A Python framework for generating synthetic log events without requiring actual infrastructure or actions.
Synthetic Adversarial Log Objects: A Framework for synthentic log generation
A framework for developing alerting and detection strategies for incident response.
A maturity matrix to measure the success of your threat detection program
a series of posts exploring the various foundational components of Detection Engineering
an all-in-one Detection Engineering Operations framework created and maintained by the European Commission to convert your CTI into an actionable detection coverage graph combining threat vectors with detection objectives, and manage your entire detection library from a central repository with a detection-as-code deployment system. The OpenTide format aims at measuring and expanding detection coverage, and its rule deployment engine is fully extensible and support multiple platforms in parallel (leveraging all the technology features and native query language). OpenTide works both within a single DE team as a main framework, and across SOC as a common format to facilitate data interexchange
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.