awesome-detection-engineering
github.com/infosecb/awesome-detection-engineering ↗Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me concepts & frameworks resources from awesome-detection-engineering"
Installation instructions →What's inside
Concepts & Frameworks
- Alerting and Detection Strategies (ADS) Framework | Palantir
Palantir - A blueprint for creating and documenting effective detection content.
- Blue-team-as-Code - the Spiral of Joy | Den Iuzvyk, Oleg Kolesnikov
Den Iuzvyk, Oleg Kolesnikov - Blue-Team-as-Code: Lessons From Real-world Red Team Detection Automation Using Logs.
- Cyber Kill Chain | Lockheed Martin
Lockheed Martin - Lockheed Martin's framework that outlines the 7 stages commonly observed in a cyber attack.
- Detection Development Lifecycle | Haider Dost et al.
Haider Dost et al. - Snowflake’s implementation of the Detection Development Lifecycle.
- Detection Engineering AI Maturity Framework | Brendan Chamberlain
Brendan Chamberlain - A community framework with four maturity levels across ten dimensions for assessing how organizations apply AI and LLMs across a detection engineering program, from foundations through the detection lifecycle.
- Detection Engineering Field Manual | Zack Allen
Zack Allen - a series of posts exploring the various foundational components of Detection Engineering.
Detection Content & Signatures
- Anvilogic Detection Armory
Anvilogic's opensource and publicly available detection content.
- AttackRuleMap
Mapping of open-source detection rules and atomic tests.
- AWS GuardDuty Findings
A list of all AWS GuardDuty Findings, their descriptions, and associated data sources.
- Azure Defender for Cloud Security Alerts
A list of all Azure Security for Cloud Alerts, their descriptions, and associated data sources.
- CAR Coverage Comparision
A matrix of MITRE ATT&CK technique IDs and links to available Splunk Security Content, Elastic detection rules, Sigma rules, and CAR content.
- Center for Threat Informed Defense Security Stack Mappings
Describes cloud computing platform's (Azure, AWS) built-in detection capabilities and their mapings to the MITRE ATT&CK framework.
General Resources
- ATT&CK Navigator | MITRE
MITRE - MITRE's open-source tool that can be used to track detection coverage, visibility, and other efforts and their relationship to the ATT&CK framework.
- Awesome Kubernetes (K8s) Threat Detection
Another Awesome List dedicated to Kubernetes (K8s) threat detection.
- Cloud Threat Landscape | Wiz
Wiz - A cloud detection engineering-focused database, that lists threat actors known to have compromised cloud environments, the tools and techniques in their arsenal, and the technologies they prefer to target.
- Detection and Response Pipeline
A list of tools for each component of a detection and response pipeline which includes real-world examples.
- Detection at Scale Podcast | Jack Naglieri
Jack Naglieri - A detection engineering-focused podcast featuring many thought leaders in the specialization.
- Detection Engineering Twitter List | Zack Allen
Zack Allen - A Twitter list of Detection Engineering thought leaders.
Logging, Monitoring & Data Sources
- Elastalert | Yelp
Yelp - ElastAlert is a simple framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch.
- Elastic Common Schema
Elastic's proprietary model used as a framework for normalizing security data.
- Exabeam Common Information Model
Exabeam's proprietary model used as a framework for normalizing security data.
- InnerWarden
Autonomous security agent for Linux with real-time threat detection and response via 38 eBPF hooks, 48 detectors, and 23 correlation rules.
- Linux auditd Detection Ruleset
Linux auditd ruleset that produces telemetry required for threat detection use cases.
- Loghub
Opensource and freely available security data sources for research and testing.
Showing a sample of 70 resources. View the full list on GitHub →