Zircolite is a standalone tool written in Python 3 that allows the use of SIGMA rules on various log formats including MS Windows EVTX, Auditd, Sysmon for Linux, EVTXtract, CSV, and XML. It is relatively fast, based on a Sigma backend (SQLite), and can export results to multiple formats like JSON, CSV, Splunk, Elastic, Zinc, and Timesketch. Zircolite can be used directly in Python or through provided binaries.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A tool that collects and displays user activity and system events on a Windows system.
Investigate malicious logons by visualizing and analyzing Windows Active Directory event logs with LogonTracer.
A logging proxy tool created in response to the 'MongoDB Apocalypse', with Docker support.
HonnyPotter is a WordPress plugin that logs all failed login attempts, with a caution to use it at your own risk.
Sysmon for Linux is a tool that monitors and logs system activity with advanced filtering to identify malicious activity.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.