Skip to content

WireRecon/Detection-Engineering

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

115 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Cover Picture

Detection-Engineering

This repository contains detection engineering work and lab artifacts, organized by detection language and platform.

Structure

  • sigma/ — Sigma rules (planned)
  • yara/ — YARA rules and static malware analysis write-ups
  • snort/ — Snort intrusion detection rules (planned)
  • kql/ — Microsoft Sentinel KQL (planned)
  • splunk/ — Splunk SPL (planned)

Notes

  • Write-ups (.md) live inside each detection folder (e.g., yara/docs/, sigma/docs/) to keep documentation scoped to that detection type.
  • Malware samples are analyzed using static techniques unless explicitly stated otherwise.
  • Rules target high-signal, behavior-based indicators over brittle IOCs where possible.

About

Detection Engineering and Threat Hunting content.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages