Regex patterns for detecting ClickFix social engineering attacks
-
Updated
Dec 4, 2025 - HTML
Regex patterns for detecting ClickFix social engineering attacks
Wireshark-color-filters for network scanning packets scanning easy to understand attack patterns
POC framework for detecting LOLBin abuse in Sysmon logs using Splunk SPL. Implements 12 layered checks (signature matching, parent-child anomalies, threat intel, statistical baselines) with risk scoring for automated alert prioritization. Supports standalone Splunk or distributed n8n architecture.
This detection engineering repo is for the Detection as Code CI/CD pipeline
Official community detection rules for Pipelock - the open-source agent firewall
Jibril Runtime Security Public Types. Important for unmarshalling events and similar needs.
This repo, focuses on detection engineering for Kubernetes Cluster. Sysdig Falco is used to create rules.
Fast DFIR toolkit built for high-volume EVTX and log analysis, delivering rapid parsing, detection-driven triage, timeline reconstruction, and case-ready reporting.
Manage your detection use cases portfolio
Jibril public security detection recipes.
uberAgent configuration: UXM settings & ESA rules + checks
A curated list of Awesome Detection Rules
Files for the lab of Digital Communications at the University of Seville.
An API that takes a txt file containing threat intelligence and turns it into a detection rule.
A collection of custom-built dashboards for threat hunting.
A command line tool that takes a txt file containing threat intelligence and turns it into a detection rule.
Docker Container for Elastic Detection CLI
A userscript that enhances the SentinelOne PowerQuery interface with a custom threat hunting button that follow the website UI / UX design interface.
Check Sigma rules for easy-to-bypass whitelists to make them more robust (https://github.com/SigmaHQ/sigma)
Add a description, image, and links to the detection-rules topic page so that developers can more easily learn about it.
To associate your repository with the detection-rules topic, visit your repo's landing page and select "manage topics."