Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 

README.md

Detections

This directory contains detection content managed as code.

Structure

Sentinel

Microsoft Sentinel detections are organized by ATT&CK tactic-aligned folders.

Sigma

Reserved for Sigma content where applicable.

Mappings

Used for ATT&CK and Cyber Kill Chain mapping artifacts.

Detection Expectations

Detection content should follow repository standards for:

  • naming
  • lifecycle
  • severity
  • tagging
  • metadata quality
  • folder placement

See:

Lifecycle

Detections should use one of the following lifecycle values:

  • experimental
  • testing
  • production
  • deprecated

See:

Related Content

Goal

The goal of this directory is to manage detection content as structured, governed, and maintainable engineering artifacts.