6 (+0)
GitHub issues: Enabled
Number of forks: 865
Total Stargazers: 4,669 (+0)
Total Subscribers: 372 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 700.9 days
Mean response time: 700.9 days
90th percentile: 700.9 days
Tracked items: 1

Most active contributors

Sign in to see contributor activity.

Related repositories by overlapping contributors

No overlapping-contributor repos identified yet.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 2
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 921 days
Stale 30+ days: 2
Stale 90+ days: 1

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

No label distribution available yet.

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Threat Hunter Playbook is a community-driven collection of threat hunting documentation and executable resources that structures detection logic and adversary tradecraft around the MITRE ATT&CK framework.

The project addresses the challenge of making threat hunting repeatable and knowledge-transferable by documenting not just what hunters find, but how they think and reason through investigations. It captures this knowledge in interactive Jupyter notebooks that combine markdown explanations, analytics, datasets, and validation queries. Hunts are organized by MITRE ATT&CK tactics and techniques, allowing hunters to understand post-compromise behavior in a standardized way. The notebooks function as executable documents that can be run locally or remotely using pre-recorded security datasets and BinderHub, enabling validation and experimentation without requiring live environments.

The tool suits threat hunting teams and detection engineers who want to build institutional knowledge around hunt methodology and share findings across their organization or the broader community. It works well for teams that value structured, repeatable hunting processes grounded in adversary tradecraft rather than ad hoc investigation. The project is particularly useful for those seeking to accelerate hunt development by leveraging documented techniques and datasets that others have already validated. The playbook emphasizes a three-stage lifecycle—plan, execute, and report—that applies whether you are designing new hunts or learning from existing ones.

The project is actively evolving to incorporate AI-augmented workflows through Agent Skills, which capture hunting knowledge as explicit, structured workflows with templates and references rather than replacing existing practices. Development focuses on integrating generative AI capabilities across the planning, execution, and reporting stages while maintaining human oversight and decision-making authority. The codebase is maintained as a community-driven resource where threat hunters contribute documented hunts and supporting materials.