Endpoint detection pipeline using Sysmon, Splunk, and Atomic Red Team. Learning detection engineering hands-on.
-
Updated
Mar 17, 2026
Endpoint detection pipeline using Sysmon, Splunk, and Atomic Red Team. Learning detection engineering hands-on.
A simulated Modbus TCP industrial process lab for exploring protocol-valid control actions, process impact, and investigation evidence.
Laboratório de Detection Engineering com Wazuh e Sysmon para detecção de execução do PowerShell mapeada à técnica MITRE ATT&CK T1059.001. | | Detection Engineering lab with Wazuh and Sysmon for PowerShell detection mapped to MITRE ATT&CK T1059.001.
SOC-style home lab: centralized Linux log monitoring with SSH brute-force detection and automated alerting.
AI-powered SIEM-lite web app that ingests security logs, detects attacks with Sigma rules and ML anomaly detection, and summarizes incidents with an LLM. Maps findings to MITRE ATT&CK. Built with Quarkus & React.
To associate your repository with the detection-engineerin topic, visit your repo's landing page and select "manage topics."