Marble - the real time decision engine for fraud and AML
-
Updated
Jul 29, 2026 - HTML
Marble - the real time decision engine for fraud and AML
A free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing. Gain visibility and control, hunt for advanced threats, collaborate with the community, and write detections-as-code.
The Threat Hunting In Rapid Iterations (THIRI) Jupyter notebook is designed as a research aide to let you rapidly prototype threat hunting rules.
The Web Exploit Detector is a Node.js application used to detect possible infections, malicious code and suspicious files in web hosting environments
Hunting Queries for Defender ATP
Sigma detection rules for hunting with the threathunting-keywords project
Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs
Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-know
Check Sigma rules for easy-to-bypass whitelists to make them more robust (https://github.com/SigmaHQ/sigma)
A userscript that enhances the SentinelOne PowerQuery interface with a custom threat hunting button that follow the website UI / UX design interface.
Sigma detections for real ATT&CK techniques, with a compiler that emits Wazuh, Splunk and Sentinel from one source. 36 rules, 33 techniques, MIT.
A command line tool that takes a txt file containing threat intelligence and turns it into a detection rule.
Docker Container for Elastic Detection CLI
A collection of custom-built dashboards for threat hunting.
Security Playbooks is a collection of MITRE ATT&CK mapping, detection rules (Sigma, YARA, and Suricata), detection validation, and hands-on lab for cybersecurity professionals and SOC analysts.
🛡️ Open-source Sigma rules, Sysmon config & IR playbooks for Thai/ASEAN SOC teams. Mapped to MITRE ATT&CK, tested, bilingual. By ECOP Thailand.
Sigma-format SAST detection rules for Active Directory attack techniques — CLAUDE 94 rules across 14 categories, mapped to MITRE ATT&CK v14 | For blue teams, SOC analysts and purple team exercises
An API that takes a txt file containing threat intelligence and turns it into a detection rule.
Manage your detection use cases portfolio
Add a description, image, and links to the detection-rules topic page so that developers can more easily learn about it.
To associate your repository with the detection-rules topic, visit your repo's landing page and select "manage topics."