Marble - the real time decision engine for fraud and AML
-
Updated
Aug 24, 2026 - HTML
Marble - the real time decision engine for fraud and AML
A free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing. Gain visibility and control, hunt for advanced threats, collaborate with the community, and write detections-as-code.
The Threat Hunting In Rapid Iterations (THIRI) Jupyter notebook is designed as a research aide to let you rapidly prototype threat hunting rules.
The Web Exploit Detector is a Node.js application used to detect possible infections, malicious code and suspicious files in web hosting environments
Hunting Queries for Defender ATP
Sigma detection rules for hunting with the threathunting-keywords project
CVE proof-of-concept labs, exploit scripts, and detection/prevention rules (Nginx, Apache, Snort, YARA) for high-severity CVEs. Authorized security testing & research only.
Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs
Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-know
Check Sigma rules for easy-to-bypass whitelists to make them more robust (https://github.com/SigmaHQ/sigma)
32 production-quality KQL detection rules for Microsoft Sentinel, mapped to MITRE ATT&CK for Cloud, credential access, lateral movement, exfiltration, defense evasion, and more
A userscript that enhances the SentinelOne PowerQuery interface with a custom threat hunting button that follow the website UI / UX design interface.
Sigma detections for real ATT&CK techniques, compiled to Wazuh, Splunk and Sentinel from one source. 67 rules, 64 techniques, Windows + Linux, ATT&CK Navigator layer, MIT.
Huntable CTI Studio is an AI-assisted cyber threat intelligence workbench that turns open-source CTI into Sigma rules.
A command line tool that takes a txt file containing threat intelligence and turns it into a detection rule.
Docker Container for Elastic Detection CLI
A collection of custom-built dashboards for threat hunting.
An API that takes a txt file containing threat intelligence and turns it into a detection rule.
Security Playbooks is a collection of defensive security resources, MITRE ATT&CK mapping, incident response, detection rules (Sigma, YARA, and Suricata), security validation, detection validation, and hands-on labs for cybersecurity professionals and SOC analysts.
Add a description, image, and links to the detection-rules topic page so that developers can more easily learn about it.
To associate your repository with the detection-rules topic, visit your repo's landing page and select "manage topics."