Skip to content

avrgsec/detection-lab

Repository files navigation

Detection Lab

A collection of Sigma detection rules for threat detection and response, organized by operating system and attack technique.

🎯 About

Detection Lab provides production-ready Sigma rules covering:

  • macOS persistence and privilege escalation
  • Windows credential access and lateral movement
  • Linux security monitoring
  • Cloud infrastructure protection
  • Network traffic analysis

Each detection is mapped to MITRE ATT&CK techniques and tested in live environments.

🔗 Live Site

avrgsec.me

Browse detections, read testing methodology, and download Sigma rules.

📝 Blog

Technical writeups on detection engineering, testing approaches, and security research.

🛠️ Tech Stack

  • Astro - Static site generation
  • Tailwind CSS - Styling
  • Sigma - Detection rule format
  • Cloudflare Pages - Hosting & CDN

📄 License

MIT

🔗 Links

About

Adversary First Detection Engineering - Sigma rules for threat detection

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published