Skip to main content

Detection Engineering & Response

Platforms and engines that collect server and endpoint logs, correlate them with threat intelligence, and generate alerts on suspicious behavior. This category includes SIEM, EDR, SOAR, network detection engines (IDS/IPS/NDR), and malware pattern-matching tools.

8 Tools Cataloged
ToolLicensePlatformsPricingAction
Amazon GuardDutyProprietaryAWSCommercialProfile
osctrlMITLinux, macOS, WindowsOpen SourceProfile
osqueryApache-2.0 OR GPL-2.0-onlyLinux, macOS, WindowsOpen SourceProfile
ShuffleAGPL-3.0-only (backend); MIT (apps, SDK, workflows, docs)Linux, macOS, WindowsFree / CommercialProfile
SigmaDRL-1.1Platform-agnostic (rule format)FreeProfile
SnortGPL-2.0-onlyLinux, FreeBSDOpen SourceProfile
WazuhGPL-2.0-only with OpenSSL linking exceptionLinux, Windows, macOSFree / CommercialProfile
YARABSD-3-ClauseLinux, macOS, WindowsOpen SourceProfile

Tools in Detection Engineering & Response

AWS managed threat detection service that monitors CloudTrail, VPC Flow Logs, and DNS logs for anomalies across accounts and workloads.

LicenseProprietary
PlatformAWS

osctrl

Open Source

Go-based fleet manager for osquery endpoints with admin UI, REST API, and distributed query management for scalable telemetry.

LicenseMIT
PlatformLinux, macOS, Windows

osquery

Open Source

Operating system instrumentation framework that exposes low-level system telemetry as SQL tables for security monitoring.

LicenseApache-2.0 OR GPL-2.0-only
PlatformLinux, macOS, Windows

Shuffle

Free / Commercial

Open-source SOAR platform that automates security workflows, integrates threat intelligence and case tools, and supports hybrid deployments.

LicenseAGPL-3.0-only (backend); MIT (apps, SDK, workflows, docs)
PlatformLinux, macOS, Windows

Sigma

Free

Generic signature format for describing log detection rules, enabling portable threat detections across different SIEMs.

LicenseDRL-1.1
PlatformPlatform-agnostic (rule format)

Snort

Open Source

Open-source network intrusion detection and prevention engine that inspects traffic with rule-based signatures and protocol analysis.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD

Wazuh

Free / Commercial

Open-source SIEM and XDR platform providing endpoint monitoring, log analysis, file integrity checks, and threat detection.

LicenseGPL-2.0-only with OpenSSL linking exception
PlatformLinux, Windows, macOS

YARA

Open Source

Pattern-matching engine that helps malware researchers identify and classify binary samples based on text and binary rules.

LicenseBSD-3-Clause
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is Detection Engineering & Response?

Platforms and engines that collect server and endpoint logs, correlate them with threat intelligence, and generate alerts on suspicious behavior. This category includes SIEM, EDR, SOAR, network detection engines (IDS/IPS/NDR), and malware pattern-matching tools.

What topics does the Detection Engineering & Response category cover?

SIEM Log Aggregation & Correlation, Endpoint Detection & Response (EDR), Security Orchestration & Response (SOAR), Network IDS / IPS, Detection Rule Engineering (Sigma / YARA)

About Detection Engineering & Response

Detection engineering tools collect, correlate, and alert on security events from servers, endpoints, and network traffic. The category spans several tool types. SIEM platforms aggregate logs from across an organization and apply correlation rules to surface suspicious activity. EDR agents monitor endpoint processes, file operations, and network connections to detect malware and lateral movement. SOAR platforms automate alert triage and response actions, reducing the time analysts spend on repetitive investigation steps. Network detection engines like Snort and Suricata inspect traffic against signature and protocol anomaly rules, while Zeek provides session-level logging for forensic reconstruction. Detection rule frameworks like Sigma let teams write vendor-neutral rules and convert them to platform-specific query languages. The category also includes YARA, a pattern-matching tool used to identify and classify malware samples by file content. Teams building detection engineering programs use these tools together: SIEM for log aggregation and correlation, EDR for endpoint visibility, SOAR for response automation, and Sigma for portable rule management.

Covered Topics & Disciplines

SIEM Log Aggregation & CorrelationEndpoint Detection & Response (EDR)Security Orchestration & Response (SOAR)Network IDS / IPSDetection Rule Engineering (Sigma / YARA)