A POC to implement Detection-as-Code with Terraform and Sumo Logic.
-
Updated
Jul 27, 2023 - Python
A POC to implement Detection-as-Code with Terraform and Sumo Logic.
A Python-native Detection as Code Framework
Infrastructure as code for CrowdStrike — manage detections, workflows, saved searches, and more with a Terraform-like lifecycle.
A Pythonic Detection Rules Framework
Resource for all things threat detection
Rust stream processing engine for real-time detection. Open-source Apache Flink alternative built for detection engineering, fraud prevention, and MITRE ATT&CK coverage. 1.5M events/sec, single 15MB binary, no JVM.
42-project AWS SOC/SOAR portfolio with Wazuh, TheHive, Cortex, MISP, n8n, AWS security, Terraform, detection engineering, IR, dashboards, and GenAI/MCP/RAG/agentic AI security automation.
Security infrastructure · Detection as code · Multi-cloud
Validation harnesses, test cases, and reports for detection quality gates.
A comprehensive, modular Detection as Code framework for Microsoft Sentinel, deployable through Terraform with centralised configuration and automated documentation.
Jibril Runtime Security Public Types. Important for unmarshalling events and similar needs.
This detection engineering repo is for the Detection as Code CI/CD pipeline
Detection-as-code for Microsoft Sentinel and Defender XDR. 12 analytic rules, 10 hunting queries, 4 SOAR playbooks, ATT&CK Navigator coverage, CI validation, and full L3 SOC workflow documentation.
All things Detection Engineering from Proposal to Detection-as-Code repository for Microsoft Sentinel and eventually Splunk. YAML-based detection rules mapped to MITRE ATT&CK and Cyber Kill Chain stages, enriched with lifecycle tags and automated for CI/CD deployment.
Detection as Code portfolio. Validated Python pipeline, Atomic Red Team telemetry, KQL, Sigma, and Sentinel-aligned detections.
Static analysis tool to detect risky and inconsistent patterns in AI-assisted codebases
Detection as Code pipeline for Splunk detections with YAML rules, schema and SPL validation, PR governance, self-hosted GitHub Actions, and automated Splunk REST deployment.
Detection engineering lab using Python, SQL, and YAML to identify malicious behavior through log analysis and detection-as-code workflows.
SOC manager toolkit for assessing detection engineering maturity using Elastic's DEBMM framework — dropdown-driven Excel assessment, auto-scoring, monthly history tracking, exec-ready PowerPoint reports.
Add a description, image, and links to the detection-as-code topic page so that developers can more easily learn about it.
To associate your repository with the detection-as-code topic, visit your repo's landing page and select "manage topics."