4 مستودعات
Collections of pre-built detection rules, signatures, and analytics for various security platforms.
Explore 4 awesome GitHub repositories matching part of an awesome list · Detection Content Libraries. Refine with filters or upvote what's useful.
Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that
Provides a universal, platform-agnostic format for detection content.
This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base
Contains native detection rules designed for the Elastic SIEM platform.
Elastic Security detection content for Endpoint
Includes endpoint behavioral rules, YARA signatures, and ransomware detection artifacts.
This repository contains example YARA-L rules and dashboards for use within Google Security Operations (SecOps)
Provides native