A compilation of suggested tools for each component in a detection and response pipeline, along with real-world examples. The purpose is to create a reference hub for designing effective threat detection and response pipelines. Join us, explore the curated content, and contribute to this collaborative effort. Main Components of a Detection & Response Pipeline: - Detection-as-Code Pipeline - Data Pipeline - Detection and Correlation Engine - Response Orchestration and Automation - Investigation and Case Management - Real-world Examples - Additional Resources Detection-as-Code Pipeline Tool / Service Purpose: - GitHub: Detection content development - GitLab: Detection content development - Gitea: Detection content development - AWS CodeCommit: Detection content development - GitHub Actions: CI/CD pipeline - GitLab Runner: CI/CD pipeline - Drone: CI/CD pipeline - AWS CodePipeline: CI/CD pipeline Resources: Automating Detection-as-Code: An example reference that uses GitHub for detection content development, GitHub Actions for CI/CD, Elastic as SIEM, GitHub Issues for alert management, and Tines for alert and response handling. Practical Detection-as-Code: An exa
A report on detecting lateral movement through tracking event logs, updated to include analysis of various tools and commands used by attackers.
jimi is an orchestration automation tool for multi-team collaboration and automation in IT/Security operations, Development, and CI/CD pipelines.
A collection of AWS security architectures for various security operations.
An automation platform with community support and documentation for easy development.
Fast Intercept is a security automation platform that empowers users to maximize their existing security products and automate routine tasks.
A DFIR Playbook Spec based on YAML for collaborative incident response processes.
A defense-in-depth security automation and monitoring framework utilizing threat intelligence, machine learning, and serverless technologies.
Scumblr is a web application for periodic syncs of data sources and security analysis to streamline proactive security.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.