Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.
☆1,346Aug 3, 2026Updated last month
Alternatives and similar repositories for awesome-detection-engineering
Users that are interested in awesome-detection-engineering are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ✨ A compilation of suggested tools/services for each component in a detection and response pipeline, along with real-world examples. The …☆299Feb 5, 2024Updated 2 years ago
- ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️☆4,730Jan 5, 2026Updated 8 months ago
- Splunk Security Content☆1,697Updated this week
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆62Mar 12, 2022Updated 4 years ago
- Online resources related to Detection Engineering. Detection rules, detection logic, attack samples, detection tests and emulation tools…☆183Aug 22, 2026Updated last month
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A framework for developing alerting and detection strategies for incident response.☆908Sep 8, 2025Updated last year
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆826Aug 14, 2026Updated last month
- Main Sigma Rule Repository☆11,076Updated this week
- KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunt…☆1,752Updated this week
- A starter pack of resources to help you get started in Detection Engineering.☆196Jun 4, 2026Updated 3 months ago
- A repository of my own Sigma detection rules.☆166Nov 25, 2025Updated 9 months ago
- ☆2,700Updated this week
- Detect Tactics, Techniques & Combat Threats☆2,341Sep 14, 2026Updated last week
- Mapping of open-source detection rules and atomic tests.☆215Jul 15, 2026Updated 2 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- This is a collection of threat detection rules / rules engines that I have come across.☆300May 5, 2024Updated 2 years ago
- Awesome Security lists for SOC/CERT/CTI☆1,917Updated this week
- A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data int…☆2,560Sep 13, 2026Updated last week
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,673Jan 12, 2026Updated 8 months ago
- Granular, Actionable Adversary Emulation for the Cloud☆2,403Updated this week
- A curated knowledge base to build, run and mature a SOC (including CSIRT).☆1,878Updated this week
- Built-in Panther detection rules and policies☆465Sep 10, 2026Updated last week
- Resources To Learn And Understand SIGMA Rules☆189Feb 14, 2023Updated 3 years ago
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆664Jun 19, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A repository of curated datasets from various attacks☆820Updated this week
- Anvilogic Forge☆119Mar 31, 2026Updated 5 months ago
- Awesome list of keywords and artifacts for Threat Hunting sessions☆673Aug 4, 2025Updated last year
- Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS☆1,697Jan 8, 2025Updated last year
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12,573Sep 14, 2026Updated last week
- Practical Threat Detection Engineering, Published by Packt☆97Apr 22, 2026Updated 5 months ago
- A curated list of tools for incident response☆9,401Jul 15, 2026Updated 2 months ago
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆224Sep 4, 2024Updated 2 years ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆69Jul 2, 2026Updated 2 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A curated list of resources about detecting threats and defending Kubernetes systems.☆412Sep 2, 2023Updated 3 years ago
- This project aims to compare and evaluate the telemetry of various EDR products.☆1,986Sep 2, 2026Updated 3 weeks ago
- ☆102Jul 20, 2026Updated 2 months ago
- Automate the creation of a lab environment complete with security tooling and logging best practices☆5,027Jul 6, 2024Updated 2 years ago
- An index of publicly available and open-source threat detection rulesets.☆140Apr 17, 2025Updated last year
- Threatest is a CLI and Go framework for end-to-end testing threat detection rules.☆347Updated this week
- Collection of example YARA-L rules for use within Google Security Operations☆516Aug 6, 2026Updated last month