-
Updated
Aug 20, 2026 - Python
detection-as-code
Here are 103 public repositories matching this topic...
A POC to implement Detection-as-Code with Terraform and Sumo Logic.
-
Updated
Jul 27, 2023 - Python
Microsoft Sentinel SIEM Log Source Analyzer
-
Updated
Jun 10, 2026 - PowerShell
ESLint-style linter for Sigma detection rules. Validates against Sigma 2.1.0, scores rules across six quality dimensions, emits stable rule IDs.
-
Updated
Aug 9, 2026 - Python
Official, curated detection content (Sigma, YARA, IOC packs) for the Rustinel endpoint detection engine.
-
Updated
Sep 2, 2026 - Python
Infrastructure as code for CrowdStrike — manage detections, saved searches, lookup files, and more with a Terraform-like lifecycle.
-
Updated
Sep 1, 2026 - Python
A Python-native Detection as Code Framework
-
Updated
Jan 23, 2026 - Python
A Pythonic Detection Rules Framework
-
Updated
May 19, 2026 - Python
Automated Detection-as-Code (DaC) CI/CD pipeline for validating and programmatically deploying SIEM detection rules via GitHub Actions and the Wazuh API
-
Updated
Aug 31, 2026 - Python
Huntable CTI Studio is an AI-assisted cyber threat intelligence workbench that turns open-source CTI into Sigma rules.
-
Updated
Sep 3, 2026 - Python
A curated reference of threat detection engineering & incident response frameworks, tools, and detection rule sources.
-
Updated
Jun 30, 2026
Data Loss Prevention as Code: author Microsoft Purview DLP policies in a YAML DSL, compile and validate them offline, deploy through a reviewable simulation-first pipeline.
-
Updated
Aug 10, 2026 - Python
Rust stream processing engine for real-time detection. Open-source Apache Flink alternative built for detection engineering, fraud prevention, and MITRE ATT&CK coverage. 1.5M events/sec, single 15MB binary, no JVM.
-
Updated
Aug 31, 2026 - Rust
9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated Detection-as-Code pipeline (GitHub Actions, OIDC), SOAR playbooks, and a SOC 2 control mapping.
-
Updated
Aug 12, 2026 - Kusto
Parallax — a self-hosted toolkit for SentinelOne AI-SIEM engineers: map parser & detection-library coverage, visualize MITRE ATT&CK gaps, and validate that detection rules actually fire by generating synthetic test logs from each rule's own logic and verifying the resulting alerts.
-
Updated
Jul 17, 2026 - Python
Autonomous cybersecurity agent for SMBs — self-hosted, AI-powered, WASM-sandboxed skills
-
Updated
Sep 1, 2026 - Rust
A practical Detection-as-Code platform that brings software engineering principles to threat detection, validation, and security operations.
-
Updated
Jul 15, 2026 - Python
Purple-team detection-engineering lab with ML-assisted Sigma/YARA rule generation, and coverage/FP/evasion scoring.
-
Updated
Aug 26, 2026 - Python
A threat hunter that lives in your terminal with memories in Notion.
-
Updated
Jul 3, 2026 - Go
Add this topic to your repo
To associate your repository with the detection-as-code topic, visit your repo's landing page and select "manage topics."