A POC to implement Detection-as-Code with Terraform and Sumo Logic.
-
Updated
Jul 27, 2023 - Python
A POC to implement Detection-as-Code with Terraform and Sumo Logic.
Infrastructure as code for CrowdStrike — manage detections, workflows, saved searches, and more with a Terraform-like lifecycle.
A Python-native Detection as Code Framework
Official, curated detection content (Sigma, YARA, IOC packs) for the Rustinel endpoint detection engine.
A Pythonic Detection Rules Framework
Resource for all things threat detection
ESLint-style linter for Sigma detection rules. Validates against Sigma 2.1.0, scores rules across six quality dimensions, emits stable rule IDs.
Rust stream processing engine for real-time detection. Open-source Apache Flink alternative built for detection engineering, fraud prevention, and MITRE ATT&CK coverage. 1.5M events/sec, single 15MB binary, no JVM.
Security infrastructure · Detection as code · Multi-cloud
42-project AWS SOC/SOAR portfolio with Wazuh, TheHive, Cortex, MISP, n8n, AWS security, Terraform, detection engineering, IR, dashboards, and GenAI/MCP/RAG/agentic AI security automation.
Detection as Code pipeline for Splunk detections with YAML rules, schema and SPL validation, PR governance, self-hosted GitHub Actions, and automated Splunk REST deployment.
A comprehensive, modular Detection as Code framework for Microsoft Sentinel, deployable through Terraform with centralised configuration and automated documentation.
This detection engineering repo is for the Detection as Code CI/CD pipeline
Detection-as-code for Microsoft Sentinel and Defender XDR. 12 analytic rules, 10 hunting queries, 4 SOAR playbooks, ATT&CK Navigator coverage, CI validation, and full L3 SOC workflow documentation.
Agentic security detection & response harness — an LLM agent that investigates, authors, validates, and unit-tests Sigma detection rules offline, and documents findings in Notion.
Jibril Runtime Security Public Types. Important for unmarshalling events and similar needs.
Parallax — a self-hosted toolkit for SentinelOne AI-SIEM engineers: map parser & detection-library coverage, visualize MITRE ATT&CK gaps, and validate that detection rules actually fire by generating synthetic test logs from each rule's own logic and verifying the resulting alerts.
All things Detection Engineering from Proposal to Detection-as-Code repository for Microsoft Sentinel and eventually Splunk. YAML-based detection rules mapped to MITRE ATT&CK and Cyber Kill Chain stages, enriched with lifecycle tags and automated for CI/CD deployment.
Detection engineering rules, mappings, tests, and tuning artifacts.
Add a description, image, and links to the detection-as-code topic page so that developers can more easily learn about it.
To associate your repository with the detection-as-code topic, visit your repo's landing page and select "manage topics."