andrewkolagit/DetectPack-Forge
DetectPack Forge turns plain-English behaviors or sample logs into production-ready detection packs — Sigma, KQL (Sentinel), SPL (Splunk) — plus tests and a response playbook, mapped to MITRE ATT&CK, fully powered by Gen AI.
Generates detection artifacts through a two-stage Gemini AI pipeline: first inferring logsource, field schemas, and MITRE techniques from behavior descriptions or log samples, then synthesizing Sigma/KQL/SPL rules and test cases from that intermediate schema. Frontend (Vite + React) webhooks to n8n for orchestration, enabling local deployment without modifying core detection logic.
No commits in the last 6 months.
Stars
24
Forks
1
Language
TypeScript
License
—
Category
Last pushed
Sep 15, 2025
Commits (30d)
0
Get this data via API
curl "https://pt-edge.onrender.com/api/v1/quality/agents/andrewkolagit/DetectPack-Forge"
Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.
Higher-rated alternatives
AgentSeal/agentseal
Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor...
Nebulock-Inc/agentic-threat-hunting-framework
ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and...
cosai-oasis/secure-ai-tooling
The CoSAI Risk Map is a framework for identifying, analyzing, and mitigating security risks in...
HeadyZhang/agent-audit
Static security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis....
oasm-platform/open-asm
Open-source platform for cybersecurity Attack Surface Management (OASM).