Online resources related to Detection Engineering. Detection rules, detection logic, attack samples, detection tests and emulation tools, logging configuration and best practices, event log references, resources, labs, data manipulation online tools, blogs, newsletters, good reads, books, trainings, podcasts, videos and twitter/x accounts.
☆178Jul 14, 2026Updated last month
Alternatives and similar repositories for awesome-detection-engineer
Users that are interested in awesome-detection-engineer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Online resources related to SOC Analysts. Incident investigation reference material, blogs, newsletters, good reads, books, trainings, po…☆84Feb 14, 2026Updated 5 months ago
- Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation o…☆1,316Aug 3, 2026Updated last week
- Repository with Hunting and Detection Queries for Microsoft Sentinel and Microsoft Defender XDR☆17Jun 9, 2026Updated 2 months ago
- how to strangle threats☆60Updated this week
- A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concret…☆59Mar 5, 2026Updated 5 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆99Jan 7, 2026Updated 7 months ago
- Sigma rules to share with the community☆126Jan 29, 2025Updated last year
- A starter pack of resources to help you get started in Detection Engineering.☆194Jun 4, 2026Updated 2 months ago
- Detection Reliability And Precision Efficiency (DRAPE) is an index used to assess detection performance☆36Nov 17, 2025Updated 8 months ago
- Detection engineering template☆15Jul 24, 2025Updated last year
- Mapping of open-source detection rules and atomic tests.☆215Jul 15, 2026Updated 3 weeks ago
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆123Jan 18, 2026Updated 6 months ago
- Collection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc)☆81Apr 12, 2026Updated 4 months ago
- sKaleQL is an opinionated template repository for managing, executing, and organizing Kusto Query Language (KQL) queries against Azure Lo…☆20May 20, 2025Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or eve…☆288Jun 23, 2026Updated last month
- An index of publicly available and open-source threat detection rulesets.☆136Apr 17, 2025Updated last year
- KQL Queries. Microsoft Defender, Microsoft Sentinel☆924Updated this week
- Awesome list of keywords and artifacts for Threat Hunting sessions☆671Aug 4, 2025Updated last year
- KQL Queries☆42Updated this week
- ResearchDev - XDR & SIEM Detection☆66Apr 16, 2025Updated last year
- Awesome Security lists for SOC/CERT/CTI☆1,854Updated this week
- PowerShell tools to help defenders hunt smarter, hunt harder.☆488Oct 29, 2025Updated 9 months ago
- Utilizing your Threat data from a MISP instance into CarbonBlack Response by exposing the data in the Threat Intelligence Feed.☆20May 25, 2022Updated 4 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Repository with supporting materials for Invictus Academy/Training☆44Jul 22, 2026Updated 3 weeks ago
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆441May 21, 2026Updated 2 months ago
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆822Jul 28, 2026Updated 2 weeks ago
- Convert Sigma rules to SIEM queries, directly in your browser.☆122Jun 20, 2026Updated last month
- A small guide on Unknown/Orphaned SIDs and some PowerShell tools to help you get rid of them.☆21Apr 16, 2026Updated 3 months ago
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆158Apr 1, 2026Updated 4 months ago
- Sublime rules for email attack detection, prevention, and threat hunting.☆369Updated this week
- An opensource sigma conversion tool built using pysigma☆174Updated this week
- This operational dashboard correlates data from Microsoft Defender for Endpoint/Server (MDE) and Azure Monitor Agent (AMA) to identify co…☆18May 13, 2026Updated 3 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- This is a collection of threat detection rules / rules engines that I have come across.☆299May 5, 2024Updated 2 years ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆334Updated this week
- A repository of my own Sigma detection rules.☆167Nov 25, 2025Updated 8 months ago
- A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 D…☆793Jun 3, 2026Updated 2 months ago
- This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.☆18Jun 25, 2026Updated last month
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆54Oct 23, 2024Updated last year
- Rulezet is an open-source web platform for sharing, evaluating, improving, and managing cybersecurity detection rules (YARA, Sigma, Suric…☆56Updated this week