Skip to content
78

Awesome Detection Engineering

Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.

1.3k stars152 forks73 entriesLast push Aug 3, 2026 (1 month ago)License CC0-1.0

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Concepts & Frameworks

MITRE ATT&CK

The foundational framework of adversary tactics, techniques, and procedures based on real-world observations.

In 4 listsDetails

Alerting and Detection Strategies (ADS) Framework | Palantir

A blueprint for creating and documenting effective detection content.

In 2 lists

Detection Engineering Maturity Matrix | Kyle Bailey

A detailed matrix that serves as a tool to measure the overall maturity of an organization's Detection Engineering program.

Detection Maturity Level (DML) Model | Ryan Stillions

Defines and describes 8 different levels of an organization's threat detection program maturity.

The Pyramid of Pain | David J Bianco

A model used to describe various categorizations of indicator's of compromise and their level of effectiveness in detecting threat actors.

Cyber Kill Chain | Lockheed Martin

Lockheed Martin's framework that outlines the 7 stages commonly observed in a cyber attack.

In 2 lists

MaGMa (Management, Growth and Metrics & Assessment) Use Case Defintion Model

A business-centric approach for defining threat detection use cases.

Synthetic Adversarial Log Objects (SALO) | Splunk

Synthetic Adversarial Log Objects (SALO) is a framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event.

In 2 lists

The Zen of Security Rules | Justin Ibarra

Outlines 19 aphorisms that serve as universal principles for the creation of high quality detection content.

Blue-team-as-Code - the Spiral of Joy | Den Iuzvyk, Oleg Kolesnikov

Blue-Team-as-Code: Lessons From Real-world Red Team Detection Automation Using Logs.

Detection Development Lifecycle | Haider Dost et al.

Snowflake’s implementation of the Detection Development Lifecycle.

Threat Detection Maturity Framework | Haider Dost of Snowflake

A maturity matrix to measure the success of your threat detection program.

Elastic's Detection Engineering Behavior Maturity Model

Elastic's qualitative and quantitative approach to measuring threat detection program maturity.

Detection Engineering AI Maturity Framework | Brendan Chamberlain

A community framework with four maturity levels across ten dimensions for assessing how organizations apply AI and LLMs across a detection engineering program, from foundations through the detection lifecycle.

Prioritizing Detection Engineering | Ryan McGeehan

A longtime detection engineer outlines how a detection engineering program should be built from the ground up.

Detection Engineering Field Manual | Zack Allen

a series of posts exploring the various foundational components of Detection Engineering.

Open Threat Informed Detection Engineering aka OpenTide'

an all-in-one Detection Engineering Operations framework created and maintained by the European Commission to convert your CTI into an actionable detection coverage graph combining threat vectors with detection objectives, and manage your entire detection library from a central repository with a…

ThreatMapper | Andrey Pautov

CTI-to-detection workbench for mapping threat reports to ATT&CK, comparing TTP overlap with groups and campaigns, identifying detection gaps, and exporting analyst-ready outputs.

ZettelForge

Agentic memory system that treats Sigma and YARA rules as first-class memory entities, with an LLM rule explainer, STIX 2.1 knowledge graph of CTI entities, and offline-first RAG to connect rules to the actors and techniques they detect. Python, MIT.

Detection Content & Signatures

Rulehound

An index of publicly available and open-source threat detection rulesets.

MITRE Cyber Analytics Repository (CAR)

MITRE's well-maintained repository of detection content.

In 3 lists

CAR Coverage Comparision

A matrix of MITRE ATT&CK technique IDs and links to available Splunk Security Content, Elastic detection rules, Sigma rules, and CAR content.

Sigma Rules

Sigma's repository of turnkey detection content. Content can be converted for use with most SIEMs.

In 5 listsDetails

Sigma rule converter

An opensource tool that can convert detection content for use with most SIEMs.

RSigma | Timescale

A complete Sigma detection engineering toolkit with parser, evaluation engine, rule conversion, streaming runtime, linter, CLI, MCP, and LSP.

In 2 lists

AttackRuleMap

Mapping of open-source detection rules and atomic tests.

Splunk Security Content

Splunk's open-source and frequently updated detection content that can be tweaked for use in other tools.

In 2 lists

Elastic Detection Rules

Elastic's detection rules written natively for the Elastic SIEM. Can easily be converted for use by other SIEMs using Uncoder.

In 3 lists

Elastic Endpoint Behavioral Rules

Elastic's endpoint behavioral (prevention) rules written in EQL, natively for the Elastic endpoint agent.

In 3 lists

Agent Threat Rules (ATR)

An open MIT detection-rule standard for AI-agent and MCP attacks (prompt injection, tool poisoning, context exfiltration), like Sigma or YARA for the agent layer, with OWASP LLM/Agentic and MITRE ATLAS mappings on each rule.

In 3 lists

Chronicle (GCP) Detection Rules

Chronicle's detection rules written natively for the the Chronicle Platform.

In 2 lists

Exabeam Content Library

Exabeam's out of the box detection content compatible with the Exabeam Common Information Model.

Panther Labs Detection Rules

Panther Lab's native detection rules.

Anvilogic Detection Armory

Anvilogic's opensource and publicly available detection content.

AWS GuardDuty Findings

A list of all AWS GuardDuty Findings, their descriptions, and associated data sources.

GCP Security Command Center Findings

A list of all GCP Security Command Center Findings, their descriptions, and associated data sources.

