Online resources related to Detection Engineering. Detection rules, detection logic, attack samples, detection tests and emulation tools, logging configuration and best practices, event log references, resources, labs, data manipulation online tools, blogs, newsletters, good reads, books, trainings, podcasts, videos and twitter/x accounts.
☆174Jul 14, 2026Updated last week
Alternatives and similar repositories for awesome-detection-engineer
Users that are interested in awesome-detection-engineer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Online resources related to SOC Analysts. Incident investigation reference material, blogs, newsletters, good reads, books, trainings, po…☆67Feb 14, 2026Updated 5 months ago
- Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation o…☆1,303Updated this week
- Repository with Hunting and Detection Queries for Microsoft Sentinel and Microsoft Defender XDR☆17Jun 9, 2026Updated last month
- how to strangle threats☆58Updated this week
- A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concret…☆57Mar 5, 2026Updated 4 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- ☆99Jan 7, 2026Updated 6 months ago
- Sigma rules to share with the community☆126Jan 29, 2025Updated last year
- A starter pack of resources to help you get started in Detection Engineering.☆193Jun 4, 2026Updated last month
- Detection Reliability And Precision Efficiency (DRAPE) is an index used to assess detection performance☆36Nov 17, 2025Updated 8 months ago
- Detection engineering template☆15Jul 24, 2025Updated last year
- Mapping of open-source detection rules and atomic tests.☆214Jul 15, 2026Updated last week
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆122Jan 18, 2026Updated 6 months ago
- Collection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc)☆81Apr 12, 2026Updated 3 months ago
- sKaleQL is an opinionated template repository for managing, executing, and organizing Kusto Query Language (KQL) queries against Azure Lo…☆20May 20, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or eve…☆287Jun 23, 2026Updated last month
- An index of publicly available and open-source threat detection rulesets.☆136Apr 17, 2025Updated last year
- KQL Queries. Microsoft Defender, Microsoft Sentinel☆919Jul 16, 2026Updated last week
- Awesome list of keywords and artifacts for Threat Hunting sessions☆668Aug 4, 2025Updated 11 months ago
- KQL Queries☆42Jun 30, 2026Updated 3 weeks ago
- ResearchDev - XDR & SIEM Detection☆66Apr 16, 2025Updated last year
- Awesome Security lists for SOC/CERT/CTI☆1,777Updated this week
- PowerShell tools to help defenders hunt smarter, hunt harder.☆487Oct 29, 2025Updated 8 months ago
- Utilizing your Threat data from a MISP instance into CarbonBlack Response by exposing the data in the Threat Intelligence Feed.☆20May 25, 2022Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Repository with supporting materials for Invictus Academy/Training☆44Updated this week
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆440May 21, 2026Updated 2 months ago
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆816Jan 14, 2026Updated 6 months ago
- Convert Sigma rules to SIEM queries, directly in your browser.☆121Jun 20, 2026Updated last month
- A small guide on Unknown/Orphaned SIDs and some PowerShell tools to help you get rid of them.☆21Apr 16, 2026Updated 3 months ago
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆157Apr 1, 2026Updated 3 months ago
- Sublime rules for email attack detection, prevention, and threat hunting.☆369Updated this week
- This operational dashboard correlates data from Microsoft Defender for Endpoint/Server (MDE) and Azure Monitor Agent (AMA) to identify co…☆17May 13, 2026Updated 2 months ago
- An opensource sigma conversion tool built using pysigma☆173Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- This is a collection of threat detection rules / rules engines that I have come across.☆300May 5, 2024Updated 2 years ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆331Updated this week
- A repository of my own Sigma detection rules.☆167Nov 25, 2025Updated 7 months ago
- A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 D…☆791Jun 3, 2026Updated last month
- This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.☆17Jun 25, 2026Updated 3 weeks ago
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆54Oct 23, 2024Updated last year
- Rulezet is an open-source web platform for sharing, evaluating, improving, and managing cybersecurity detection rules (YARA, Sigma, Suric…☆55Updated this week