Skip to content

Define DetLab import-ready content conventions #4

Description

@egrexsec

Objective

Document the content conventions required for playbook entries that should import cleanly into DetLab-DAC.

Rationale

The playbook is most valuable when it complements DetLab-DAC instead of becoming a disconnected markdown dump. Clear conventions will help future detections, hunts, and investigations stay compatible with the documentation-first workflow.

Scope

  • Define required frontmatter fields for import-ready detection content.
  • Document recommended markdown sections and naming conventions.
  • Add examples for related detections, ATT&CK mapping, telemetry assumptions, triage, validation, and public-safety redaction.
  • Cross-link the conventions from README and CONTRIBUTING.

Acceptance criteria

  • Contributors can tell whether a new file is DetLab import-ready.
  • At least one existing example is annotated or updated to match the conventions.
  • Guidance is vendor-neutral where possible and explicit when content is Microsoft Defender, AWS, or Velociraptor specific.
  • No secrets, tenant data, or private environment details are encouraged.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationenhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions