Detections

Interactive, expandable content (like it should’ve been)

The repo ships multi-platform detection content and IR playbooks with reproducible counts. All numbers below are Verified (reproducible today); no inflated "total library" number is shown.

Verify lane: pwsh -NoProfile -File .\scripts\verify\verify-counts.ps1 and pwsh -NoProfile -File .\scripts\verify\generate-verified-counts.ps1 -OutFile .\PROOF_PACK\VERIFIED_COUNTS.md.
Read case study: 29 Wazuh rule blocks
MITRE ATT&CK

Mapped by tactic (representative)

Sigma rules are organized by tactic. Tiles expand with examples and pivots. Full mapping lives in the repo.