Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Open reference library

Playbooks for the work in front of you.

Follow a practical path from first alert or hunt question to evidence, a decision and a handoff. 26 curated playbooks are readable without an account. Your ticks stay in this browser; you can copy the checklist or download JSON.

26 playbooks

SOC

Day-to-day triage and analyst handoffs

Detection engineering

Review rules, data, translations and tuning

Threat hunting

Turn hypotheses into evidence and detections

Alert response

Investigate what a detection says happened

Incident scenarios

Follow an incident across response families

These are general guides. Match investigation, escalation and disruptive actions to your organisation’s approved processes and available telemetry. Sources and scope are listed on each playbook.