Build evidence, not alert volume
Telemetry requirements, detections-as-code, triage, ATT&CK mapping, validation, and coverage metrics.
Open detection engineering βFIELD FRAMEWORK / VERSION 2.1
Operational guidance for the people making technical and business decisions during an incident.
Built for security operations, engineering, infrastructure, identity, cloud, legal, privacy, and business owners. Adapt the decision authority, telemetry, tooling, and regulatory paths to your environment before an incident.
The objective is not to follow a document mechanically. It is to establish reliable evidence, explicit authority, reversible containment where possible, and measurable recovery criteria.
This six-stage workflow supports active response. It complements NIST SP 800-61 Rev. 3 and NIST CSF 2.0; it is not intended to replace organization-wide cybersecurity risk management.
βΊ Evidence and new impact can return the team to validation, scoping, or containment at any time.
Telemetry requirements, detections-as-code, triage, ATT&CK mapping, validation, and coverage metrics.
Open detection engineering βRoles, severity, evidence discipline, containment gates, communications, recovery criteria, and exercises.
Open response procedures βScenario-specific actions with decision authority, evidence requirements, rollback, and validation.
Open incident playbooks βSeverity, evidence, cloud, identity, ransomware, executive-update, and post-incident templates.
Open the field kit βAI/LLM lifecycle, evidence requirements, authority reduction, rollback, and the operational AI-IR-01 playbook.
Open AI Security IR βRepository, maintainer, workflow, dependency, credential, package, release, and artifact compromise response.
Open repository response βConfirm the incident lead, protected communication channel, evidence repository, time standard, emergency access path, escalation tree, recovery owners, and authority for disruptive containment.