Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
-
Updated
Jan 4, 2024 - Python
Detection engineering is the practice of designing, developing, testing, and maintaining security detections that identify malicious or unauthorized activity. It combines security telemetry, threat intelligence, adversary behavior, and detection analytics to help defenders identify and investigate threats.
Detection engineering commonly involves creating and validating detection rules, analyzing security logs and telemetry, mapping detections to adversary techniques, reducing false positives, and improving detection coverage. It is used across security operations, threat hunting, incident response, and security monitoring.
This topic covers tools, frameworks, detection-as-code practices, detection rules, testing methodologies, and other technologies used to build and maintain effective security detections.
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
Windows Events Attack Samples
Security sensor for realtime threat detection and protection
☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
Awesome Security lists for SOC/CERT/CTI
A curated knowledge base to build, run and mature a SOC (including CSIRT).
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
Splunk Security Content
A resource containing all the tools each ransomware gangs uses
Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows environments
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
Pipelined Query Language
Awesome list of keywords and artifacts for Threat Hunting sessions
MCP to help Defenders Detection Engineer Harder and Smarter
Open-source endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.
A flexible threat detection platform that simplifies rule management and deployment using K8s CronJob and Helm, but can also run standalone or with other job schedulers like Nomad.
Misc Threat Hunting Resources