Threat Detection & Anomaly Detection rules for popular open-source components
☆53Jul 27, 2022Updated 4 years ago
Alternatives and similar repositories for threat-detection-rules
Users that are interested in threat-detection-rules are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- SIEGMA - Transform Sigma rules into SIEM consumables☆161Mar 10, 2025Updated last year
- Threat Feeds, Threat lists, and regular lists of known IP ranges and domains. It updates every 4 hours.☆16May 21, 2021Updated 5 years ago
- My logstash plugins. Filter: sig (for security detect -> IOC, sig, New value, Reference, link, frequence, ...). Output: alert created by …☆10Jul 26, 2019Updated 7 years ago
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆62Mar 12, 2022Updated 4 years ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆39Dec 17, 2025Updated 7 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- An ongoing & curated collection of awesome software best practices and remediation techniques, libraries and frameworks, E-books and vide…☆50Nov 11, 2022Updated 3 years ago
- A Sigma based detection pipeline☆12Dec 15, 2023Updated 2 years ago
- A curated list of resources to deep dive into the intersection of applied machine learning and threat detection.☆19Sep 23, 2020Updated 5 years ago
- Splunk code (SPL) for serious threat hunters and detection engineers.☆294Jan 15, 2024Updated 2 years ago
- Cyber Threats Detection Rules☆14Sep 16, 2025Updated 10 months ago
- Linux based vulnerabilities (CVE) exploit detection through runtime security using Falco/Osquery/Yara/Sigma☆22Nov 27, 2023Updated 2 years ago
- A POC to implement Detection-as-Code with Terraform and Sumo Logic.☆32Jul 27, 2023Updated 3 years ago
- ⚠️ ARCHIVED**: This repository is no longer actively maintained. All Sigma rules are now managed and available in SIEM Rules☆14Mar 19, 2026Updated 4 months ago
- This repository contains Splunk queries to hunt some anomalies☆47Jul 28, 2022Updated 4 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Import specific data sources into the Sigma generic and open signature format.☆78May 6, 2022Updated 4 years ago
- Threat Detection System using Hybrid (Machine Learning + Lexical Analysis) learning Approach.☆11May 30, 2017Updated 9 years ago
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆22Jan 22, 2021Updated 5 years ago
- A script to create and assign SOP tasks into the cases☆20Aug 16, 2020Updated 5 years ago
- certstream + analytics☆11Jan 17, 2020Updated 6 years ago
- Bring Your Own Mitre Att&ck © Matrix !☆13Oct 19, 2023Updated 2 years ago
- This directory contains random scripts from threat hunting or malware research☆11Feb 15, 2018Updated 8 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆21Jul 1, 2023Updated 3 years ago
- Pritunl Access Control System☆11Jul 28, 2026Updated 2 weeks ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Contains research.splunk.com site code☆12Apr 10, 2024Updated 2 years ago
- A test case runner for Sigma rules☆14Aug 14, 2024Updated last year
- 🌦️ Domain Ranker☆16Sep 7, 2019Updated 6 years ago
- Knowledge base of analytics designed to cover threats based on MITRE's ATT&CK.☆23Dec 13, 2018Updated 7 years ago
- Sigma rules to share with the community☆126Jan 29, 2025Updated last year
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆441May 21, 2026Updated 2 months ago
- ☆31Nov 25, 2025Updated 8 months ago
- ☆21May 19, 2016Updated 10 years ago
- Threat Detection Rules (Snort/Sigma/Yara)☆14Jan 23, 2024Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Check Sigma rules for easy-to-bypass whitelists to make them more robust (https://github.com/SigmaHQ/sigma)☆16Feb 1, 2021Updated 5 years ago
- Meer is a "spooler" for Suricata / Sagan.☆30Jun 21, 2023Updated 3 years ago
- simple webapp for converting sigma rules into siem queries using the pySigma library☆50Sep 1, 2023Updated 2 years ago
- A repository to share contributions related to TheHive Project☆22Sep 15, 2021Updated 4 years ago
- Snort_rules detection bad actors.☆30Jul 14, 2026Updated last month
- FIles and guides related to using Elasticstack as a SIEM☆12May 16, 2020Updated 6 years ago
- Actionable analytics designed to combat threats based on MITRE's ATT&CK.☆24Aug 21, 2019Updated 6 years ago