Zircolite Logo

Zircolite

0
Free
Visit Website

Zircolite is a standalone tool written in Python 3 that allows the use of SIGMA rules on various log formats including MS Windows EVTX, Auditd, Sysmon for Linux, EVTXtract, CSV, and XML. It is relatively fast, based on a Sigma backend (SQLite), and can export results to multiple formats like JSON, CSV, Splunk, Elastic, Zinc, and Timesketch. Zircolite can be used directly in Python or through provided binaries.

FEATURES

ALTERNATIVES

Browse a library of EQL analytics now natively integrated in Elasticsearch.

Free

A centralized tool for security monitoring and analysis that integrates various open source big data technologies.

Free

Python library and command line tools for log visualization with interactive plots.

Free

ELAT (Event Log Analysis Tool) is a tool that helps in analyzing Windows event logs for malware detection.

Free

An Event Hub to gather, process, and monitor system events and link them to an inventory.

Free

GrokEVT is a tool for reading Windows event log files and converting them to a human-readable format.

Free

A Command Line Map-Reduce tool for analyzing cowrie log files over time and creating visualizations and statistics.

Free

Security-Guard helps secure microservices and serverless containers by detecting and blocking exploits.

Free