# infosecB/awesome-detection-engineering

Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.

Repository: https://github.com/infosecB/awesome-detection-engineering
Canonical: https://ross.abutalabs.com/products/awesome-detection-engineering
License: CC0-1.0
License Family: permissive
Topics: detection-engineering, splunk, mitre, awesome-list, awesome, cybersecurity, threat-detection
Last push: 2026-08-03T16:57:29+00:00

## Health v2 (maintenance only)
Score: 75/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 95, release rhythm 35, longevity 100
- inputs: {"age_days": 2168, "days_push": 30, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1330, forks 146 (observed 2026-08-28T04:04:23.988938+00:00)

## What it is
A curated awesome-list of resources for detection engineering, the cybersecurity discipline of designing and operating detective controls. It catalogs frameworks like MITRE ATT&CK, detection content and signatures, and logging/monitoring data sources.

## Use cases
- find resources for building a detection engineering program
- learn about MITRE ATT&CK and detection frameworks
- discover detection content and signature sources
- find logging and monitoring data sources for threat detection
- measure the maturity of a threat detection program
- get started in a blue team detection engineering career

## When to choose
- you need a curated starting point for detection engineering tools, frameworks, and reading
- you are building or maturing an organization's threat detection capability
- you want references for writing high-quality detection rules and use cases

## When to avoid
- you need runnable detection software rather than a list of links
- you are looking for offensive security or penetration testing resources
- you need a specific tool rather than an overview of the field

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, monitoring, alerting, developer-tools
- domain: security, awesome-lists, monitoring
- platform: -
- tags: detection-engineering, awesome-list, threat-detection, mitre-attack, cybersecurity, blue-team, curated-list, web-server

## Member repositories
- infosecB/awesome-detection-engineering (main) score 75

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:23.988938+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:45:31.961973+00:00, confidence not recorded.
  - readme: https://github.com/infosecB/awesome-detection-engineering (fetched 2026-08-28T04:04:23.988938+00:00, sha 5805ec891636)
- Data as of 2026-08-30T08:39:29.467469+00:00.
