-
Updated
Sep 4, 2026 - Python
detection-as-code
Here are 114 public repositories matching this topic...
A POC to implement Detection-as-Code with Terraform and Sumo Logic.
-
Updated
Jul 27, 2023 - Python
Microsoft Sentinel SIEM Log Source Analyzer
-
Updated
Jun 10, 2026 - PowerShell
RuleVis is a powerful analysis tool that transforms your Wazuh ruleset into a dynamic, interactive force-directed graph. It helps you visualize the complex relationships between rules, identify critical dependencies, discover structural issues, and analyze the distribution of your rule IDs.
-
Updated
Nov 12, 2025 - JavaScript
ESLint-style linter for Sigma detection rules. Validates against Sigma 2.1.0, scores rules across six quality dimensions, emits stable rule IDs.
-
Updated
Aug 9, 2026 - Python
Official, curated detection content (Sigma, YARA, IOC packs) for the Rustinel endpoint detection engine.
-
Updated
Sep 5, 2026 - Python
Infrastructure as code for CrowdStrike — manage detections, saved searches, lookup files, and more with a Terraform-like lifecycle.
-
Updated
Sep 1, 2026 - Python
A Python-native Detection as Code Framework
-
Updated
Jan 23, 2026 - Python
A Pythonic Detection Rules Framework
-
Updated
May 19, 2026 - Python
Automated Detection-as-Code (DaC) CI/CD pipeline for validating and programmatically deploying SIEM detection rules via GitHub Actions and the Wazuh API
-
Updated
Aug 31, 2026 - Python
Huntable CTI Studio is an AI-assisted cyber threat intelligence workbench that turns open-source CTI into Sigma rules.
-
Updated
Sep 5, 2026 - Python
A curated reference of threat detection engineering & incident response frameworks, tools, and detection rule sources.
-
Updated
Jun 30, 2026
A Python tool that parses EVTX files and converts them into JSON formatted logs mimicking Wazuh agent behavior in version 4.x. wazuhevtx is designed as a helper for wazuh-logtest tool.
-
Updated
Sep 26, 2025 - Python
Data Loss Prevention as Code: author Microsoft Purview DLP policies in a YAML DSL, compile and validate them offline, deploy through a reviewable simulation-first pipeline.
-
Updated
Aug 10, 2026 - Python
A helper for Wazuh Security Configuration Assessment (SCA) to create a custom SCA based on loosening.
-
Updated
Sep 5, 2026 - Python
The project utilizes of a wazuh-manager installed on WSL or a Linux machine, allowing testing custom rules locally before moving to production.
-
Updated
Feb 13, 2026 - Python
Rust stream processing engine for real-time detection. Open-source Apache Flink alternative built for detection engineering, fraud prevention, and MITRE ATT&CK coverage. 1.5M events/sec, single 15MB binary, no JVM.
-
Updated
Aug 31, 2026 - Rust
9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated Detection-as-Code pipeline (GitHub Actions, OIDC), SOAR playbooks, and a SOC 2 control mapping.
-
Updated
Aug 12, 2026 - Kusto
Parallax — a self-hosted toolkit for SentinelOne AI-SIEM engineers: map parser & detection-library coverage, visualize MITRE ATT&CK gaps, and validate that detection rules actually fire by generating synthetic test logs from each rule's own logic and verifying the resulting alerts.
-
Updated
Jul 17, 2026 - Python
Add this topic to your repo
To associate your repository with the detection-as-code topic, visit your repo's landing page and select "manage topics."