A Digital Commons for sovereign security operations in the EU.
We publish the content layer of security operations — playbooks, detections, control mappings, telemetry shapes and operational metrics — as portable, vendor-neutral artifacts above open standards (CACAO v2, Sigma, OSCAL, D3FEND, OCSF). Reference compilers translate them into runnable form for the orchestrator you already operate: n8n, Temporal or LangGraph.
Built in the open, owned by no single vendor, for organisations meeting the European regulatory baseline (NIS2, DORA, CRA, GDPR, the EU AI Act) without locking their playbooks to one runtime.
| Framework | secops-ng-framework — content, compilers, mappings, metrics |
| Start here | Quickstart |
| Field notes | secops-ng.com · RSS |
| Questions | GitHub Discussions |
| Chat | Discord |
| Fediverse | @secops_ng@mastodon.social |
Every contribution is welcome, from a typo to a new playbook. Read
CONTRIBUTING.md
first: clone, build, DCO sign-off, typed pull-request templates and the
review process. Issues labelled good first issue are reserved for new
contributors.