Enterprise Security Data Pipeline Platform (SDPP) — Real-Time Threat Detection + Deeply Integrated LLM Agents
-
Updated
Jun 2, 2026 - Go
Enterprise Security Data Pipeline Platform (SDPP) — Real-Time Threat Detection + Deeply Integrated LLM Agents
Clickdetect - generic and no vendor lock-in threshold based detection
A document tagging library
A learning-focused PE analysis engine with modular detectors, heuristic analysis, and HTML reporting.
Real-time container threat detection, automated defense, and forensic evidence collection.
🛠️ Build and manage AI agents easily with Agent Hub, a versatile platform integrating TypeScript, Python, Angular, and FastAPI for seamless development.
Ferramenta CLI em Python para análise de logs de segurança com isolamento por projeto, detecção de ameaças via assinaturas regex e gerenciamento de IPs maliciosos.
The open detection and remediation core behind Vallhund. Normalized telemetry in; findings, actor classification, coverage boundaries, and agent-ready remediation prompts out.
Machine Learning based Network Intrusion Detection System with real-time packet analysis and MERN dashboard.
SOC home lab using Elastic SIEM: endpoint logging, detections (KQL), and incident reports.
AI-Powered SOC Threat Hunting Platform | Sysmon + Python Detection Engine + Machine Learning (Isolation Forest) + VirusTotal Enrichment + Flask Dashboard
Multi-platform threat detection pipeline with SIEM simulation (Linux, AIX, Unix, Cloud)
GUARDIUM is an intelligent Wazuh rule optimization framework designed to reduce false positives, improve alert accuracy, and assist SOC teams in maintaining high-quality SIEM detections. GUARDIUM combines rule analysis, threat context, and Large Language Models (LLMs) to automatically evaluate, explain, and optimize Wazuh rules.
High-throughput DNS intelligence and domain behavior analysis framework for offensive security and threat research.
Modular Linux attack timeline detection engine with MITRE ATT&CK mapping and CI-backed test suite.
Defensive SOC analytics toolkit for log normalization, detection rules, risk scoring, and HTML reports.
Local-first security log analyzer with detection rules and web UI
Python-based AI security detection platform — detects prompt injection, data exfiltration and unsafe agent actions across chat and agentic AI systems
Cross-platform Python log analysis tool for Windows Event Logs and Linux syslogs with brute force, privilege escalation, and suspicious process detection.
Defensive log triage CLI for suspicious authentication, firewall, DNS, and outbound traffic patterns.
Add a description, image, and links to the detection-engine topic page so that developers can more easily learn about it.
To associate your repository with the detection-engine topic, visit your repo's landing page and select "manage topics."