Zion Boggan zionboggan.com ↗

add detection-as-code to labs

92fd666   Zion Boggan committed on May 29, 2026 (3 weeks ago)
assets/detection.png +0 -0
Binary file not shown
index.html +12 -0
@@ -221,6 +221,18 @@
<div class="shead"><span class="idx mono">02</span><h2>Security Labs</h2><span class="rule"></span></div>
<div class="cards">
+ <a class="card" href="https://github.com/zionboggan/detection-as-code">
+ <div class="thumb"><img loading="lazy" src="assets/detection.png" alt="One Sigma rule compiled to Splunk, Sentinel KQL and Elastic ES|QL"></div>
+ <div class="body">
+ <h3>Detection-as-Code</h3>
+ <p>Sigma rules mapped to MITRE ATT&CK, linted and tested in CI, and compiled to
+ Splunk, Elastic, and Microsoft Sentinel KQL - one rule, every SIEM. Detection
+ engineering done as a pipeline, not a console click.</p>
+ <div class="tags"><span>Sigma</span><span>Splunk</span><span>Sentinel KQL</span><span>Elastic</span></div>
+ <span class="lnk mono">detection-as-code</span>
+ </div>
+ </a>
+
<a class="card" href="https://github.com/zionboggan/soc-automation-lab">
<div class="thumb"><img loading="lazy" src="assets/soc.png" alt="Wazuh Threat Hunting dashboard with MITRE ATT&CK mapping"></div>
<div class="body">