{"repo":"andrewkolagit/DetectPack-Forge","free":true,"listed":false,"github":"https://github.com/andrewkolagit/DetectPack-Forge","clone":"git clone https://github.com/andrewkolagit/DetectPack-Forge.git","description":"DetectPack Forge turns plain-English behaviors or sample logs into production-ready detection packs — Sigma, KQL (Sentinel), SPL (Splunk) — plus tests and a response playbook, mapped to MITRE ATT&CK, fully powered by Gen AI.","language":"TypeScript","stars":24,"topics":["cybersecurity","mitre-attack","n8n","n8n-workflow","playbook","secuirty","security-tools","sentinel","siem","splunk"],"license":null,"category":"security-tools","readme_excerpt":"DetectPack Forge Turn plain-English behaviors or small log samples into production-ready detection packs — Sigma, KQL (Sentinel), and SPL (Splunk) — with tests and a short response playbook, all mapped to MITRE ATT&CK. What is this? DetectPack Forge is a helper for people learning or working with SIEMs. You describe a behavior (e.g., “many failed logons then a success”) or paste a few log lines, and the app generates: Sigma (vendor-neutral rule YAML) KQL (Microsoft Sentinel) SPL (Splunk) Tests (positive/negative examples) Playbook (concise incident-response checklist) MITRE ATT&CK technique tags Why it’s useful: you don’t need to memorize different query syntaxes to begin writing detections; you learn by example and get artifacts you can paste directly into a SIEM. How it works (architecture) Frontend (Vite + React + Tailwind + shadcn-ui) Simple wizard: Describe (type behavior) or Logs (paste sample). Calls a single n8n webhook with JSON and renders the returned artifacts in tabs. Env var: VITE N8N WEBHOOK URL points to your n8n webhook. Backend (n8n + Gemini)Backend (n8n + Gemini) 1. 🛎️ Webhook (POST) receives: 2. 🧹 Preprocess Function normalizes the body: 3. 🧠 AI Agent – Schema (Gemini) infers: 4. 🧩 Parse Schema (Function) safely parses the agent output and attaches it to the flow. 5. 🧪 AI Agent – Artifacts (Gemini) creates Sigma/KQL/SPL/tests/playbook from the schema + inputs. 6. 📤 Return JSON to the webhook caller: Running Locally To run the frontend locally and con","default_branch":null,"files":null,"tree":[],"storefront":"/r/andrewkolagit","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/andrewkolagit/DetectPack-Forge/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}