The Threat Hunter Playbook
The Threat Hunter Playbook is another project started by Roberto and José Rodriguez with the intention of sharing detections with the community following MITRE ATT&CK tactics to categorize adversary behavior. Later on, they incorporated the project into an interactive notebook, which allows easy replication and visualization of the detection data. Combined with OSSEM, the Mordor project, and BinderHub, you'll find queries in SQL format that you can adapt and use in your own environment. You can read and explore more about the Threat Hunter Playbook at its official website: https://threathunterplaybook.com. In addition, you can read Roberto's post about how to set up Binder infrastructure at the following link: https://medium.com/threat-hunters-forge/threat-hunter-playbook-mordor-datasets-binderhub-open-infrastructure-for-open-8c8aee3d8b4.
Besides the motivating sharing objective behind this project, as you can see in the following screenshot...