Here are
25 public repositories
matching this topic...
POC framework for detecting LOLBin abuse in Sysmon logs using Splunk SPL. Implements 12 layered checks (signature matching, parent-child anomalies, threat intel, statistical baselines) with risk scoring for automated alert prioritization. Supports standalone Splunk or distributed n8n architecture.
Updated
Dec 2, 2025
Python
Regex patterns for detecting ClickFix social engineering attacks
A collection of custom-built dashboards for threat hunting.
Manage your detection use cases portfolio
Updated
Mar 21, 2025
Python
Wireshark-color-filters for network scanning packets scanning easy to understand attack patterns
Jibril public security detection recipes.
Docker Container for Elastic Detection CLI
Updated
Jan 1, 2024
Dockerfile
Updated
Feb 1, 2021
Python
A command line tool that takes a txt file containing threat intelligence and turns it into a detection rule.
Updated
Feb 10, 2026
Python
Files for the lab of Digital Communications at the University of Seville.
Updated
Mar 11, 2021
Jupyter Notebook
A userscript that enhances the SentinelOne PowerQuery interface with a custom threat hunting button that follow the website UI / UX design interface.
Updated
Jan 13, 2026
JavaScript
A curated list of Awesome Detection Rules
Jibril Runtime Security Public Types. Important for unmarshalling events and similar needs.
An API that takes a txt file containing threat intelligence and turns it into a detection rule.
Updated
Feb 4, 2026
Python
uberAgent configuration: UXM settings & ESA rules + checks
Updated
Feb 5, 2026
PowerShell
Updated
Jan 29, 2026
Python
Sentrilite is a Threat Detection-As-Code & Reponse (DACR) Platform for Linux, Hybrid-Cloud Infrastructure
Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs
Sigma detection rules for hunting with the threathunting-keywords project
Updated
Mar 2, 2025
Python
Improve this page
Add a description, image, and links to the
detection-rules
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
detection-rules
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.