Starred repositories
How to design, build, and operate AI agents for infrastructure teams — safely. 13 chapters covering architecture, sandboxing, credentials, change control, observability, and more.
A project for hunting detection resistant threat activity using ML. It has been proven and battle tested at great scale and is finding threat activity undetected by major name commercial security p…
DevOps Interview Questions
SOCAutomators Substack blog companion — threat research, DBIR analysis, and security operations content
Provides situational awareness of Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) networks in support of network security assessments. #nsacyber
A curated collection of DFIR skills and workflows for InfoSec practitioners.
Learn DevSecOps and Cloud Security Engineering fundamentals.
Sample playbooks for the Palo Alto Networks Ansible modules.
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Pers…
List of books, blogs, newsletters and people!
If you want to become good at AI engineering & system design, join this newsletter 👇
Automated threat intel feed parsing and consolidation💻👾🤖
Cyber Threat Intelligence Data, Indicators, and Analysis
PowerShell tools to help defenders hunt smarter, hunt harder.
Collection of Cyber Threat Intelligence sources from the deep and dark web
A Sigma to Wazuh / OSSEC converter including a generated Windows Sysmon ruleset
A hands-on Detection Engineering lab for building a full Detection-as-Code pipeline. This project uses Stratus Red Team to simulate attacks in AWS, with custom Sigma rules automatically deployed to…
Scan MCP servers for potential threats & security findings.
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
A Post-exploitation Toolset for Interacting with the Microsoft Graph API
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
CiscoCXSecurity / Detection-Engineering-Framework
Forked from Ke0xes/Detection-Engineering-FrameworkThis repository contains a 90-day cybersecurity study plan, along with resources and materials for learning various cybersecurity concepts and technologies. The plan is organized into daily tasks, …