A curated reference of threat detection engineering & incident response frameworks, tools, and detection rule sources.
-
Updated
Jun 30, 2026
A curated reference of threat detection engineering & incident response frameworks, tools, and detection rule sources.
Splunk SIEM detection engineering on 33.4M BOTSv1 events — Risk-Based Alerting, contentctl detection-as-code with CI-built app, CIM/tstats detections mapped to MITRE ATT&CK, and Suricata EVE ingest.
Add a description, image, and links to the risk-based-alerting topic page so that developers can more easily learn about it.
To associate your repository with the risk-based-alerting topic, visit your repo's landing page and select "manage topics."