Detection Engineering research, open-source tools, conference presentations, and technical publications shared with the security community.
☆28Dec 17, 2025Updated 8 months ago
Alternatives and similar repositories for security-publications
Users that are interested in security-publications are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A guide to simplify the process of evaluating Datadog's Cloud SIEM security capabilities to detect AWS threats.☆20Jul 24, 2023Updated 3 years ago
- A collection of utilities to help with analysis on the command line.☆18Aug 9, 2024Updated 2 years ago
- Repository with Sample threat hunting notebooks on Security Event Log Data Sources☆70Dec 2, 2022Updated 3 years ago
- A POC to implement Detection-as-Code with Terraform and Sumo Logic.☆31Jul 27, 2023Updated 3 years ago
- A script to create and assign SOP tasks into the cases☆20Aug 16, 2020Updated 6 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Presentations from the CX Security Labs team☆35Jun 25, 2026Updated 2 months ago
- bro on debian with elasticsearch support☆24Mar 27, 2017Updated 9 years ago
- RID Hijacking Proof of Concept script by Kevin Joyce☆15Oct 30, 2018Updated 7 years ago
- Cloud-native SIEM for intelligent security analytics for your entire enterprise.☆22Nov 22, 2021Updated 4 years ago
- Tools for Incident Response and Malware Analysis☆11Feb 9, 2025Updated last year
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆22Jan 30, 2018Updated 8 years ago
- Issues to consider when planning a red team exercise.☆14Aug 23, 2017Updated 9 years ago
- ☆13May 9, 2022Updated 4 years ago
- Find world writable directories that contain a .exe or .dll file☆13Aug 31, 2021Updated 5 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Threat Detection & Anomaly Detection rules for popular open-source components☆53Jul 27, 2022Updated 4 years ago
- Easily embed table in your Pelican articles.☆12Jan 12, 2023Updated 3 years ago
- The aim of this repository is to provide a list of examples of tools, sources and measures available to incident response teams☆65Jul 15, 2020Updated 6 years ago
- Mapping NSM rules to MITRE ATT&CK☆72Aug 29, 2020Updated 6 years ago
- Nagios dashboard in ncurses☆18Jul 12, 2017Updated 9 years ago
- Detection Ideas & Rules repository.☆179Sep 10, 2021Updated 4 years ago
- security trust center project☆17Mar 28, 2026Updated 5 months ago
- ☆15Jan 10, 2019Updated 7 years ago
- study material used for the 2018 CISSP exam☆11May 20, 2019Updated 7 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- TIBER-Cases is a project created to give cases of The Hive platform for Threat Intelligence Analysts mainly. All the cases are mapped to …☆27Jul 13, 2022Updated 4 years ago
- Living off the False Positive!☆42Apr 3, 2026Updated 5 months ago
- 🚨ATTENTION🚨 The VERIS mappings have migrated to the Center’s Mappings Explorer project. See README below. This repository is kept here …☆72Apr 3, 2024Updated 2 years ago
- Find kernel32 base and API addresses. Simple C++ implementation☆24Apr 7, 2022Updated 4 years ago
- Dash rootkit. Linux Trojan Backdoor. (MALWARE)☆12Apr 3, 2023Updated 3 years ago
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆16Jul 6, 2026Updated 2 months ago
- ☆21Jul 13, 2026Updated last month
- A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concret…☆61Mar 5, 2026Updated 6 months ago
- A Python, Boto3 script that leverages a forensic volume to attach & mount to a selected instance, run a memory dump, unmount and detach f…☆12Jul 15, 2020Updated 6 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆31Nov 25, 2025Updated 9 months ago
- High performance time ordered PCAP merging utility☆24Jun 20, 2022Updated 4 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆161Mar 10, 2025Updated last year
- Hogzilla is an Intrusion Detection System (IDS) supported by Snort, Apache Spark, HBase and libnDPI, which provides Network Anomaly Detec…☆28Apr 18, 2018Updated 8 years ago
- This is a collection of Security Baselines that I use in my virtual lab environment.☆23Mar 11, 2020Updated 6 years ago
- ☆19May 5, 2024Updated 2 years ago
- FAIR cyber risk quantification toolkits, agent-based control simulation (FAIR-CAM), threat event frequency estimator (PyPI), LLM classifi…☆30Jul 3, 2026Updated 2 months ago