Anvilogic Forge
☆119Mar 31, 2026Updated 3 months ago
Alternatives and similar repositories for armory
Users that are interested in armory are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- DetectPack Forge turns plain-English behaviors or sample logs into production-ready detection packs — Sigma, KQL (Sentinel), SPL (Splunk)…☆24Mar 19, 2026Updated 4 months ago
- ☆16May 3, 2024Updated 2 years ago
- Security Content for the PEAK Threat Hunting Framework☆47Feb 15, 2024Updated 2 years ago
- Sublime rules for email attack detection, prevention, and threat hunting.☆369Updated this week
- Independently deploy customized honeyservices in AWS to trigger alerts on unauthorized access. It utilizes a dedicated CloudTrail for pre…☆52Nov 16, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Browser extension blocking scam and phishing pages https://chromewebstore.google.com/detail/nehboro/ljgklnaofelbcnegjniagpmjknkmaiom☆15Apr 22, 2026Updated 3 months ago
- An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&CK insights, real-world incidents, references and secur…☆174Jul 12, 2026Updated last week
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆224Sep 4, 2024Updated last year
- This is a collection of threat detection rules / rules engines that I have come across.☆300May 5, 2024Updated 2 years ago
- Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation o…☆1,302Jul 11, 2026Updated last week
- ☆41Nov 29, 2024Updated last year
- ✨ A compilation of suggested tools/services for each component in a detection and response pipeline, along with real-world examples. The …☆296Feb 5, 2024Updated 2 years ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆69Jul 2, 2026Updated 3 weeks ago
- To clean up your AWS AMIs: First, include AMIs by name or tag. Second, exclude AMIs in use, younger than N days, or the newest N images. …☆36Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A powershell script for creating a Windows honeyport.☆12Jun 24, 2015Updated 11 years ago
- Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.☆114Dec 3, 2025Updated 7 months ago
- This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits containing potential secret or interesting…☆47Aug 16, 2024Updated last year
- ☆395Apr 15, 2026Updated 3 months ago
- Stupid Simple Detection Testing☆13Mar 7, 2024Updated 2 years ago
- A PoC to Simulate Ransomware Attack on AWS Environment☆33Oct 14, 2024Updated last year
- Built-in Panther detection rules and policies☆458Updated this week
- Convert cloudtrail data to MITRE ATT&CK Sightings☆82Jul 25, 2022Updated 3 years ago
- Resources for DFIR. And more.☆12Jul 3, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Cyber deception with generative cloud-native traps☆15Apr 13, 2025Updated last year
- Mapping of open-source detection rules and atomic tests.☆214Jul 15, 2026Updated last week
- A framework for developing alerting and detection strategies for incident response.☆890Sep 8, 2025Updated 10 months ago
- 威胁检测规则集☆15Jul 5, 2019Updated 7 years ago
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆816Jan 14, 2026Updated 6 months ago
- A collection of open source threat detection rules created by Cyber Castle's team.☆14Jun 2, 2022Updated 4 years ago
- This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple…☆866Updated this week
- ShellSweeping the evil.☆183Nov 25, 2024Updated last year
- kubernetes-for-soc aims to fast-track the learning curve for SOC analysts by enabling them to swiftly grasp the essential concepts and kn…☆56Dec 18, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Awesome secure by default libraries to help you eliminate bug classes!☆712Dec 6, 2025Updated 7 months ago
- A curated list of resources about detecting threats and defending Kubernetes systems.☆409Sep 2, 2023Updated 2 years ago
- CloudGrappler is a purpose-built tool designed for effortless querying of high-fidelity and single-event detections related to well-known…☆267Nov 21, 2025Updated 8 months ago
- A public collection of detections designed to detect threats associated with the Okta WIC Platform.☆31Updated this week
- Threatest is a CLI and Go framework for end-to-end testing threat detection rules.☆345Updated this week
- Welcome to Autoaudit, a log tampering detection tool.☆13Mar 19, 2024Updated 2 years ago
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆61Mar 12, 2022Updated 4 years ago