
Zircolite v3.8.1
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Standalone SIGMA-Based Detection Tool for EVTX, Auditd, Sysmon for Linux, XML, CSV, or JSONL/NDJSON Logs

Zircolite is a standalone tool written in Python 3 that allows you to use SIGMA rules on:
- MS Windows EVTX (EVTX, XML, and JSONL formats)
- Auditd logs
- Sysmon for Linux
- EVTXtract
- CSV and XML logs
- JSON Array logs
Key Features
- Fast: 452,554 events against 4,319 Sigma rules in 11.6 s, and 1.7 million events in 105 s — the fastest of the three on both test corpora, ahead of Hayabusa and Chainsaw, both of them Rust tools. See the benchmark.
- Automatic Log Type Detection: Automatically identifies log formats and timestamp fields using magic bytes, content analysis, and regex-based fallback -- no need to specify format flags in most cases.
- Multiple Input Formats: Supports various log formats including EVTX, JSON Lines, JSON Arrays, CSV, XML, and more. Compressed or archived logs (gzip, bzip2, ZIP, 7-Zip) are supported; use
--archive-passwordfor encrypted ZIP/7z. - Native Sigma Support: Zircolite can directly use native Sigma rules (YAML) by converting them with pySigma.
- Sigma Correlations: Counts, value statistics and temporal sequences — absence conditions and chains included — across every input file, each alert reported with the events behind it.
- SIGMA Backend: It is based on a SIGMA backend (SQLite) and does not use internal SIGMA-to-something conversion.
- Advanced Log Manipulation: It can manipulate input logs by splitting fields and applying transformations, allowing for more flexible and powerful log analysis.
- Field Transforms: Apply custom Python transformations to fields during processing (e.g., Base64 decoding, hex-to-ASCII conversion).
- Flexible Export: Zircolite can export results to multiple formats using Jinja templates, including JSON, CSV, JSONL, Splunk, Elastic, OpenSearch, Timesketch, SARIF, ATT&CK Navigator, and more.
- Rich Terminal Output: Detection results displayed in severity-sorted tables with MITRE ATT&CK technique IDs, ATT&CK tactics heatmap, rule coverage metrics, and clickable output file links.
You can use Zircolite directly with Python, or download a standalone binary that needs no Python installation.
Documentation is available here (dedicated site) or here (repository directory).
Requirements / Installation
[!NOTE] Everything in this section applies only when running Zircolite from source. The standalone binaries and the Docker image carry their own Python, every dependency and the compiled kernel: they need no Python, no package manager and no C compiler.
The project has been tested with Python 3.10 and above. Dependencies are declared in
pyproject.toml; install them from the cloned repository with
PDM (pdm install), uv
(uv sync) or Poetry (poetry install).
The examples below run python3 zircolite.py: activate the environment the tool created,
or prefix them with pdm run, uv run or poetry run.
Dependencies
- Required:
orjson,xxhash,rich,rich-argparse,RestrictedPython,requests,urllib3,pySigma,evtx(pyevtx-rs),jinja2,lxml,chardet,psutil,pyyaml,py7zr,ijson,pyahocorasick,pyroaring py7zris imported only when a.7zinput is opened; ZIP, gzip and bzip2 use the standard library.
⚠️ Install a C compiler first
Installing from source compiles Zircolite's flattening kernel with Cython — but only if a C compiler is already there. Without one the install still succeeds and every run flattens events in Python instead, which is slower. The binaries and the Docker image are built with the kernel already compiled, so this does not concern them.
So install the toolchain before pdm install:
| Platform | Prerequisite |
|---|---|
| Debian, Ubuntu | apt install build-essential python3-dev |
| RHEL, Fedora, Rocky | dnf install gcc python3-devel |
| Alpine | apk add build-base python3-dev |
| macOS | xcode-select --install |
| Windows | Build Tools for Visual Studio ("Desktop development with C++") |
Cython itself needs no installing: it is a build-time requirement, fetched into an isolated build environment and never added to your environment.
Standalone binaries
Every release publishes a self-contained package per platform. Each carries its own Python and every dependency, so nothing has to be installed first.
| Target | Archive | Runs on |
|---|---|---|
linux-x64 | Zircolite-<version>-linux-x64.zip | glibc 2.28 or later: RHEL 8, Debian 10, Ubuntu 20.04 and newer |
linux-arm64 | Zircolite-<version>-linux-arm64.zip | glibc 2.28 or later |
macos-arm64 | Zircolite-<version>-macos-arm64.zip | macOS 15 or later, Apple silicon |
windows-x64 | Zircolite-<version>-windows-x64.zip | Windows 10 or later |
windows-arm64 | Zircolite-<version>-windows-arm64.zip | Windows 10 or later, ARM64 |
Intel Macs and musl-based distributions such as Alpine have no binary; use Python or Docker there.
unzip Zircolite-<version>-linux-x64.zip
cd Zircolite-<version>-linux-x64
./Zircolite --events sysmon.evtx --ruleset rules/rules_windows_merged.json
In the examples below, replace python3 zircolite.py with the path to the executable.
The binaries are not code-signed. macOS quarantines a download made with a browser, the
extracted files inherit the flag, and Gatekeeper then blocks the executable and every
library in _internal/. Clear it from the whole directory, recursively, before the first
run:
xattr -dr com.apple.quarantine Zircolite-<version>-macos-arm64
Quick Start
Check out (old) tutorials made by others (EN, ES, and FR) here.
EVTX Files
Help is available with:
# Don't forget to prefix with "pdm run" or "uv run" or "poetry run" when needed
python3 zircolite.py -h
If your EVTX files have the extension ".evtx":
# python3 zircolite.py --evtx <EVTX FOLDER or EVTX FILE> --ruleset <SIGMA RULESET> [--ruleset <OTHER RULESET>]
python3 zircolite.py --evtx sysmon.evtx --ruleset rules/rules_windows_merged.json
--ruleset can be left out: Zircolite then uses rules/rules_windows_merged.json, which
covers Sysmon and the generic Windows channels.
Using Native Sigma Rules (YAML)
You can use native Sigma rules (YAML) directly:
# Single YAML rule
python3 zircolite.py --evtx sample.evtx --ruleset path/to/rule.yml
# Directory of Sigma rules
python3 zircolite.py --evtx sample.evtx --ruleset ./sigma/rules/windows/process_creation
# With pySigma pipelines
python3 zircolite.py --evtx sample.evtx --ruleset rule.yml --pipeline sysmon --pipeline windows-logsources
--pipeline-list shows the installed pipelines. Naming one that is not installed stops
the run with exit code 2, before any rule is converted.
Other Log Formats
Zircolite auto-detects the log format in most cases, so explicit format flags are optional: