Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Categories
  3. Security
  4. Detection Engineering

Detection Engineering

The "Awesome Detection Engineering" project is a curated collection of resources aimed at enhancing the design, implementation, and operation of cybersecurity detection controls. Detection engineering focuses on developing effective strategies and tools to identify and respond to security threats in real-time. This list encompasses a variety of resources, including frameworks, tools, methodologies, and community contributions that support security professionals in building robust detection capabilities. Whether you are a beginner seeking foundational knowledge or an experienced practitioner looking for advanced techniques, this collection offers valuable insights and practical tools to strengthen your cybersecurity posture. Dive in to discover how to elevate your detection engineering skills and improve your organization's security defenses.

detection-engineeringcybersecuritythreat-detectionsecurity-toolsincident-responsemonitoringsecurity-controls
RSSView on GitHub
1.2k stars112 forks0 contributorsUpdated
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub

Related Awesome Lists

📦
Hacking

The "Awesome Hacking" project is a curated resource list designed for those interested in the field of hacking, which involves exploring and exploiting vulnerabilities in computer systems and networks. This list encompasses a wide range of categories, including penetration testing tools, ethical hacking tutorials, security research papers, and community forums. It serves as a valuable resource for beginners looking to learn the basics of cybersecurity, as well as experienced professionals seeking advanced techniques and tools. Whether you are aiming to enhance your skills or stay updated on the latest security trends, this collection offers a wealth of information to support your hacking journey.

16.1k
📦
Security

The "Awesome Security" project is a curated collection of resources focused on enhancing security practices in the digital realm. This list encompasses a wide range of categories including security tools, libraries, frameworks, tutorials, and best practices for various platforms and technologies. It is designed to benefit security professionals, developers, and system administrators alike, providing valuable insights and tools to safeguard applications and data. Whether you are a beginner looking to understand security fundamentals or an experienced practitioner seeking advanced techniques, this project offers a wealth of information to help you improve your security posture and protect your digital assets.

14.2k
📦
Malware Analysis

The "Awesome Malware Analysis" project is a curated resource list designed to assist security professionals and researchers in the field of malware analysis. Malware analysis involves examining malicious software to understand its behavior, functionality, and impact. This list includes tools for static and dynamic analysis, reverse engineering resources, malware databases, and educational materials such as tutorials and courses. It is valuable for both beginners looking to learn the basics and experienced analysts seeking advanced techniques and tools. Users can find a wealth of resources to enhance their skills and improve their malware analysis capabilities.

13.6k
📦
Web Security

The "Awesome Web Security" project is a curated collection of resources focused on the security of web applications and services. Web security encompasses practices and technologies designed to protect websites and online services from cyber threats, vulnerabilities, and attacks. This list includes tools for penetration testing, secure coding practices, frameworks, libraries, and educational materials such as articles and tutorials. It is valuable for developers, security professionals, and researchers who seek to enhance their understanding of web security and implement robust security measures. Users can find essential tools and knowledge to safeguard their web applications effectively and stay ahead of potential threats.

13.2k

Table of Contents

4 sections · 65 projects

Concepts & Frameworks

16 projects
MITRE ATT&CK

attack.mitre.org
Alerting and Detection Strategies (ADS) Framework | PalantirAlerting and Detection Strategies (ADS) Framework | Palantir

A framework for developing rigorous, documented alerting and detection strategies to improve incident response efficacy.

#peer-review#security#mitre-attack
Stars890
Forks138
Last commit10 months ago
Detection Engineering Maturity Matrix | Kyle Bailey

detectionengineering.io
Detection Maturity Level (DML) Model | Ryan Stillions

ryanstillions.blogspot.com
The Pyramid of Pain | David J Bianco

detect-respond.blogspot.com
Cyber Kill Chain | Lockheed Martin

lockheedmartin.com
MaGMa (Management, Growth and Metrics & Assessment) Use Case Defintion Model

betaalvereniging.nl
Synthetic Adversarial Log Objects (SALO) | SplunkSynthetic Adversarial Log Objects (SALO) | Splunk

A Python framework for generating synthetic log events without requiring actual infrastructure or actions.

#devops#data-science#synthetic-data
Stars92
Forks11
Last commit2 years ago
The Zen of Security Rules | Justin Ibarra

br0k3nlab.com
Blue-team-as-Code - the Spiral of Joy | Den Iuzvyk, Oleg Kolesnikov

sansorg.egnyte.com
Detection Development Lifecycle | Haider Dost et al.

medium.com
Threat Detection Maturity Framework | Haider Dost of Snowflake

medium.com
Elastic's Detection Engineering Behavior Maturity Model

elastic.co
Prioritizing Detection Engineering | Ryan McGeehan

medium.com
Detection Engineering Field Manual | Zack Allen

detectionengineering.net
Open Threat Informed Detection Engineering aka OpenTide'

github.com

Detection Content & Signatures

24 projects
Rulehound

rulehound.com
MITRE Cyber Analytics Repository (CAR)

car.mitre.org
CAR Coverage Comparision

car.mitre.org
Sigma RulesSigma Rules

A generic and open signature format for describing log event detections, shareable across SIEM systems.

#signatures#yaml#siem
Stars10,775
Forks2,715
Last commit2 days ago
Sigma rule converter

sigconverter.io
AttackRuleMap

attackrulemap.com
Splunk Security ContentSplunk Security Content

An open-source repository of security detections, analytic stories, and response playbooks mapped to MITRE ATT&CK for Splunk Enterprise Security.

#splunk-enterprise-security#security-analytics#cicd
Stars1,656
Forks477
Last commit1 day ago
Elastic Detection RulesElastic Detection Rules

A public repository for developing, testing, and maintaining detection rules for Elastic Security's SIEM, with tools for Detections as Code.

#siem#security-automation#security
Stars2,663
Forks684
Last commit1 day ago
Elastic Endpoint Behavioral RulesElastic Endpoint Behavioral Rules

Open-source detection logic (rules, YARA, EQL) for Elastic Security's endpoint protection against malware, ransomware, and advanced threats.

#malware-protection#yara-rules#open-security
Stars1,461
Forks166
Last commit3 days ago
Elastic Yara SignaturesElastic Yara Signatures

Open-source detection logic (rules, YARA, ransomware protection) for Elastic Security's endpoint protection platform.

#malware-protection#yara-rules#open-security
Stars1,461
Forks166
Last commit3 days ago
Chronicle (GCP) Detection RulesChronicle (GCP) Detection Rules

A collection of example YARA-L detection rules and dashboards for Google Security Operations (SecOps).

#siem#detection-as-code#yara-l
Stars508
Forks133
Last commit1 month ago
Exabeam Content LibraryExabeam Content Library

An online repository of Exabeam's security detection content, including data sources, use cases, and rules based on the Common Information Model 2.0.

#siem-content#security-analytics#log-sources
Stars32
Forks7
Last commit1 month ago
Panther Labs Detection RulesPanther Labs Detection Rules

A collection of built-in detection rules and policies for Panther, a modern SIEM, enabling security monitoring as code.

#yaml#siem#detection-as-code
Stars458
Forks201
Last commit7 days ago
Anvilogic Detection ArmoryAnvilogic Detection Armory

An open-source repository of cybersecurity detection rules and threat identifiers for security teams to enhance threat detection capabilities.

#security-analytics#splunk#mitre-attack
Stars119
Forks8
Last commit3 months ago
AWS GuardDuty Findings

docs.aws.amazon.com
GCP Security Command Center Findings

cloud.google.com
Azure Defender for Cloud Security Alerts

docs.microsoft.com
Center for Threat Informed Defense Security Stack MappingsCenter for Threat Informed Defense Security Stack Mappings

A collection of native security controls for major cloud platforms mapped to MITRE ATT&CK techniques to enable threat-informed defense decisions.

#yaml#azure#security
Stars389
Forks61
Last commit2 years ago
Detection Engineering with SplunkDetection Engineering with Splunk

A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.

#text4shell#vulnerability#splunk
Stars69
Forks10
Last commit21 days ago
Google Cloud Security AnalyticsGoogle Cloud Security Analytics

A community-driven collection of pre-built security analytics queries and rules for auditing and threat detection in Google Cloud.

#security-analytics#yara-l#log-analytics
Stars370
Forks76
Last commit2 years ago
KQL Advanced Hunting Queries & Analytics RulesKQL Advanced Hunting Queries & Analytics Rules

A collection of ready-to-use KQL queries for threat hunting, detection, and analytics in Microsoft Defender for Endpoint and Azure Sentinel.

#azure-sentinel#security-analytics#vulnerability-management
Stars1,721
Forks325
Last commit1 month ago
Sigma2KQLSigma2KQL

Automatically converts Sigma detection rules to Kusto Query Language (KQL) for Microsoft Defender and Sentinel.

#detection-as-code#sigma-rules#security-automation
Stars6
Forks0
Last commit4 days ago
TerraSigmaTerraSigma

Automates conversion of Sigma rules to Terraform and Sentinel YAML for detection engineering in Microsoft Sentinel.

#devops#sigma-rules#security-automation
Stars5
Forks0
Last commit4 days ago
Detections Digest | Sergey Polzunov

detections-digest.rulecheck.io

Logging, Monitoring & Data Sources

13 projects
Windows Logging Cheatsheets

malwarearchaeology.com
Linux auditd Detection RulesetLinux auditd Detection Ruleset

A production-ready auditd configuration for Linux security monitoring that works out-of-the-box across major distributions.

#security-hardening#linux-security#auditd-configuration
Stars1,870
Forks308
Last commit2 months ago
MITRE ATT&CK Data Sources Blog Post

medium.com
MITRE ATT&CK Data Sources List

attack.mitre.org
Splunk Common Information Model (CIM)

docs.splunk.com
Elastic Common Schema

elastic.co
Exabeam Common Information ModelExabeam Common Information Model

A hierarchical framework defining the structure of security content across Exabeam products for event normalization and analysis.

#event-normalization#siem#exabeam
Stars12
Forks4
Last commit17 days ago
Open Cybersecurity Schema Framework (OCSF)

schema.ocsf.io
LoghubLoghub

A large collection of real-world system log datasets for AI-driven log analytics research.

#logs#operating-systems#distributed-systems
Stars2,779
Forks783
Last commit2 days ago
Elastalert | YelpElastalert | Yelp

A simple framework for alerting on anomalies, spikes, or other patterns in Elasticsearch data.

#devops#siem#observability
Stars7,988
Forks1,690
Last commit1 year ago
MatanoMatano

An open source, serverless security data lake for AWS that normalizes logs, enables detection-as-code, and supports petabyte-scale threat hunting.

#siem-alternative#aws-serverless#security-analytics
Stars1,687
Forks122
Last commit1 year ago
Microsoft XDR Advanced Hunting Schema

learn.microsoft.com
InnerWardenInnerWarden

An autonomous open-source security agent for Linux that detects, scores, and automatically responds to threats using eBPF, AI, and collaborative defense.

#honeypot#self-hosted-security#sigma-rules
Stars162
Forks30
Last commit22 days ago

General Resources

12 projects
ATT&CK Navigator | MITRE

mitre-attack.github.io
Detection Engineering Weekly | Zack Allen

detectionengineering.net
Detection Engineering Twitter List | Zack Allen

twitter.com
DETT&CT: MAPPING YOUR BLUE TEAM TO MITRE ATT&CK™

mbsecure.nl
Awesome Kubernetes (K8s) Threat DetectionAwesome Kubernetes (K8s) Threat Detection

A curated list of resources for detecting threats and defending Kubernetes systems.

#container-security#cloud-native-security#security-hardening
Stars409
Forks44
Last commit2 years ago
Detection and Response PipelineDetection and Response Pipeline

A curated reference hub of tools and real-world examples for designing effective threat detection and response pipelines.

#security-reference#self-hosted-security#security-automation
Stars296
Forks24
Last commit2 years ago
Living Off the Living Off the Land

lolol.farm
Detection at Scale Podcast | Jack Naglieri

podcasts.apple.com
Cloud Threat Landscape | Wiz

threats.wiz.io
Splunk ES Correlation Searches Best Practices | OpsTuneSplunk ES Correlation Searches Best Practices | OpsTune

A collection of Splunk SPL queries and prototypes for threat hunting and detection engineering.

#security-analytics#siem#rules
Stars294
Forks46
Last commit2 years ago
How Google Does It: Making threat detection high-quality, scalable, and modern | Anton Chuvakin, Tim Nguyen

cloud.google.com
SOCLabs

soc-labs.top