dogear

enter for all results · esc to close

Detection Engineering

74 items from infosecb/awesome-detection-engineering ★1,356

  1. 0
    Sigma github.com

    Generic signature format for SIEM systems already containing an extensive ruleset.

  2. 0
    Matano github.com

    Open source serverless security lake platform on AWS that lets you ingest, store, and analyze petabytes of security data into an Apache Iceberg data lake and run realtime Python detections as code.

  3. 0
    Elastalert | Yelp github.com

    ElastAlert is a simple framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch.

  4. 0
    Loghub github.com

    Opensource and freely available security data sources for research and testing.

  5. 0
    KQL Advanced Hunting Queries & Analytics Rules github.com

    A list of endpoint detections and hunting queries for Microsoft Defender for Endpoint, Defender For Identity, and Defender For Cloud Apps.

  6. 0
    Agent Threat Rules (ATR) github.com

    An open MIT detection-rule standard for AI-agent and MCP attacks (prompt injection, tool poisoning, context exfiltration), like Sigma or YARA for the agent layer, with OWASP LLM/Agentic and MITRE ATLAS mappings on each rule.

  7. 0
    Splunk Security Content github.com

    Splunk's open-source and frequently updated detection content that can be tweaked for use in other tools.

  8. 0
    Alerting and Detection Strategies (ADS) Framework | Palantir github.com

    A blueprint for creating and documenting effective detection content.

  9. 0
    timescale/rsigma github.com

    [rsigma] - A complete detection engineering toolkit for the Sigma detection standard, with a parser, evaluation engine, rule conversion, streaming runtime, linter, CLI, MCP, and LSP

  10. 0
    Chronicle (GCP) Detection Rules github.com

    Chronicle's detection rules written natively for the Chronicle Platform.

  11. 0
    Rustinel | Karib0u github.com

    Open-source endpoint detection engine for Windows and Linux that collects ETW/eBPF telemetry and evaluates Sigma, YARA, and IOC detections.

  12. 0
    Center for Threat Informed Defense Security Stack Mappings github.com

    Describes cloud computing platform's (Azure, AWS) built-in detection capabilities and their mappings to the MITRE ATT&CK framework.

  13. 0
    Google Cloud Security Analytics github.com

    This repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud.

  14. 0
    Detection and Response Pipeline github.com

    A list of tools for each component of a detection and response pipeline which includes real-world examples.

  15. 0
    Anvilogic Detection Armory github.com

    Anvilogic's opensource and publicly available detection content.

  16. 0
    Synthetic Adversarial Log Objects (SALO) | Splunk github.com

    Synthetic Adversarial Log Objects (SALO) is a framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event.

  17. 0
    SOCTalk github.com

    Open source, LLM driven SOC automation platform for MSPs and MSSPs built on Wazuh. Triages, investigates, and escalates alerts through a two tier AI pipeline with human in the loop review, multi tenant isolation, and a no code triage policy editor backed by deterministic…

  18. 0
    Detection Engineering with Splunk github.com

    A GitHub repo dedicated to sharing detection analytics in SPL.

  19. 0
    ZettelForge github.com

    Agentic memory system that treats Sigma and YARA rules as first-class memory entities, with an LLM rule explainer, STIX 2.1 knowledge graph of CTI entities, and offline-first RAG to connect rules to the actors and techniques they detect. Python, MIT.

  20. 0
    osquery osquery.io

    osquery is an instrumentation framework that expose the operating system as a high-performance relational database.

  21. 0
    Exabeam Content Library github.com

    Exabeam's out of the box detection content compatible with the Exabeam Common Information Model.

  22. 0
    ThreatMapper | Andrey Pautov github.com

    CTI-to-detection workbench for mapping threat reports to ATT&CK, comparing TTP overlap with groups and campaigns, identifying detection gaps, and exporting analyst-ready outputs.

  23. 0
    TerraSigma github.com

    A repository of all SIGMA rules converted to Microsoft Sentinel Terraform Scheduled analytic resources. The repository runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository. Proper entity mapping is completed for…

  24. 0
    Sigma2KQL github.com

    A repository of all SIGMA rules converted to KQL that runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository.

  25. 0
    Exabeam Common Information Model github.com

    Exabeam's proprietary model used as a framework for normalizing security data.

  26. 0
    Detection Engineering Twitter List | Zack Allen x.com

    A Twitter list of Detection Engineering thought leaders.

  27. 0
    Cloud Threat Landscape | Wiz threats.wiz.io

    A cloud detection engineering-focused database, that lists threat actors known to have compromised cloud environments, the tools and techniques in their arsenal, and the technologies they prefer to target.

  28. 0
    SOCLabs soc-labs.top

    A lab for blue teamers and detection engineers, with real threat data and support for popular SIEM query languages, enabling hands-on learning and practice in detection rule writing and threat hunting.

  29. 0
    Sigma rule converter sigconverter.io

    An opensource tool that can convert detection content for use with most SIEMs.

  30. 0
    Open Cybersecurity Schema Framework (OCSF) schema.ocsf.io

    An opensource security data source and event schema.

  31. next page of items loading…