This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base
Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that
Elastic Security detection content for Endpoint
This repository contains example YARA-L rules and dashboards for use within Google Security Operations (SecOps)
الميزات الرئيسية لـ chronicle/detection-rules هي: Detection Rules and Analytics, Detection Content Libraries.
تشمل البدائل مفتوحة المصدر لـ chronicle/detection-rules: elastic/detection-rules — This project is a detection-as-code framework providing a library of security monitoring rules and predefined… sigmahq/sigma — Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides… elastic/protections-artifacts — Elastic Security detection content for Endpoint. googlecloudplatform/security-analytics. otrf/threathunter-playbook — ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to… sublime-security/sublime-rules.