Zircolite Logo

Zircolite

0
Free
Visit Website

Zircolite is a standalone tool written in Python 3 that allows the use of SIGMA rules on various log formats including MS Windows EVTX, Auditd, Sysmon for Linux, EVTXtract, CSV, and XML. It is relatively fast, based on a Sigma backend (SQLite), and can export results to multiple formats like JSON, CSV, Splunk, Elastic, Zinc, and Timesketch. Zircolite can be used directly in Python or through provided binaries.

FEATURES

ALTERNATIVES

Sysmon for Linux is a tool that monitors and logs system activity with advanced filtering to identify malicious activity.

Free

A dynamic GUI for advanced log analysis, allowing users to execute SQL queries on structured log data.

Free

Windows Event Log Analyzer with logon timeline generator and noise reduction for fast forensics.

Free

A log management solution that optimizes SIEM performance, provides rapid search and troubleshooting, and meets compliance requirements.

Commercial

Elastic is a search-powered AI company that enables users to find answers from all data in real-time at scale.

Commercial

Search AWS CloudWatch logs on the command line with aws-sdk-for-go.

Free

Browse a library of EQL analytics now natively integrated in Elasticsearch.

Free

ELAT (Event Log Analysis Tool) is a tool that helps in analyzing Windows event logs for malware detection.

Free