Enterprise Security Data Pipeline Platform (SDPP) — Real-Time Threat Detection + Deeply Integrated LLM Agents
-
Updated
Sep 5, 2026 - Go
Enterprise Security Data Pipeline Platform (SDPP) — Real-Time Threat Detection + Deeply Integrated LLM Agents
ClickDetect is a vendor-agnostic alerting framework for threshold-based detection. It works with ClickHouse, OpenSearch/Elasticsearch, VictoriaLogs, PostgreSQL, DuckDB or any custom data source through a flexible integration layer.
A document tagging library
A learning-focused PE analysis engine with modular detectors, heuristic analysis, and HTML reporting.
The project utilizes of a wazuh-manager installed on WSL or a Linux machine, allowing testing custom rules locally before moving to production.
Real-time container threat detection, automated defense, and forensic evidence collection.
Ferramenta CLI em Python para análise de logs de segurança com isolamento por projeto, detecção de ameaças via assinaturas regex e gerenciamento de IPs maliciosos.
The open detection and remediation core behind Vallhund. Normalized telemetry in; findings, actor classification, coverage boundaries, and agent-ready remediation prompts out.
Hybrid prompt-injection detection engine (regex · Sentinel v2 · LLM judge) — 95.1% PINT balanced accuracy. Detection core of TUP AIGSMP. Built at Apart Research Global South Hackathon 2026.
Machine Learning based Network Intrusion Detection System with real-time packet analysis and MERN dashboard.
Opensource detections for web related artifacts and access requests
Python-based AI security detection platform — detects prompt injection, data exfiltration and unsafe agent actions across chat and agentic AI systems
Enterprise defense tool for **Living Off the Agent (LOTA)** attacks — indirect prompt injection used to hijack enterprise AI agents (Copilot, Salesforce Agentforce, internal dev-tool bots, etc.) for lateral movement.
SOC home lab using Elastic SIEM: endpoint logging, detections (KQL), and incident reports.
Multi-platform threat detection pipeline with SIEM simulation (Linux, AIX, Unix, Cloud)
AIGSMP (SIEM for AI) for the LLM intelligence layer — hybrid detection engine (regex · classifier · LLM judge) mapped to OWASP LLM Top 10 & MITRE ATLAS. Ingest, detect, alert. No inline blocking.
A real-time Security Information and Event Management (SIEM) system featuring a multi-stage heuristic detection engine, automated IP enrichment via VirusTotal/IP-API, and a live Streamlit SOC dashboard for visualizing global threat telemetry.
Entorno sintético local para formación en detección de identidad, investigación y flujo SOC.
High-throughput DNS intelligence and domain behavior analysis framework for offensive security and threat research.
Modular Linux attack timeline detection engine with MITRE ATT&CK mapping and CI-backed test suite.
To associate your repository with the detection-engine topic, visit your repo's landing page and select "manage topics."