Skip to content

petstuk/detections

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

13 Commits
 
 
 
 
 
 
 
 

Repository files navigation

detections

This repository is used to build multiple detections across 14 different categories. It is a detection engineering practice space, with rules written primarily in Sigma and optionally translated for Splunk and/or Sentinel.

Categories

  • DNS-Based
  • Network & TLS
  • Windows Authentication & Credentials
  • Windows Process Execution & LOLBins
  • Windows Persistence
  • Lateral Movement
  • Active Directory Attacks
  • Linux Persistence & Privesc
  • Email & Phishing
  • Cloud & Modern Identity
  • Malware & C2
  • Defence Evasion
  • Data Exfiltration

About

This repository is used to build multiple detections across 14 different categories. It is a detection engineering practice space, with rules written primarily in Sigma and optionally translated for Splunk and/or Sentinel.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors