Enterprise Security Data Pipeline Platform (SDPP) — Real-Time Threat Detection + Deeply Integrated LLM Agents
-
Updated
Sep 5, 2026 - Go
Enterprise Security Data Pipeline Platform (SDPP) — Real-Time Threat Detection + Deeply Integrated LLM Agents
ClickDetect is a vendor-agnostic alerting framework for threshold-based detection. It works with ClickHouse, OpenSearch/Elasticsearch, VictoriaLogs, PostgreSQL, DuckDB or any custom data source through a flexible integration layer.
A document tagging library
A learning-focused PE analysis engine with modular detectors, heuristic analysis, and HTML reporting.
The project utilizes of a wazuh-manager installed on WSL or a Linux machine, allowing testing custom rules locally before moving to production.
Real-time container threat detection, automated defense, and forensic evidence collection.
Ferramenta CLI em Python para análise de logs de segurança com isolamento por projeto, detecção de ameaças via assinaturas regex e gerenciamento de IPs maliciosos.
The open detection and remediation core behind Vallhund. Normalized telemetry in; findings, actor classification, coverage boundaries, and agent-ready remediation prompts out.
Machine Learning based Network Intrusion Detection System with real-time packet analysis and MERN dashboard.
Hybrid prompt-injection detection engine (regex · Sentinel v2 · LLM judge) — 95.1% PINT balanced accuracy. Detection core of TUP AIGSMP. Built at Apart Research Global South Hackathon 2026.
Modular Linux attack timeline detection engine with MITRE ATT&CK mapping and CI-backed test suite.
Opensource detections for web related artifacts and access requests
Python-based AI security detection platform — detects prompt injection, data exfiltration and unsafe agent actions across chat and agentic AI systems
GUARDIUM is an intelligent Wazuh rule optimization framework designed to reduce false positives, improve alert accuracy, and assist SOC teams in maintaining high-quality SIEM detections. GUARDIUM combines rule analysis, threat context, and Large Language Models (LLMs) to automatically evaluate, explain, and optimize Wazuh rules.
Multi-platform threat detection pipeline with SIEM simulation (Linux, AIX, Unix, Cloud)
SOC home lab using Elastic SIEM: endpoint logging, detections (KQL), and incident reports.
Enterprise defense tool for **Living Off the Agent (LOTA)** attacks — indirect prompt injection used to hijack enterprise AI agents (Copilot, Salesforce Agentforce, internal dev-tool bots, etc.) for lateral movement.
A real-time Security Information and Event Management (SIEM) system featuring a multi-stage heuristic detection engine, automated IP enrichment via VirusTotal/IP-API, and a live Streamlit SOC dashboard for visualizing global threat telemetry.
Entorno sintético local para formación en detección de identidad, investigación y flujo SOC.
High-throughput DNS intelligence and domain behavior analysis framework for offensive security and threat research.
To associate your repository with the detection-engine topic, visit your repo's landing page and select "manage topics."