Attack Detection Engine

5-source telemetry pipeline · 42 detection rules · ATT&CK mappings · 53% minimum coverage gate in CI · Source repo ↗
Static benchmark data. The repository documents 42 rules across log, traffic, behaviour, EDR event, and code telemetry sources; that rule count is explicitly marked as not independently reproduced in the source README. CI currently enforces a --cov-fail-under=53 minimum. This is a pattern-matching engine with ATT&CK mappings — not an ML-based anomaly detector.
53%
Minimum coverage gate
CI --cov-fail-under=53
0
Documented rules
5
Telemetry sources
Log/traffic/behaviour/event/code
29
Collected test cases
23 test functions · README snapshot
Detector surfaces
Log telemetry
LogDetector
Network traffic
TrafficDetector
Process behaviour
BehaviorDetector
EDR/SIEM events
EventDetector
Source code
CodeDetector
Evidence boundary

This repository is a rule-based detection/mapping library, not an EDR, SIEM, telemetry collector, or ML anomaly detector. The source README currently labels the documented 42-rule total as unverified until reproduced with the sibling attack-v19-core installed.