awesome-detection-engineering

Detection frameworks

A curated list of resources and frameworks for designing, implementing, and optimizing detection controls in cybersecurity defense programs

Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.

GitHub

869 stars
28 watching
79 forks
last commit: about 2 years ago
Linked from 1 awesome list

awesomeawesome-listcybersecuritydetection-engineeringmitresplunkthreat-detection

Awesome Detection Engineering / Concepts & Frameworks

MITRE ATT&CKThe foundational framework of adversary tactics, techniques, and procedures based on real-world observations
Alerting and Detection Strategies (ADS) Framework | Palantir703almost 5 years agoA blueprint for creating and documenting effective detection content
Detection Engineering Maturity Matrix | Kyle BaileyA detailed matrix that serves as a tool to measure the overall maturity of an organization's Detection Engineering program
Detection Maturity Level (DML) Model | Ryan StillionsDefines and describes 8 different levels of an organization's threat detection program maturity
The Pyramid of Pain | David J BiancoA model used to describe various categorizations of indicator's of compromise and their level of effectiveness in detecting threat actors
Cyber Kill Chain | Lockheed MartinLockheed Martin's framework that outlines the 7 stages commonly observed in a cyber attack
MaGMa (Management, Growth and Metrics & Assessment) Use Case Defintion ModelA business-centric approach for defining threat detection use cases
Synthetic Adversarial Log Objects (SALO) | Splunk77over 2 years agoSynthetic Adversarial Log Objects (SALO) is a framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event
The Zen of Security Rules | Justin IbarraOutlines 19 aphorisms that serve as universal principles for the creation of high quality detection content
Blue-team-as-Code - the Spiral of Joy | Den Iuzvyk, Oleg KolesnikovBlue-Team-as-Code: Lessons From Real-world Red Team Detection Automation Using Logs
Detection Development Lifecycle | Haider Dost et al.Snowflake’s implementation of the Detection Development Lifecycle
Threat Detection Maturity Framework | Haider Dost of SnowflakeA maturity matrix to measure the success of your threat detection program
Elastic's Detection Engineering Behavior Maturity ModelElastic's qualitative and quantitative approach to measuring threat detection program maturity
Prioritizing Detection Engineering | Ryan McGeehanA longtime detection engineer outlines how a detection engineering program should be built from the ground up

Awesome Detection Engineering / Detection Content & Signatures

MITRE Cyber Analytics Repository (CAR)MITRE's well-maintained repository of detection content
CAR Coverage ComparisionA matrix of MITRE ATT&CK technique IDs and links to available Splunk Security Content, Elastic detection rules, Sigma rules, and CAR content
Sigma Rules8,490almost 2 years agoSigma's repository of turnkey detection content. Content can be converted for use with most SIEMs
Sigma rule converterAn opensource tool that can convert detection content for use with most SIEMs
Splunk Security Content1,319almost 2 years agoSplunk's open-source and frequently updated detection content that can be tweaked for use in other tools
Elastic Detection Rules1,990almost 2 years agoElastic's detection rules written natively for the Elastic SIEM. Can easily be converted for use by other SIEMs using Uncoder
Elastic Endpoint Behavioral Rules1,074almost 2 years agoElastic's endpoint behavioral (prevention) rules written in EQL, natively for the Elastic endpoint agent
Elastic Yara Signatures1,074almost 2 years agoElastic's YARA signatures, which run on the Elastic endpoint agent
Elastic Endpoint Ransomware Artifact1,074almost 2 years agoElastic's ranswomware artifact, which runs on the Elastic endpoint agent
Chronicle (GCP) Detection Rules326almost 2 years agoChronicle's detection rules written natively for the the Chronicle Platform
Exabeam Content Library17almost 2 years agoExabeam's out of the box detection content compatible with the Exabeam Common Information Model
Panther Labs Detection Rules346almost 2 years agoPanther Lab's native detection rules
Anvilogic Detection Armory88almost 2 years agoAnvilogic's opensource and publicly available detection content
AWS GuardDuty FindingsA list of all AWS GuardDuty Findings, their descriptions, and associated data sources
GCP Security Command Center FindingsA list of all GCP Security Command Center Findings, their descriptions, and associated data sources
Azure Defender for Cloud Security AlertsA list of all Azure Security for Cloud Alerts, their descriptions, and associated data sources
Center for Threat Informed Defense Security Stack Mappings379over 2 years agoDescribes cloud computing platform's (Azure, AWS) built-in detection capabilities and their mapings to the MITRE ATT&CK framework
Detection Engineering with Splunk58over 2 years agoA GitHub repo dedicated to sharing detection analytics in SPL
Google Cloud Security Analytics327over 2 years agoThis repository serves as a community-driven list of sample security analytics for auditing cloud usage and for detecting threats to your data & workloads in Google Cloud
KQL Advanced Hunting Queries & Analytics Rules1,292almost 2 years agoA list of endpoint detections and hunting queries for Microsoft Defender for Endpoint, Defender For Identity, and Defender For Cloud Apps

