Skip to content
#

detection-rules

Here are 92 public repositories matching this topic...

32 production-quality KQL detection rules for Microsoft Sentinel, mapped to MITRE ATT&CK for Cloud, credential access, lateral movement, exfiltration, defense evasion, and more

  • Updated Aug 1, 2026
tyrian-detection-pack

Sigma to Wazuh, Splunk and Sentinel from one source. Compiles 96% of SigmaHQ to Wazuh, refuses what it cannot translate faithfully, and ships 67 range-tested ATT&CK rules to prove it. MIT.

  • Updated Sep 18, 2026
  • Python

Add this topic to your repo

To associate your repository with the detection-rules topic, visit your repo's landing page and select "manage topics."

Learn more