The detection engine: correlation rules on the event stream you already forward, outside the SIEM. Sequences across hosts in log time, state that survives a crash. Rust, no JVM, embeddable.
-
Updated
Sep 27, 2026 - Rust
The detection engine: correlation rules on the event stream you already forward, outside the SIEM. Sequences across hosts in log time, state that survives a crash. Rust, no JVM, embeddable.
Правила корреляции и нормализаторы для KUMA
A community-driven collection of multi-event correlation detection rules in Sigma format — built for threat hunters and defenders.
Backup Crowdstrike NGSIEM correlation rules, lookups, custom parsers /AND Falcon Fusion SOAR workflows to dated folders on disk using the FalconPy.
Analyze IBM QRadar CRE performance from JMX TSV exports. Ranked rule reports (HTML/JSON/CSV/MD) with optimization recommendations. Not affiliated with IBM.
Splunk Enterprise home lab — SPL queries, correlation rules, threat hunting, and detection engineering using Windows and Linux logs
To associate your repository with the correlation-rules topic, visit your repo's landing page and select "manage topics."