Splunk Security Content
-
Updated
Dec 17, 2025 - Python
Splunk Security Content
Windows Events Attack Samples
☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
A resource containing all the tools each ransomware gangs uses
Awesome Security lists for SOC/CERT/CTI
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows environments
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
Awesome list of keywords and artifacts for Threat Hunting sessions
Misc Threat Hunting Resources
attack2jira automates the process of standing up a Jira environment that can be used to track and measure ATT&CK coverage
Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques
Pipelined Query Language
lolC2 is a collection of C2 frameworks that leverage legitimate services to evade detection
Threatest is a CLI and Go framework for end-to-end testing threat detection rules.
Mapping of open-source detection rules and atomic tests.
yara detection rules for hunting with the threathunting-keywords project
Add a description, image, and links to the detection-engineering topic page so that developers can more easily learn about it.
To associate your repository with the detection-engineering topic, visit your repo's landing page and select "manage topics."