A curated arsenal of 55 blue team / detection engineering tools across 13 sections, mapped to real SOC workflows. Where a tool appears in your own lab work, the entry links to your writeup.
-
Updated
Jul 17, 2026
A curated arsenal of 55 blue team / detection engineering tools across 13 sections, mapped to real SOC workflows. Where a tool appears in your own lab work, the entry links to your writeup.
SIEM-based exfiltration detection - Wazuh + Suricata + SLIPS + MITRE ATT&CK
SOC portfolio: Windows Security Logs, Sysmon, incident triage, IOC enrichment, MITRE ATT&CK, Python and PowerShell automation.
Contract-driven telemetry and detection validation platform for ATT&CK-mapped testing with Wazuh integration, blind-spot diagnosis, regression tracking, and evidence reports.
Splunk BOTSv3 SOC investigation - CoinMiner drive-by attack on Frothly Brewing with full MITRE ATT&CK, NIST CSF, NIST 800-53, and CIS Controls v8 framework mappings.
AI-assisted SOC alert investigator with agentic reasoning
Add a description, image, and links to the mittre-attack topic page so that developers can more easily learn about it.
To associate your repository with the mittre-attack topic, visit your repo's landing page and select "manage topics."