awesome-detection-engineering
github.com/infosecb/awesome-detection-engineering ↗Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me detection content & signatures resources from awesome-detection-engineering"
Installation instructions →What's inside
Detection Content & Signatures
- Agent Threat Rules (ATR)
An open MIT detection-rule standard for AI-agent and MCP attacks (prompt injection, tool poisoning, context exfiltration), like Sigma or YARA for the agent layer, with OWASP LLM/Agentic and MITRE ATLAS mappings on each rule.
- Anvilogic Detection Armory
Anvilogic's opensource and publicly available detection content.
- AttackRuleMap
Mapping of open-source detection rules and atomic tests.
- AWS GuardDuty Findings
A list of all AWS GuardDuty Findings, their descriptions, and associated data sources.
- Azure Defender for Cloud Security Alerts
A list of all Azure Security for Cloud Alerts, their descriptions, and associated data sources.
- CAR Coverage Comparision
A matrix of MITRE ATT&CK technique IDs and links to available Splunk Security Content, Elastic detection rules, Sigma rules, and CAR content.
Concepts & Frameworks
- Alerting and Detection Strategies (ADS) Framework | Palantir
A blueprint for creating and documenting effective detection content.
- Blue-team-as-Code - the Spiral of Joy | Den Iuzvyk, Oleg Kolesnikov
Blue-Team-as-Code: Lessons From Real-world Red Team Detection Automation Using Logs.
- Cyber Kill Chain | Lockheed Martin
Lockheed Martin's framework that outlines the 7 stages commonly observed in a cyber attack.
- Detection Development Lifecycle | Haider Dost et al.
Snowflake’s implementation of the Detection Development Lifecycle.
- Detection Engineering AI Maturity Framework | Brendan Chamberlain
A community framework with four maturity levels across ten dimensions for assessing how organizations apply AI and LLMs across a detection engineering program, from foundations through the detection lifecycle.
- Detection Engineering Field Manual | Zack Allen
a series of posts exploring the various foundational components of Detection Engineering.
General Resources
- ATT&CK Navigator | MITRE
MITRE's open-source tool that can be used to track detection coverage, visibility, and other efforts and their relationship to the ATT&CK framework.
- Awesome Kubernetes (K8s) Threat Detection
Another Awesome List dedicated to Kubernetes (K8s) threat detection.
- Cloud Threat Landscape | Wiz
A cloud detection engineering-focused database, that lists threat actors known to have compromised cloud environments, the tools and techniques in their arsenal, and the technologies they prefer to target.
- CTI Analyst Field Manual | Andrey Pautov
Practical CTI-to-detection reference covering evidence labels, source reliability, ATT&CK mapping gates, hunting hypotheses, and detection backlog workflow.
- Detection and Response Pipeline
A list of tools for each component of a detection and response pipeline which includes real-world examples.
- Detection at Scale Podcast | Jack Naglieri
A detection engineering-focused podcast featuring many thought leaders in the specialization.
Logging, Monitoring & Data Sources
- Elastalert | Yelp
ElastAlert is a simple framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch.
- Elastic Common Schema
Elastic's proprietary model used as a framework for normalizing security data.
- Exabeam Common Information Model
Exabeam's proprietary model used as a framework for normalizing security data.
- InnerWarden
Autonomous security agent for Linux with real-time threat detection and response via 38 eBPF hooks, 48 detectors, and 23 correlation rules.
- Linux auditd Detection Ruleset
Linux auditd ruleset that produces telemetry required for threat detection use cases.
- Loghub
Opensource and freely available security data sources for research and testing.
Showing a sample of 74 resources. View the full list on GitHub →