Azure Defender for Cloud Security Alerts

A list of all Azure Security for Cloud Alerts, their descriptions, and associated data sources.

In 2 lists

Center for Threat Informed Defense Security Stack Mappings

Describes cloud computing platform's (Azure, AWS) built-in detection capabilities and their mapings to the MITRE ATT&CK framework.

Detection Engineering with Splunk

A GitHub repo dedicated to sharing detection analytics in SPL.

Google Cloud Security Analytics

This repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud.

In 2 lists

KQL Advanced Hunting Queries & Analytics Rules

A list of endpoint detections and hunting queries for Microsoft Defender for Endpoint, Defender For Identity, and Defender For Cloud Apps.

In 2 lists

Sigma2KQL

A repository of all SIGMA rules converted to KQL that runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository.

In 2 lists

TerraSigma

A repository of all SIGMA rules converted to Microsoft Sentinel Terraform Scheduled analytic resources. The repository runs on a weekly schedule to update the repository and align with the up to date version of the SIGMA rules repository. Proper entity mapping is completed for the rules to ensure…

In 2 lists

Detections Digest | Sergey Polzunov

A newsletter that features updates from many popular detection content sources listed here.

Logging, Monitoring & Data Sources

Windows Logging Cheatsheets

Multiple cheatsheets outlined recommendations for Windows Event logging at various levels of granularity.

In 2 lists

Linux auditd Detection Ruleset

Linux auditd ruleset that produces telemetry required for threat detection use cases.

In 3 lists

MITRE ATT&CK Data Sources Blog Post

MITRE describes various data sources and how they relate to the TTPs found in the MITRE ATT&CK framework.

In 2 lists

MITRE ATT&CK Data Sources List

Data source objects added to MITRE ATT&CK as part of v10.

In 2 lists

Splunk Common Information Model (CIM)

Splunk's proprietary model used as a framework for normalizing security data.

Elastic Common Schema

Elastic's proprietary model used as a framework for normalizing security data.

Exabeam Common Information Model

Exabeam's proprietary model used as a framework for normalizing security data.

Open Cybersecurity Schema Framework (OCSF)

An opensource security data source and event schema.

osquery | Facebook

A SQL-powered operating system instrumentation, monitoring, and analytics framework that exposes OS data as relational tables for querying and detection.

In 5 listsDetails

Loghub

Opensource and freely available security data sources for research and testing.

Elastalert | Yelp

ElastAlert is a simple framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch.

Matano

Open source cloud-native security lake platform (SIEM alternative) for threat hunting, Python detections-as-code, and incident response on AWS 🦀.

In 4 lists

Microsoft XDR Advanced Hunting Schema

To help with multi-table queries, you can use the advanced hunting schema, which includes tables and columns with event information and details about devices, alerts, identities, and other entity types.

In 2 lists

InnerWarden

Autonomous security agent for Linux with real-time threat detection and response via 38 eBPF hooks, 48 detectors, and 23 correlation rules.

In 2 lists

Rustinel | Karib0u

Open-source endpoint detection engine for Windows and Linux that collects ETW/eBPF telemetry and evaluates Sigma, YARA, and IOC detections.

In 2 lists

SOCTalk

Open source, LLM driven SOC automation platform for MSPs and MSSPs built on Wazuh. Triages, investigates, and escalates alerts through a two tier AI pipeline with human in the loop review, multi tenant isolation, and a no code triage policy editor backed by deterministic execution. Apache 2.0.

In 2 lists

General Resources

ATT&CK Navigator | MITRE

MITRE's open-source tool that can be used to track detection coverage, visibility, and other efforts and their relationship to the ATT&CK framework.

Detection Engineering Weekly | Zack Allen

A newsletter dedicated to news and how-tos for Detection Engineering.

In 3 lists

Detection Engineering Twitter List | Zack Allen

A Twitter list of Detection Engineering thought leaders.

DETT&CT: MAPPING YOUR BLUE TEAM TO MITRE ATT&CK™

Outlines a methodology measuring security data visibility and detection coverage against the MITRE ATT&CK framework.

In 2 lists

Awesome Kubernetes (K8s) Threat Detection

Another Awesome List dedicated to Kubernetes (K8s) threat detection.

Detection and Response Pipeline

A list of tools for each component of a detection and response pipeline which includes real-world examples.

Living Off the Living Off the Land

A collection of resources for thriving off the land.

In 2 lists

Detection at Scale Podcast | Jack Naglieri

A detection engineering-focused podcast featuring many thought leaders in the specialization.

Cloud Threat Landscape | Wiz

A cloud detection engineering-focused database, that lists threat actors known to have compromised cloud environments, the tools and techniques in their arsenal, and the technologies they prefer to target.

CTI Analyst Field Manual | Andrey Pautov

Practical CTI-to-detection reference covering evidence labels, source reliability, ATT&CK mapping gates, hunting hypotheses, and detection backlog workflow.

Splunk ES Correlation Searches Best Practices | OpsTune

A highly detailed guide to producing high quality detection content in the Splunk Enterprise Security app.

How Google Does It: Making threat detection high-quality, scalable, and modern | Anton Chuvakin, Tim Nguyen

The team at Google highlights 5 key principles for building a high quality, scalable and modern threat detection program.

SOCLabs

A lab for blue teamers and detection engineers, with real threat data and support for popular SIEM query languages, enabling hands-on learning and practice in detection rule writing and threat hunting.

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed today
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
88

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k563 entriesPushed 27 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago