RunbooksDB Home Page
Last updated
Was this helpful?
Last updated
Was this helpful?
The RunbooksDB home page consists of five tabs:
Repositories: A set of processes that can be reused and have controlled access.
Procedures: A set of steps required to execute a tactic. For example, a procedure for browser extension-based persistence could describe how a malicious extension is injected to maintain persistence.
Techniques: A grouping of procedures. Techniques are added to a tactic for use in an engagement. For example, if a tactic is persistence, a technique could exist for browser extensions.
Tactics: A grouping of techniques. Tactics are added to a methodology for use in a runbook. This usually represents a type of attack, such as persistence or a privilege escalation from the MITRE ATT&CK framework. This can also be a logical grouping or structure for techniques.
Methodologies: A grouping of tactics that are put into a runbook. It contains a title, ID, description, and the selected series of tactics. Tactics can be chosen to apply to the methodology when used as a runbook. This is similar to how the MITRE ATT&CK is broken down, where the methodology represents the framework for TTPs.
PlexTrac provides a container for all instances called "PlexTrac Curated" that contains community-produced procedures on MITRE/CTI.
This repository contains over 1,500 MITRE procedures from the ATT&CK matrix that can be leveraged. It is available to all users and cannot be deleted.
Once a test plan is imported, another default repository is created. This repository contains all procedures included in the imported test plans.
The default repositories cannot be deleted.
Once added, any additional repositories will be displayed on the page alphabetically according to their title.
Each repository card offers an overview of its contents and settings. It includes the Repository Title, which helps identify the repository, and the Repository Type, which can be categorized as Open, Managed, or Private. The meatballs menu provides convenient options for copying or deleting the repository. Additionally, a Repository Description is available for further context. The card also displays the number of procedures contained, giving insight into the repository's complexity and the number of added users. This indicates the level of collaboration or access granted to others.
To view all procedures, click the Procedures tab. This view will display helpful information such as the procedure ID, repository ID, methodology, repository, source, assigned tags, and the ability to edit or delete a procedure.
The table view can be customized by clicking the column view icon to the right of the search bar.
Click the Techniques tab to view all techniques. This view will display the title, ID, leveraged tactics, and the ability to edit or delete them.
The table view can be customized by clicking the column view icon to the right of the search bar.
To view all tactics, click the Tactics tab. This view will display the title, ID, leveraged methodology, and the ability to edit or delete.
The table view can be customized by clicking the column view icon to the right of the search bar.
Click on the Methodologies tab to see all methodologies and find the title, ID, and options to edit or delete them.