Zircolite is a standalone tool written in Python 3 that allows the use of SIGMA rules on various log formats including MS Windows EVTX, Auditd, Sysmon for Linux, EVTXtract, CSV, and XML. It is relatively fast, based on a Sigma backend (SQLite), and can export results to multiple formats like JSON, CSV, Splunk, Elastic, Zinc, and Timesketch. Zircolite can be used directly in Python or through provided binaries.
Common questions about Zircolite including features, pricing, alternatives, and user reviews.
Zircolite is Standalone SIGMA-based detection tool for EVTX, Auditd, Sysmon for Linux, XML or JSONL/NDJSON Logs. It is a Security Operations solution designed to help security teams with Log Management, Security Tools.
Zircolite is a free Security Operations tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/wagga40/Zircolite/ for download and installation instructions.
Popular alternatives to Zircolite include:
Compare all Zircolite alternatives at https://cybersectools.com/alternatives/zircolite
Zircolite is for security teams and organizations that need Log Management, Security Tools. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Security Operations tools can be found at https://cybersectools.com/categories/security-operations
Head-to-head feature, pricing, and rating breakdowns.
SOC resilience platform detecting & repairing drift in detection rules and pipelines.
A Yara ruleset designed to detect PHP shells and other webserver malware for malware analysis and threat detection.
Sigma is a generic and open signature format for SIEM systems and other security tools to detect and respond to threats.