Skip to content
#

detection-as-code

Here are 68 public repositories matching this topic...

azure-sentinel-detection-engineering

9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated Detection-as-Code pipeline (GitHub Actions, OIDC), SOAR playbooks, and a SOC 2 control mapping.

  • Updated Jul 6, 2026
  • Kusto

Rust stream processing engine for real-time detection. Open-source Apache Flink alternative built for detection engineering, fraud prevention, and MITRE ATT&CK coverage. 1.5M events/sec, single 15MB binary, no JVM.

  • Updated Jul 20, 2026
  • Rust

30 + project AWS SOC/SOAR Ecosystem portfolio with Wazuh, TheHive, Cortex, MISP, n8n, network security monitoring, Threat Detection & Hunting, Alert triage, Log Analysis, Detection engineering, Incident Response, dashboards, and AI security automation.

  • Updated Jul 26, 2026
  • Python

Improve this page

Add a description, image, and links to the detection-as-code topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the detection-as-code topic, visit your repo's landing page and select "manage topics."

Learn more