Awesome Detection Engineering / Logging, Monitoring & Data Sources

Windows Logging CheatsheetsMultiple cheatsheets outlined recommendations for Windows Event logging at various levels of granularity
Linux auditd Detection Ruleset1,517almost 2 years agoLinux auditd ruleset that produces telemetry required for threat detection use cases
MITRE ATT&CK Data Sources Blog PostMITRE describes various data sources and how they relate to the TTPs found in the MITRE ATT&CK framework
MITRE ATT&CK Data Sources ListData source objects added to MITRE ATT&CK as part of v10
Splunk Common Information Model (CIM)Splunk's proprietary model used as a framework for normalizing security data
Elastic Common SchemaElastic's proprietary model used as a framework for normalizing security data
Exabeam Common Information Model8almost 2 years agoExabeam's proprietary model used as a framework for normalizing security data
Open Cybersecurity Schema Framework (OCSF)An opensource security data source and event schema
Loghub1,883almost 2 years agoOpensource and freely available security data sources for research and testing
Elastalert | Yelp8,004about 2 years agoElastAlert is a simple framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch
Matano1,482about 2 years agoOpen source cloud-native security lake platform (SIEM alternative) for threat hunting, Python detections-as-code, and incident response on AWS 🦀
Microsoft XDR Advanced Hunting SchemaTo help with multi-table queries, you can use the advanced hunting schema, which includes tables and columns with event information and details about devices, alerts, identities, and other entity types

Awesome Detection Engineering / General Resources

ATT&CK Navigator | MITREMITRE's open-source tool that can be used to track detection coverage, visibility, and other efforts and their relationship to the ATT&CK framework
Detection Engineering Weekly | Zack AllenA newsletter dedicated to news and how-tos for Detection Engineering
Detection Engineering Twitter List | Zack AllenA Twitter list of Detection Engineering thought leaders
DETT&CT: MAPPING YOUR BLUE TEAM TO MITRE ATT&CK™Outlines a methodology measuring security data visibility and detection coverage against the MITRE ATT&CK framework
Awesome Kubernetes (K8s) Threat Detection368about 3 years agoAnother Awesome List dedicated to Kubernetes (K8s) threat detection
Detection and Response Pipeline262over 2 years agoA list of tools for each component of a detection and response pipeline which includes real-world examples
Living Off the Living Off the LandA collection of resources for thriving off the land
Detection at Scale Podcast | Jack NaglieriA detection engineering-focused podcast featuring many thought leaders in the specialization
Cloud Threat Landscape | WizA cloud detection engineering-focused database, that lists threat actors known to have compromised cloud environments, the tools and techniques in their arsenal, and the technologies they prefer to target
Splunk ES Correlation Searches Best Practices | OpsTune268over 2 years agoA highly detailed guide to producing high quality detection content in the Splunk Enterprise Security app

Backlinks from these awesome lists:

More related projects: