Arcana: A Unified Framework for Incident Response Documentation and Knowledge Management @FIRSTdotorg
Arcana: A Unified Framework for Incident Response Documentation and Knowledge Management  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 11 minutes ago
Vishal Thakur (Atlassian, AU), Jayden Vo (Atlassian, AU)

The Arcana Framework is an open‑source initiative designed to standardize and elevate the way Incident Response teams document, share, and operationalize security knowledge. Built and maintained by the Atlassian Incident Response team, Arcana structures IR knowledge across Playbooks, Runbooks, SOPs, and Knowledge Base Articles, providing immediate, customizable templates ready for operational use.

The framework will be released publicly at the FIRST Conference and hosted on Atlassian’s official GitHub repository, where the community can contribute their own documents and receive full credit. Arcana aims to close the gap between documentation theory and field application—bridging best practices, automation readiness, and real‑world response needs.

---

Vishal Thakur is a Regional Manager of CSIRT operations and security researcher based in Sydney, Australia. With over 13 years of experience leading incident response and cyber defense teams across Atlassian, Salesforce, TikTok USDS, Commonwealth Bank of Australia, he specializes in large-scale threat detection, malware analysis, and proactive cyber operations.

Vishal is the Founder of HackSydney and BSides Sydney, and a frequent speaker and trainer at FIRST, DEF CON, Black Hat, SANS conferences. His current research focuses on anticipatory threat modeling, AI-enabled adversarial simulation, and preemptive defense frameworks. He is the creator of PR3TACK, a next-generation threat modeling framework, and Warhead, a research project for offensive techniques that can be used for red-teaming operations. Vishal has also actively worked in the research field of cognitive malware and has published papers on that subject in academic and institutional journals.

Jayden Vo is a Senior Security Incident Response Analyst at Atlassian, where he has spent the past five years responding to a wide variety of incidents and threat actors. Outside of responding to security incidents, Jayden dedicates time for proactive threat hunting and tracking threat actors targeting Atlassian. He has previously shared his threat hunting methodologies and threat actor research in various TLP:RED environments.
Arcana: A Unified Framework for Incident Response Documentation and Knowledge ManagementFrom Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE RemediationLightning Talks!Anti-Forensics - You are Doing it Wrong (Believe Me, Im an IR Consultant)What Can Cybersecurity Incident Responders Learn from Real-World Crises?Enhancing Incident Response with AWS CIRT, MSSPs, and ISVsEpisode 55: Merike Kaeo, FIRSTCON26 Program ChairProactive EDR Against Adaptive Evasion: Countering Self‑Modifying Agentic MalwareProduction Is the New Attack Surface: Why Post-Deployment Endpoint Detection Is Now CriticalOROCHIFY - An Assist to Product Developers in Manufacturing Industry to Find VulnerabilitiesRemediation-Aware Reachability: Patching Containers, Prioritizing with Agentic-CTI, and Scaling...Threat Hunting with Python & Pandas
FIRST |

Arcana: A Unified Framework for Incident Response Documentation and Knowledge Management

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER