Enterprise Security Data Pipeline Platform (SDPP) — Real-Time Threat Detection + Deeply Integrated LLM Agents
-
Updated
Sep 5, 2026 - Go
Enterprise Security Data Pipeline Platform (SDPP) — Real-Time Threat Detection + Deeply Integrated LLM Agents
ClickDetect is a vendor-agnostic alerting framework for threshold-based detection. It works with ClickHouse, OpenSearch/Elasticsearch, VictoriaLogs, PostgreSQL, DuckDB or any custom data source through a flexible integration layer.
A document tagging library
A learning-focused PE analysis engine with modular detectors, heuristic analysis, and HTML reporting.
The project utilizes of a wazuh-manager installed on WSL or a Linux machine, allowing testing custom rules locally before moving to production.
Real-time container threat detection, automated defense, and forensic evidence collection.
The open detection and remediation core behind Vallhund. Normalized telemetry in; findings, actor classification, coverage boundaries, and agent-ready remediation prompts out.
Ferramenta CLI em Python para análise de logs de segurança com isolamento por projeto, detecção de ameaças via assinaturas regex e gerenciamento de IPs maliciosos.
Machine Learning based Network Intrusion Detection System with real-time packet analysis and MERN dashboard.
Hybrid prompt-injection detection engine (regex · Sentinel v2 · LLM judge) — 95.1% PINT balanced accuracy. Detection core of TUP AIGSMP. Built at Apart Research Global South Hackathon 2026.
Opensource detections for web related artifacts and access requests
Enterprise defense tool for **Living Off the Agent (LOTA)** attacks — indirect prompt injection used to hijack enterprise AI agents (Copilot, Salesforce Agentforce, internal dev-tool bots, etc.) for lateral movement.
Modular Linux attack timeline detection engine with MITRE ATT&CK mapping and CI-backed test suite.
GUARDIUM is an intelligent Wazuh rule optimization framework designed to reduce false positives, improve alert accuracy, and assist SOC teams in maintaining high-quality SIEM detections. GUARDIUM combines rule analysis, threat context, and Large Language Models (LLMs) to automatically evaluate, explain, and optimize Wazuh rules.
Python-based AI security detection platform — detects prompt injection, data exfiltration and unsafe agent actions across chat and agentic AI systems
SOC home lab using Elastic SIEM: endpoint logging, detections (KQL), and incident reports.
Multi-platform threat detection pipeline with SIEM simulation (Linux, AIX, Unix, Cloud)
A real-time Security Information and Event Management (SIEM) system featuring a multi-stage heuristic detection engine, automated IP enrichment via VirusTotal/IP-API, and a live Streamlit SOC dashboard for visualizing global threat telemetry.
Entorno sintético local para formación en detección de identidad, investigación y flujo SOC.
High-throughput DNS intelligence and domain behavior analysis framework for offensive security and threat research.
To associate your repository with the detection-engine topic, visit your repo's landing page and select "manage topics."