This repository contains example YARA-L rules and dashboards for use within Google Security Operations (SecOps)
This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base
ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to standardize the security detection lifecycle. It functions as a community-driven repository for adversary tradecraft and detection logic, using interactive notebooks to combine technical documentation with executable analytics. The project provides a validation suite for testing security hypotheses against pre-recorded telemetry datasets. This ensures that detection logic is verified in local or cloud environments before being deployed to production. The framework covers security detec
Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that
Die Hauptfunktionen von googlecloudplatform/security-analytics sind: Detection Rules and Analytics.
Open-Source-Alternativen zu googlecloudplatform/security-analytics sind unter anderem: chronicle/detection-rules — This repository contains example YARA-L rules and dashboards for use within Google Security Operations (SecOps). elastic/detection-rules — This project is a detection-as-code framework providing a library of security monitoring rules and predefined… otrf/threathunter-playbook — ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to… sigmahq/sigma — Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides… sublime-security/sublime-rules.