Enterprise Security Data Pipeline Platform (SDPP) with Integrated Real-Time Threat Detection Engine
-
Updated
Apr 3, 2026 - Go
Enterprise Security Data Pipeline Platform (SDPP) with Integrated Real-Time Threat Detection Engine
A document tagging library
Clickdetect - generic and no vendor lock-in threshold based detection
Real-time container threat detection, automated defense, and forensic evidence collection.
Machine Learning based Network Intrusion Detection System with real-time packet analysis and MERN dashboard.
Ferramenta CLI em Python para análise de logs de segurança com isolamento por projeto, detecção de ameaças via assinaturas regex e gerenciamento de IPs maliciosos.
🛠️ Build and manage AI agents easily with Agent Hub, a versatile platform integrating TypeScript, Python, Angular, and FastAPI for seamless development.
GUARDIUM is an intelligent Wazuh rule optimization framework designed to reduce false positives, improve alert accuracy, and assist SOC teams in maintaining high-quality SIEM detections. GUARDIUM combines rule analysis, threat context, and Large Language Models (LLMs) to automatically evaluate, explain, and optimize Wazuh rules.
AI-Powered SOC Threat Hunting Platform | Sysmon + Python Detection Engine + Machine Learning (Isolation Forest) + VirusTotal Enrichment + Flask Dashboard
SOC home lab using Elastic SIEM: endpoint logging, detections (KQL), and incident reports.
Modular Linux attack timeline detection engine with MITRE ATT&CK mapping and CI-backed test suite.
Multi-platform threat detection pipeline with SIEM simulation (Linux, AIX, Unix, Cloud)
High-throughput DNS intelligence and domain behavior analysis framework for offensive security and threat research.
A modular, ecosystem-agnostic security parsing and correlation framework that ingests tool outputs, normalizes findings, enriches context, and builds attack graphs for advanced analysis, automation, and detection engineering across any environment.
A real-time Security Information and Event Management (SIEM) system featuring a multi-stage heuristic detection engine, automated IP enrichment via VirusTotal/IP-API, and a live Streamlit SOC dashboard for visualizing global threat telemetry.
Add a description, image, and links to the detection-engine topic page so that developers can more easily learn about it.
To associate your repository with the detection-engine topic, visit your repo's landing page and select "manage topics."