Skip to main content

Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.

1.3k
GitHub Stars
74
Curated Resources
4
Categories
2 hours ago
Last Refreshed
Concepts & FrameworksDetection Content & SignaturesLogging, Monitoring & Data SourcesGeneral Resources

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me detection content & signatures resources from awesome-detection-engineering"

Installation instructions →

What's inside

Detection Content & Signatures

  • Agent Threat Rules (ATR)

    An open MIT detection-rule standard for AI-agent and MCP attacks (prompt injection, tool poisoning, context exfiltration), like Sigma or YARA for the agent layer, with OWASP LLM/Agentic and MITRE ATLAS mappings on each rule.

  • Anvilogic Detection Armory

    Anvilogic's opensource and publicly available detection content.

  • AttackRuleMap

    Mapping of open-source detection rules and atomic tests.

  • AWS GuardDuty Findings

    A list of all AWS GuardDuty Findings, their descriptions, and associated data sources.

  • Azure Defender for Cloud Security Alerts

    A list of all Azure Security for Cloud Alerts, their descriptions, and associated data sources.

  • CAR Coverage Comparision

    A matrix of MITRE ATT&CK technique IDs and links to available Splunk Security Content, Elastic detection rules, Sigma rules, and CAR content.

Concepts & Frameworks

General Resources

Logging, Monitoring & Data Sources

  • Elastalert | Yelp

    ElastAlert is a simple framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch.

  • Elastic Common Schema

    Elastic's proprietary model used as a framework for normalizing security data.

  • Exabeam Common Information Model

    Exabeam's proprietary model used as a framework for normalizing security data.

  • InnerWarden

    Autonomous security agent for Linux with real-time threat detection and response via 38 eBPF hooks, 48 detectors, and 23 correlation rules.

  • Linux auditd Detection Ruleset

    Linux auditd ruleset that produces telemetry required for threat detection use cases.

  • Loghub

    Opensource and freely available security data sources for research and testing.

Showing a sample of 74 resources. View the full list on GitHub →