Detection Engineering research, open-source tools, conference presentations, and technical publications shared with the security community.
☆28Dec 17, 2025Updated 9 months ago
Alternatives and similar repositories for security-publications
Users that are interested in security-publications are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A guide to simplify the process of evaluating Datadog's Cloud SIEM security capabilities to detect AWS threats.☆20Jul 24, 2023Updated 3 years ago
- A collection of utilities to help with analysis on the command line.☆18Aug 9, 2024Updated 2 years ago
- Repository with Sample threat hunting notebooks on Security Event Log Data Sources☆70Dec 2, 2022Updated 3 years ago
- A POC to implement Detection-as-Code with Terraform and Sumo Logic.☆31Jul 27, 2023Updated 3 years ago
- A script to create and assign SOP tasks into the cases☆20Aug 16, 2020Updated 6 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Oxomium is a cybersecurity gouvernance and conformity (GRC) tool for CISCO and SECOPS. By linking framework requirements, controld schedu…☆19Updated this week
- bro on debian with elasticsearch support☆24Mar 27, 2017Updated 9 years ago
- Configure and deploy AWS GuardDuty.☆13Sep 9, 2025Updated last year
- Hikeshi is a security incident response application that keeps documenting incidents simple, so you can focus on fighting fires.☆21Mar 6, 2023Updated 3 years ago
- Cloud-native SIEM for intelligent security analytics for your entire enterprise.☆22Nov 22, 2021Updated 4 years ago
- Tools for Incident Response and Malware Analysis☆11Feb 9, 2025Updated last year
- Issues to consider when planning a red team exercise.☆14Aug 23, 2017Updated 9 years ago
- Find world writable directories that contain a .exe or .dll file☆13Aug 31, 2021Updated 5 years ago
- All my blogs for ExpDev, HTB, BinaryExploit, Etc.☆14Jul 17, 2024Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Threat Detection & Anomaly Detection rules for popular open-source components☆53Jul 27, 2022Updated 4 years ago
- The aim of this repository is to provide a list of examples of tools, sources and measures available to incident response teams☆65Jul 15, 2020Updated 6 years ago
- Mapping NSM rules to MITRE ATT&CK☆72Aug 29, 2020Updated 6 years ago
- Detection Ideas & Rules repository.☆179Sep 10, 2021Updated 5 years ago
- security trust center project☆17Mar 28, 2026Updated 6 months ago
- ☆15Jan 10, 2019Updated 7 years ago
- Suricata RPMs for CentOS/RHEL and Fedora☆19Sep 15, 2026Updated last week
- TIBER-Cases is a project created to give cases of The Hive platform for Threat Intelligence Analysts mainly. All the cases are mapped to …☆27Jul 13, 2022Updated 4 years ago
- Living off the False Positive!☆42Apr 3, 2026Updated 5 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- 🚨ATTENTION🚨 The VERIS mappings have migrated to the Center’s Mappings Explorer project. See README below. This repository is kept here …☆72Apr 3, 2024Updated 2 years ago
- Find kernel32 base and API addresses. Simple C++ implementation☆24Apr 7, 2022Updated 4 years ago
- Dash rootkit. Linux Trojan Backdoor. (MALWARE)☆12Apr 3, 2023Updated 3 years ago
- 📈 SecKC Honeypot dashboard☆19Oct 20, 2017Updated 8 years ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆18Jul 6, 2026Updated 2 months ago
- A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concret…☆61Mar 5, 2026Updated 6 months ago
- A Python, Boto3 script that leverages a forensic volume to attach & mount to a selected instance, run a memory dump, unmount and detach f…☆12Jul 15, 2020Updated 6 years ago
- ☆31Nov 25, 2025Updated 10 months ago
- High performance time ordered PCAP merging utility☆24Jun 20, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- SIEGMA - Transform Sigma rules into SIEM consumables☆161Mar 10, 2025Updated last year
- Hogzilla is an Intrusion Detection System (IDS) supported by Snort, Apache Spark, HBase and libnDPI, which provides Network Anomaly Detec…☆28Apr 18, 2018Updated 8 years ago
- YAFRA is a semi-automated framework for analyzing and representing reports about IT Security incidents.☆27Dec 14, 2021Updated 4 years ago
- ☆19May 5, 2024Updated 2 years ago
- ☆22Jul 13, 2026Updated 2 months ago
- FAIR cyber risk quantification toolkits, agent-based control simulation (FAIR-CAM), threat event frequency estimator (PyPI), LLM classifi…☆30Jul 3, 2026Updated 2 months ago
- Bro Intel Feed Linter☆26Aug 30, 2019Updated 7 years ago