TONK

Threat Observation & Network Kill-chain

references
PLAYBOOKS
playbooks

Curated hunt sequences by threat actor, environment type, and network architecture. Prioritized checklists for when intel drops an actor name and you need to know where to start.

▸ open playbooks
operational tools
NET
net-hunt-ref

Network-based detection reference. Kibana, Arkime, and Suricata queries mapped across the ATT&CK matrix, with APT correlation, OSINT notes, and air-gapped vs connected tripwire framing.

▸ open reference
HOST
host-hunt-ref

Host analyst threat hunting: indicators, detection syntax, and APT correlation, OSINT notes across the attack lifecycle .

▸ open reference
ATTRIB
attribution

Evidence-driven adversary attribution. Reads the indicators you've starred in HUNT and ranks likely threat actors cross-nation by the attribution baked into each one. Save and restore hunt state for continuity across sessions and machines.

▸ open attribution
train
DETECT
detect

Suricata and Zeek detection rule reference. Signature management, rule tuning, and detection engineering mapped to the network threat landscape.

▸ open detect