☆79Feb 19, 2026Updated 3 months ago
Alternatives and similar repositories for Detection-Engineering-Framework
Users that are interested in Detection-Engineering-Framework are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Information about most important hunts which can be performed by Threat hunters while searching for any adversary/threats inside the orga…☆15May 18, 2019Updated 7 years ago
- A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners☆120Oct 29, 2024Updated last year
- Perform file-based malware scan on your on-prem servers with AWS☆14Oct 31, 2023Updated 2 years ago
- Bachelor Thesis for XAMK - Machine Learning Methods for Malware Detection and Classification☆13Jan 29, 2020Updated 6 years ago
- A cargo subcommand to build Rust with docker☆19Aug 24, 2017Updated 8 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Cyber threat intelligence tool suite.☆41Apr 3, 2025Updated last year
- Python for Defenders Course Resources☆21Mar 12, 2026Updated 3 months ago
- SigmaHQ pySigma CrowdStrike processing pipeline☆31Nov 30, 2025Updated 6 months ago
- ☆11Jun 12, 2023Updated 3 years ago
- Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSO…☆369Jun 8, 2026Updated last week
- Templates for Cribl Stream Collectors☆59May 11, 2026Updated last month
- This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.☆49Jun 8, 2026Updated last week
- This is the integration to feed Falcon X IOC data into zscaler's platform☆20Oct 13, 2025Updated 8 months ago
- ☆17Dec 30, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A console tool for inspecting Windows Ancillary Function Driver sockets☆22May 15, 2025Updated last year
- A Python malware analysis library.☆50May 1, 2023Updated 3 years ago
- Malware analysis using Naive Bayes ML classfier☆11Sep 9, 2019Updated 6 years ago
- Plugin providing native AF_Packet support for Zeek.☆33Oct 22, 2025Updated 7 months ago
- Network scanning tool designed to detect and report changes in open ports and services over time☆13Oct 16, 2025Updated 7 months ago
- Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.☆77Mar 27, 2026Updated 2 months ago
- Incident Response automation scripts☆16Sep 5, 2025Updated 9 months ago
- My timewarrior taskwarrior integration scripts☆17Mar 29, 2017Updated 9 years ago
- ☆103Nov 21, 2025Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆46Nov 7, 2024Updated last year
- SimpleCrypt is a powerful command-line tool designed for securely encrypting and decrypting files and directories using AES-256 encryptio…☆20Mar 22, 2026Updated 2 months ago
- Manage and maintain Defender XDR custom collection configuration☆39Nov 19, 2025Updated 6 months ago
- Browser extension for launching multi-platform OSINT queries from grouped YAML profiles.☆10Apr 25, 2025Updated last year
- [SmartCom2017] An Effective Malware Detection based on Behaviour and Data Feature☆20Sep 14, 2018Updated 7 years ago
- Give AI agents secure access to your accounts - without sharing your credentials☆49Apr 15, 2026Updated 2 months ago
- Some resources to facilitate my blog on auditd for security monitoring☆13Mar 23, 2023Updated 3 years ago
- Using MCP is fun with Cyberbro!☆19Apr 25, 2026Updated last month
- Behavorial analysis of malware using machine learning☆16Mar 13, 2018Updated 8 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Convert Sigma rules to LogRhythm searches☆24Feb 27, 2022Updated 4 years ago
- Threat Modeling with ATT&CK defines how to integreate MITRE ATT&CK® into your organization’s existing threat modeling methodology.☆14May 28, 2025Updated last year
- IOCs for various malware families☆11Jul 18, 2024Updated last year
- Pentesting resources☆24May 3, 2019Updated 7 years ago
- You’ve hardened your servers, locked down your website and are ready to take on the internet. But all your hard work was in vain, because…☆15Mar 6, 2017Updated 9 years ago
- Grab form parameters easily☆14Dec 11, 2024Updated last year
- Understanding the operation and limitations of Sysmon's events☆25Sep 15, 2022Updated 3 years ago