Detection Engineering
A framework for developing alerting and detection strategies for incident response.
Small and highly portable detection tests based on MITRE's ATT&CK.
Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifyin…
☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
Threatest is a CLI and Go framework for end-to-end testing threat detection rules.
StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.
Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.
✨ A compilation of suggested tools/services for each component in a detection and response pipeline, along with real-world examples. The purpose is to create a reference hub for designing effective…
A tool that allows you to document and assess any security automation in your SOC
Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help detect real-world adversary behaviors in their environments.
A curated list of awesome Memory Forensics for DFIR
This repo contains IOC, malware and malware analysis associated with Public cloud
pocket guide for core detection engineering concepts
A curated list of Awesome Threat Intelligence resources
A collection of sources of documentation, as well as field best practices, to build/run a SOC
Cyber Defense Matrix Public Website
Public Repository of Open Source Tools for Cyber Threat Intelligence Analysts and Researchers
A robust, and flexible open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by Data Scientists & Security Analysts from the Cyber Security I…
A python library for user-friendly forecasting and anomaly detection on time series.
💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
This project aims to compare and evaluate the telemetry of various EDR products.
Detect Tactics, Techniques & Combat Threats