andrewkolagit/DetectPack-Forge

DetectPack Forge turns plain-English behaviors or sample logs into production-ready detection packs — Sigma, KQL (Sentinel), SPL (Splunk) — plus tests and a response playbook, mapped to MITRE ATT&CK, fully powered by Gen AI.

13
/ 100
Experimental

Generates detection artifacts through a two-stage Gemini AI pipeline: first inferring logsource, field schemas, and MITRE techniques from behavior descriptions or log samples, then synthesizing Sigma/KQL/SPL rules and test cases from that intermediate schema. Frontend (Vite + React) webhooks to n8n for orchestration, enabling local deployment without modifying core detection logic.

No commits in the last 6 months.

No License Stale 6m No Package No Dependents
Maintenance 2 / 25
Adoption 6 / 25
Maturity 1 / 25
Community 4 / 25

How are scores calculated?

Stars

24

Forks

1

Language

TypeScript

License

Last pushed

Sep 15, 2025

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/agents/andrewkolagit/DetectPack-Forge"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.