Skip to content
#

Detection engineering

Detection engineering is the practice of designing, developing, testing, and maintaining security detections that identify malicious or unauthorized activity. It combines security telemetry, threat intelligence, adversary behavior, and detection analytics to help defenders identify and investigate threats.

Detection engineering commonly involves creating and validating detection rules, analyzing security logs and telemetry, mapping detections to adversary techniques, reducing false positives, and improving detection coverage. It is used across security operations, threat hunting, incident response, and security monitoring.

This topic covers tools, frameworks, detection-as-code practices, detection rules, testing methodologies, and other technologies used to build and maintain effective security detections.

Here are 1,670 public repositories matching this topic...

Digital-Forensics-Guide

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

  • Updated Jan 4, 2024
  • Python

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.

  • Updated Sep 7, 2026
  • Python
Open-Source-Security-Guide

Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

  • Updated Jun 27, 2025
  • Go