✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
-
Updated
Jan 5, 2026
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
Security sensor for realtime threat detection and protection
☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
A curated knowledge base to build, run and mature a SOC (including CSIRT).
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.
Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.
Threat-hunting tool for Linux
Open source platform for cyber security analysts with many features for threat intelligence and detection engineering.
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.
select * from logs; Tailpipe is an open source SIEM for instant log insights, powered by DuckDB. Analyze millions of events in seconds, right from your terminal.
Open-source runtime AI agent security tool - monitors and controls AI agents, catching malicious tool use, prompt injection, and policy drift in real time, before the agent acts.
Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account required.
Open detection-rule standard for AI agent security threats — like Sigma, but for AI agents. Executable rules across 10 categories; merged into Microsoft AGT, Cisco AI Defense, MISP, OWASP, FINOS & SigmaHQ. MIT-licensed.
A flexible threat detection platform that simplifies rule management and deployment using K8s CronJob and Helm, but can also run standalone or with other job schedulers like Nomad.
Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud
To associate your repository with the threat-detection topic, visit your repo's landing page and select "manage topics."