{"adoption": {"forks": 146, "observed_at": "2026-08-28T04:04:23.988938+00:00", "stars": 1330}, "canonical_url": "https://ross.abutalabs.com/products/awesome-detection-engineering", "card": {"archived": false, "artifact_type": "learning-resource", "description": "Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.", "domain": ["security", "awesome-lists", "monitoring"], "enriched": true, "function": ["security", "monitoring", "alerting", "developer-tools"], "health_score": 77, "homepage": null, "language": null, "license": "CC0-1.0", "license_family": "permissive", "maturity": "active", "member_repos": ["infosecB/awesome-detection-engineering"], "name": "infosecB/awesome-detection-engineering", "platform": [], "pushed_at": "2026-08-03T16:57:29+00:00", "repo": "infosecB/awesome-detection-engineering", "stars": 1330, "tags": ["detection-engineering", "awesome-list", "threat-detection", "mitre-attack", "cybersecurity", "blue-team", "curated-list", "web-server"], "topics": ["detection-engineering", "splunk", "mitre", "awesome-list", "awesome", "cybersecurity", "threat-detection"], "urls": [], "use_cases": ["find resources for building a detection engineering program", "learn about MITRE ATT&CK and detection frameworks", "discover detection content and signature sources", "find logging and monitoring data sources for threat detection", "measure the maturity of a threat detection program", "get started in a blue team detection engineering career"], "what_it_is": "A curated awesome-list of resources for detection engineering, the cybersecurity discipline of designing and operating detective controls. It catalogs frameworks like MITRE ATT&CK, detection content and signatures, and logging/monitoring data sources.", "when_to_avoid": ["you need runnable detection software rather than a list of links", "you are looking for offensive security or penetration testing resources", "you need a specific tool rather than an overview of the field"], "when_to_choose": ["you need a curated starting point for detection engineering tools, frameworks, and reading", "you are building or maturing an organization's threat detection capability", "you want references for writing high-quality detection rules and use cases"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/awesome-detection-engineering", "repo": "infosecB/awesome-detection-engineering", "role": "main", "score": 75}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:23.988938+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:45:31.961973+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "5805ec8916368a9d7dcbccc744be3ed66ce583499b92515d06462807d27ce209", "fetched_at": "2026-08-28T04:04:23.988938+00:00", "kind": "readme", "missing": false, "url": "https://github.com/infosecB/awesome-detection-engineering"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 95, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2168, "days_push": 30, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 75, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}