Skip to content
#

detection-as-code

Here are 132 public repositories matching this topic...

tyrian-detection-pack

Sigma to Wazuh, Splunk and Sentinel from one source. Compiles 96% of SigmaHQ to Wazuh, refuses what it cannot translate faithfully, and ships 67 range-tested ATT&CK rules to prove it. MIT.

  • Updated Sep 18, 2026
  • Python

The detection engine: correlation rules on the event stream you already forward, outside the SIEM. Sequences across hosts in log time, state that survives a crash. Rust, no JVM, embeddable.

  • Updated Sep 23, 2026
  • Rust
azure-sentinel-detection-engineering

9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated Detection-as-Code pipeline (GitHub Actions, OIDC), SOAR playbooks, and a SOC 2 control mapping.

  • Updated Aug 12, 2026
  • Kusto

Add this topic to your repo

To associate your repository with the detection-as-code topic, visit your repo's landing page and select "manage topics."

Learn more