A POC to implement Detection-as-Code with Terraform and Sumo Logic.
-
Updated
Jul 27, 2023 - Python
A POC to implement Detection-as-Code with Terraform and Sumo Logic.
Infrastructure as code for CrowdStrike — manage detections, workflows, saved searches, and more with a Terraform-like lifecycle.
A Python-native Detection as Code Framework
Official, curated detection content (Sigma, YARA, IOC packs) for the Rustinel endpoint detection engine.
A Pythonic Detection Rules Framework
Resource for all things threat detection
ESLint-style linter for Sigma detection rules. Validates against Sigma 2.1.0, scores rules across six quality dimensions, emits stable rule IDs.
Rust stream processing engine for real-time detection. Open-source Apache Flink alternative built for detection engineering, fraud prevention, and MITRE ATT&CK coverage. 1.5M events/sec, single 15MB binary, no JVM.
Security infrastructure · Detection as code · Multi-cloud
42-project AWS SOC/SOAR portfolio with Wazuh, TheHive, Cortex, MISP, n8n, AWS security, Terraform, detection engineering, IR, dashboards, and GenAI/MCP/RAG/agentic AI security automation.
A comprehensive, modular Detection as Code framework for Microsoft Sentinel, deployable through Terraform with centralised configuration and automated documentation.
Detection as Code pipeline for Splunk detections with YAML rules, schema and SPL validation, PR governance, self-hosted GitHub Actions, and automated Splunk REST deployment.
This detection engineering repo is for the Detection as Code CI/CD pipeline
Agentic security detection & response harness — an LLM agent that investigates, authors, validates, and unit-tests Sigma detection rules offline, and documents findings in Notion.
Detection-as-code for Microsoft Sentinel and Defender XDR. 12 analytic rules, 10 hunting queries, 4 SOAR playbooks, ATT&CK Navigator coverage, CI validation, and full L3 SOC workflow documentation.
Detection engineering rules, mappings, tests, and tuning artifacts.
All things Detection Engineering from Proposal to Detection-as-Code repository for Microsoft Sentinel and eventually Splunk. YAML-based detection rules mapped to MITRE ATT&CK and Cyber Kill Chain stages, enriched with lifecycle tags and automated for CI/CD deployment.
Jibril Runtime Security Public Types. Important for unmarshalling events and similar needs.
Parallax — a self-hosted toolkit for SentinelOne AI-SIEM engineers: map parser & detection-library coverage, visualize MITRE ATT&CK gaps, and validate that detection rules actually fire by generating synthetic test logs from each rule's own logic and verifying the resulting alerts.
Add a description, image, and links to the detection-as-code topic page so that developers can more easily learn about it.
To associate your repository with the detection-as-code topic, visit your repo's landing page and select "manage topics."