Detection Engineering & Response
Platforms and engines that collect server and endpoint logs, correlate them with threat intelligence, and generate alerts on suspicious behavior. This category includes SIEM, EDR, SOAR, network detection engines (IDS/IPS/NDR), and malware pattern-matching tools.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| Amazon GuardDuty | Proprietary | AWS | Commercial | Profile→ |
| osctrl | MIT | Linux, macOS, Windows | Open Source | Profile→ |
| osquery | Apache-2.0 OR GPL-2.0-only | Linux, macOS, Windows | Open Source | Profile→ |
| Shuffle | AGPL-3.0-only (backend); MIT (apps, SDK, workflows, docs) | Linux, macOS, Windows | Free / Commercial | Profile→ |
| Sigma | DRL-1.1 | Platform-agnostic (rule format) | Free | Profile→ |
| Snort | GPL-2.0-only | Linux, FreeBSD | Open Source | Profile→ |
| Wazuh | GPL-2.0-only with OpenSSL linking exception | Linux, Windows, macOS | Free / Commercial | Profile→ |
| YARA | BSD-3-Clause | Linux, macOS, Windows | Open Source | Profile→ |
Tools in Detection Engineering & Response
Amazon GuardDuty
CommercialAWS managed threat detection service that monitors CloudTrail, VPC Flow Logs, and DNS logs for anomalies across accounts and workloads.
osctrl
Open SourceGo-based fleet manager for osquery endpoints with admin UI, REST API, and distributed query management for scalable telemetry.
osquery
Open SourceOperating system instrumentation framework that exposes low-level system telemetry as SQL tables for security monitoring.
Shuffle
Free / CommercialOpen-source SOAR platform that automates security workflows, integrates threat intelligence and case tools, and supports hybrid deployments.
Sigma
FreeGeneric signature format for describing log detection rules, enabling portable threat detections across different SIEMs.
Snort
Open SourceOpen-source network intrusion detection and prevention engine that inspects traffic with rule-based signatures and protocol analysis.
Wazuh
Free / CommercialOpen-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.
YARA
Open SourcePattern-matching engine that helps malware researchers identify and classify binary samples based on text and binary rules.
Frequently Asked Questions
What is Detection Engineering & Response?→
Platforms and engines that collect server and endpoint logs, correlate them with threat intelligence, and generate alerts on suspicious behavior. This category includes SIEM, EDR, SOAR, network detection engines (IDS/IPS/NDR), and malware pattern-matching tools.
What topics does the Detection Engineering & Response category cover?→
SIEM Log Aggregation & Correlation, Endpoint Detection & Response (EDR), Security Orchestration & Response (SOAR), Network IDS / IPS, Detection Rule Engineering (Sigma / YARA)
About Detection Engineering & Response
Detection engineering tools collect, correlate, and alert on security events from servers, endpoints, and network traffic. The category spans several tool types. SIEM platforms aggregate logs from across an organization and apply correlation rules to surface suspicious activity. EDR agents monitor endpoint processes, file operations, and network connections to detect malware and lateral movement. SOAR platforms automate alert triage and response actions, reducing the time analysts spend on repetitive investigation steps. Network detection engines like Snort and Suricata inspect traffic against signature and protocol anomaly rules, while Zeek provides session-level logging for forensic reconstruction. Detection rule frameworks like Sigma let teams write vendor-neutral rules and convert them to platform-specific query languages. The category also includes YARA, a pattern-matching tool used to identify and classify malware samples by file content. Teams building detection engineering programs use these tools together: SIEM for log aggregation and correlation, EDR for endpoint visibility, SOAR for response automation, and Sigma for portable rule management.
Covered Topics & Disciplines
Related Security Categories
Disk and memory forensics, malware sandboxes, and incident response collection platforms.
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
Threat intelligence platforms, IOC sharing communities, and STIX/TAXII tooling for collecting and distributing threat data.