RatVault

A curated Obsidian vault with templates, cheat sheets, and workflows for security operations, incident response, threat hunting, and more

๐Ÿ” RatVault: Obsidian for Security Analysts

A curated Obsidian vault with templates, cheatsheets, and workflows for security operations, incident response, threat hunting, and more.

๐Ÿ‘‹ Welcome

Welcome to RatVault - your comprehensive knowledge base and toolkit for security analysis!

This vault was created by Mick Donahue as a resource for security professionals to quickly access templates, cheatsheets, reference guides, and workflows. Feel free to use, customize, and extend this vault for your own security operations.

ย ย 

๐Ÿ“‹ Overview

RatVault is an Obsidian vault configured specifically for security analysts, SOC teams, incident responders, and threat hunters. It provides a structured approach to security documentation, analysis, and knowledge management using the power of Obsidian's linking and knowledge graph.

โœจ Features

  • ๐Ÿ” Security analyst templates - IR reports, malware analysis, threat hunting plans, and more
  • ๐Ÿงพ Cheatsheets - KQL, PowerShell, Bash, Windows internals, and other reference materials
  • ๐Ÿ“‹ Incident response & SOC workflows - Standardized processes for handling security events
  • ๐Ÿ“Š Dashboards - Canvas and Excalidraw visualizations for security operations
  • ๐Ÿงฐ Tool integration guides - How to use and integrate security tools
  • ๐Ÿง  Notes with backlinks and dataviews - Connect your security knowledge

๐Ÿš€ Getting Started

  1. Install Obsidian: Download from obsidian.md
  2. Open this vault: Use "Open folder as vault" in Obsidian and select this folder
  3. Install community plugins: Go to Settings โ†’ Community Plugins โ†’ Browse and install the recommended plugins
  4. Apply settings: Copy the settings.json from the Custom_Plugins folder to your .obsidian folder if you want to use the recommended settings

๐Ÿ“ฆ Vault Structure

FolderContents
Templates/Incident report, malware triage, threat hunting plans, daily logs
Cheatsheets/Query languages, scripting, systems reference
Tool_Guides/Guides for security tools and platforms
Threat_Intel/IOC templates, YARA rules, threat actor tracking
Daily_Logs/SOC daily log templates and entries
Custom_Plugins/Settings files and plugin configurations
Canvas_Dashboards/Visual dashboards for security operations

๐Ÿ’ก Recommended Plugins

  • Dataview: For querying and displaying information from your notes
  • Excalidraw: For creating diagrams and visual representations
  • Templater: For enhanced template capabilities
  • Kanban: For visual task management
  • Calendar: For date-based navigation
  • Advanced Tables: For better table management
  • Tasks: For task tracking across notes

๐ŸŽจ Recommended Themes

  1. Cybertron: A dark theme with a retro-futuristic style perfect for security work
  2. Obsidian Nord: A clean, dark blue theme that reduces eye strain during long shifts
  3. Terminal: A terminal-inspired theme that brings a hacker aesthetic

๐Ÿ“ Usage Tips

  1. Daily Logs: Start each shift by creating a new daily log from the template
  2. Incident Documentation: Use the IR template when responding to security incidents
  3. Knowledge Building: Link related notes using [[double brackets]] to build your knowledge graph
  4. Dataview Queries: Use dataview to create dashboards showing open incidents, tasks, or other data
  5. Templates: Use the templates as starting points and customize them to your needs

๐Ÿค Contributing

Feel free to enhance this vault with your own templates, cheatsheets, and workflows. Some suggested contributions:

  • Additional tool guides
  • New templates for specific security scenarios
  • Custom CSS snippets for security dashboards
  • Scripts to automate security tasks

If you create something useful, consider sharing it with the community! You can submit a pull request to the GitHub repository or reach out directly.

๐Ÿ“š Resources

โœ๏ธ About the Author

RatVault was created by Mick Donahue, a security professional passionate about knowledge management and security operations. This vault is designed to help others streamline their security workflows.

If you find this resource valuable, consider:




[!tip] Security Notes Best Practices

  1. Maintain Operational Security: Be mindful of sensitive data
  2. Regular Backups: Back up your vault regularly
  3. Consistent Structure: Follow the established structure for new notes
  4. Link Generously: Create connections between related notes
  5. Use YAML Frontmatter: Add metadata to enable powerful filtering

Related

How to Install

  1. Download the ZIP or clone the repository
  2. Open the folder as a vault in Obsidian (File โ†’ Open Vault)
  3. Obsidian will prompt you to install required plugins

Stats

Stars

2

Forks

0

Last updated 3mo ago