Objective
Document the content conventions required for playbook entries that should import cleanly into DetLab-DAC.
Rationale
The playbook is most valuable when it complements DetLab-DAC instead of becoming a disconnected markdown dump. Clear conventions will help future detections, hunts, and investigations stay compatible with the documentation-first workflow.
Scope
- Define required frontmatter fields for import-ready detection content.
- Document recommended markdown sections and naming conventions.
- Add examples for related detections, ATT&CK mapping, telemetry assumptions, triage, validation, and public-safety redaction.
- Cross-link the conventions from README and CONTRIBUTING.
Acceptance criteria
- Contributors can tell whether a new file is DetLab import-ready.
- At least one existing example is annotated or updated to match the conventions.
- Guidance is vendor-neutral where possible and explicit when content is Microsoft Defender, AWS, or Velociraptor specific.
- No secrets, tenant data, or private environment details are encouraged.
Objective
Document the content conventions required for playbook entries that should import cleanly into DetLab-DAC.
Rationale
The playbook is most valuable when it complements DetLab-DAC instead of becoming a disconnected markdown dump. Clear conventions will help future detections, hunts, and investigations stay compatible with the documentation-first workflow.
Scope
Acceptance criteria