Here are
24 public repositories
matching this topic...
Windows Events Attack Samples
☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
Updated
Nov 12, 2022
Python
PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows environments
Misc Threat Hunting Resources
Threatest is a Go framework for end-to-end testing threat detection rules.
A list of useful Detection Engineering-related resources.
Resources To Learn And Understand SIGMA Rules
SIEGMA - Transform Sigma rules into SIEM consumables
Updated
Aug 12, 2022
Python
attack2jira automates the process of standing up a Jira environment that can be used to track and measure ATT&CK coverage
Updated
Jun 20, 2021
Python
Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques
Updated
Oct 17, 2022
JavaScript
A Go implementation and parser for Sigma rules.
Automatic detection engineering technical state compliance
Updated
Jan 18, 2022
Python
simple webapp for converting sigma rules into siem queries using the pySigma library
Updated
Nov 10, 2022
JavaScript
Microsoft 365 Advanced Hunting Queries
An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.
Updated
Mar 12, 2022
Python
Research, Rules, Books, Tools and more basic stuff you can get anywhere
Updated
Oct 28, 2022
Python
Technical resources and knowledge base for dtection.io
Updated
Jun 3, 2021
Shell
Finds Cobalt Strike fingerprint on targets via traffic telemetry
Updated
Oct 7, 2022
Python
Capture all events across all logs produced during the running of a particular exploit/script. Search and filter events
Updated
Sep 5, 2021
PowerShell
Improve this page
Add a description, image, and links to the
detection-engineering
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
detection-engineering
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.