SOaC Packages

Each package bundles detections, playbooks, policies, and lab scenarios for a specific threat domain. All code is free on GitHub. Downloads are for convenience and lab integration.

How packages map to GitHub: The GitHub repository is the source of truth for all SOaC artifacts. This portal mirrors the packages for discovery, lab demos, and gated convenience downloads. Every package card links directly to its source in the repo.

Identity-led Intrusion Defense

pkg-001

Detect and contain AitM phishing, session hijacking, and identity-based attacks across Okta, Entra ID, and Azure AD.

T1557.001T1078.004T1539CISODetection EngSOC / IR
\u2713 4 detection rules (SPL + KQL)\u2713 2 CLAW playbooks\u2713 1 lab scenario\u2713 MITRE ATT&CK mapping

Ransomware Containment & Response

pkg-002

Automated host isolation, process killing, forensic snapshot capture, and SOC notification for ransomware events.

T1486T1059T1068T1490SOC / IRDetection EngPlatform
\u2713 3 detection rules\u2713 2 CLAW playbooks\u2713 1 lab scenario\u2713 Forensic evidence templates

Supply Chain & npm Compromise

pkg-003

Detect and respond to malicious npm packages, dependency confusion, and software supply chain attacks like Shai-Hulud.

T1195.002T1059.007T1027Detection EngPlatform
\u2713 3 detection rules\u2713 1 CLAW playbook\u2713 1 lab scenario\u2713 npm audit integration

BYOVD & Kernel Exploit Defense

pkg-004

Detect Bring Your Own Vulnerable Driver attacks and kernel-level exploitation used by advanced ransomware operators.

T1068T1014T1547.006Detection EngSOC / IRPlatform
\u2713 2 detection rules\u2713 1 CLAW playbook\u2713 1 lab scenario\u2713 Driver allowlist template

SEO Poisoning & Gootloader Defense

pkg-005

Detect and contain SEO poisoning campaigns and Gootloader malware delivery via compromised websites.

T1189T1059.007T1071.001Detection EngSOC / IR
\u2713 3 detection rules\u2713 1 CLAW playbook\u2713 1 lab scenario\u2713 IOC feed integration