andrewkolagit/DetectPack-Forge

DetectPack Forge turns plain-English behaviors or sample logs into production-ready detection packs — Sigma, KQL (Sentinel), SPL (Splunk) — plus tests and a response playbook, mapped to MITRE ATT&CK, fully powered by Gen AI.

19
/ 100
Experimental

This tool helps cybersecurity analysts create detection rules for their Security Information and Event Management (SIEM) systems. You describe a suspicious behavior in plain English, or provide a few lines of relevant log data. The output is a complete 'detection pack' including vendor-specific queries (Sigma, KQL for Sentinel, SPL for Splunk), test cases, a response playbook, and MITRE ATT&CK tags. This is designed for security practitioners who need to quickly develop and deploy new threat detections.

No commits in the last 6 months.

Use this if you need to rapidly generate SIEM detection rules, tests, and response playbooks from a simple description or log sample, without needing to master multiple query languages.

Not ideal if you need to fine-tune existing, highly complex detection logic or if you require deep customization beyond what standard query syntaxes offer.

cybersecurity SIEM threat-detection incident-response security-operations
No License Stale 6m No Package No Dependents
Maintenance 2 / 25
Adoption 6 / 25
Maturity 7 / 25
Community 4 / 25

How are scores calculated?

Stars

24

Forks

1

Language

TypeScript

License

Last pushed

Sep 15, 2025

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/agents/andrewkolagit/DetectPack-Forge"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.