Zircolite Logo

Zircolite

0
Free
Visit Website

Zircolite is a standalone tool written in Python 3 that allows the use of SIGMA rules on various log formats including MS Windows EVTX, Auditd, Sysmon for Linux, EVTXtract, CSV, and XML. It is relatively fast, based on a Sigma backend (SQLite), and can export results to multiple formats like JSON, CSV, Splunk, Elastic, Zinc, and Timesketch. Zircolite can be used directly in Python or through provided binaries.

FEATURES

ALTERNATIVES

Security-Guard helps secure microservices and serverless containers by detecting and blocking exploits.

Free

A collection of detections for Panther SIEM with detailed setup instructions.

Free

A collection of free shareable log samples from various systems with evidence of compromise and malicious activity, maintained by Dr. Anton Chuvakin.

Free

A tool for advanced HTTPD logfile security analysis and forensics, implementing various techniques to detect attacks against web applications.

Free

A visualization app for hpfeeds logs.

Free

Converts Sigma and Yara rules to CRYPTTECH's SIEM query language.

Free

ElastAlert is a framework for alerting on anomalies in Elasticsearch data.

Free

Procmon for Linux is a reimagining of the classic Procmon tool from Windows, allowing Linux developers to trace syscall activity efficiently.

Free
CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved