Select an element to view its properties.
Select an element to view its properties.
Comprehensive Playbook Overview & Simulation Report
RaccoonIR is a structured incident response playbook planner that connects system dependency models (what can go wrong) with response activities (what we do about it). The core workflow is:
The dependency model represents the system's operational goal structure as a directed acyclic graph (DAG). Each node (paragon) has a type β AND (all children must succeed), OR (any child suffices), or UNCONTROLLABLE (external factor with fixed probability). Probabilities propagate from leaves to root, giving a quantitative view of operational risk.
Playbooks define the incident response process as hierarchical activity diagrams. Each activity (PlaybookProcess) specifies objectives (Detect, Contain, Eradicate, Recover), action types (Technical, Administrative, Physical), responsible roles, and data flows via artifacts. Activities can be nested into sub-processes for complex multi-stage responses.
The Impact View is the central analysis tool. It shows playbook activities (left) and the dependency model (right) side-by-side, connected by ActivityImpact arrows. Three simulation modes are available:
This view answers the key question: "If we execute these response actions, how does our operational posture change?"
The Metrics tab presents computed values for every paragon in the dependency model:
[Metrics Report β see interactive view]
The SYMBIOSIS module maps business objectives to security measurement goals, security metrics, and base measurements β creating a traceable chain from strategic intent to measurable security KPIs. This ensures the playbook's response activities are aligned with organisational goals.
[SYMBIOSIS Alignment β see interactive view]
Each playbook activity can be tagged with MITRE ATT&CK techniques (adversary actions being countered) and MITRE D3FEND countermeasures (defensive techniques being applied). The MITRE View aggregates these mappings to show full technique coverage across the playbook, identifying gaps in detection and response capability.
[MITRE ATT&CK/D3FEND Coverage β see interactive view]
βββββββββββββββββββββββ ActivityImpact ββββββββββββββββββββββββ
β PLAYBOOK βββββββββββββββββββββββββββββββΆβ DEPENDENCY MODEL β
β (Response Actions)β "Activity X changes β (System Goals) β
β β Paragon Y's probability β β
β β’ Activities β from 40% β 85%" β β’ AND/OR/UNC gates β
β β’ Data Flows β β β’ Probabilities β
β β’ Roles & Actors β β β’ Critical Thresholdsβ
βββββββββββββββββββββββ ββββββββββββββββββββββββ
β β
βΌ βΌ
βββββββββββββββββββββββ ββββββββββββββββββββββββ
β MITRE ATT&CK/D3FENDβ β METRICS ENGINE β
β (Technique Mapping)β β P, CiO, Thresholds β
βββββββββββββββββββββββ ββββββββββββββββββββββββ
β β
ββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββ
βΌ
ββββββββββββββββββββββββββ
β SYMBIOSIS β
β (Business Alignment) β
ββββββββββββββββββββββββββ