Back to updates
New releaseSep 21, 2026

Zircolite v4.0.0

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Share

Zircolite

Standalone Sigma-based detection for EVTX, Auditd, Sysmon for Linux, XML, CSV and JSON logs

python version

Zircolite runs Sigma rules over your logs. It flattens events into SQLite, turns each rule into an SQL query and reports what matches, offline, in one command.

Zircolite in a terminal

  • Many log formats, detected automatically: Windows EVTX (binary, XML, JSON), Auditd, Sysmon for Linux, EVTXtract, CSV, XML and JSON, plain or in gzip, bzip2, ZIP and 7-Zip archives.
  • Sigma rules as they are: native YAML converted with pySigma, or the ready-made rulesets in rules/. Correlation rules included.
  • Fast: a compiled flattening kernel, parallel workers and rule prefiltering; see the benchmark.
  • Field processing: split packed fields and run sandboxed Python transforms (Base64 decoding, IOC extraction, LOLBin detection, …).
  • Exports: JSON, CSV, and templates for Splunk, Elastic, OpenSearch, Timesketch, SARIF and ATT&CK Navigator.
  • Zircolite Viewer: every event and detection in one zip that opens offline in a browser.

📖 Read the documentation, also in docs/.

Install

RouteHow
Standalone binary, nothing to installDownload the zip for your platform from the releases: Linux x64 and ARM64, macOS Apple silicon, Windows x64 and ARM64
Dockerdocker pull wagga40/zircolite:latest
From source, Python 3.10+git clone https://github.com/wagga40/Zircolite.git && cd Zircolite && pdm install (or uv sync, poetry install)

Source installs compile a native flattening kernel and need a C compiler for it; without one they fall back to a slower Python kernel. See Installation for compiler packages, binary details (macOS quarantine, checksums) and Docker permissions.

Quick start

# Windows logs, with the default ruleset (rules/rules_windows_merged.json)
python3 zircolite.py --events sysmon.evtx

# Linux logs: the format is detected
python3 zircolite.py --events auditd.log --ruleset rules/rules_linux.json

# Native Sigma rules, through pySigma pipelines
python3 zircolite.py --events logs/ --ruleset ./sigma/rules/windows/process_creation \
    --pipeline sysmon --pipeline windows-logsources

# Every event and detection, for the Zircolite Viewer
python3 zircolite.py --events logs/ --package

With a binary, run ./Zircolite instead of python3 zircolite.py. From source, prefix the command with pdm run (or uv run, poetry run) unless the environment is active. With Docker, mount the logs and give absolute paths:

docker run --rm --tty -v $PWD:/case/input:ro -v $PWD:/case/output \
    wagga40/zircolite:latest --events /case/input -o /case/output/detected_events.json

On a Linux host, add --user "$(id -u):$(id -g)" and -l /case/output/zircolite.log: the image runs as an unprivileged user that cannot write to a directory you own.

Detections go to detected_events.json. For logs to try it on, see EVTX-ATTACK-SAMPLES.

[!IMPORTANT] The default rulesets can contain noisy or slow rules. Select rules for your environment, and update them with python3 zircolite.py -U.

How it works

Zircolite flattens each event into a row of an SQLite table, converts every Sigma rule into an SQL query over that table, and reports the rows that match.

How Zircolite works: logs are flattened into rows of an SQLite table, Sigma rules become SQL queries, and matching rows become detections

Zircolite Viewer

--package writes one zip holding every event of the run, with the detections and correlation alerts linked to them. Extract it and open index.html: the viewer runs offline and offers an overview, the detections, a searchable event table, a timeline, the ATT&CK matrix, entities, process trees and an SQL console. Share a package as you would the logs it came from. See Zircolite Viewer.

A tour of the Zircolite Viewer: from the Overview to a Mimikatz detection, its event, a host search, the timeline, the ATT&CK matrix and the process tree

Benchmark

Median wall time on a 10-core Apple M1 Max, each tool at its defaults with its own rules:

Tool4 Sysmon EVTX, 478 MB8 EVTX over 11 channels, 13.3 GB
Zircolite11.6 s104.8 s
Hayabusa 4.1.024.7 s518.8 s
Chainsaw 2.16.0113.5 s206.3 s

Zircolite uses more memory than the others, through its parallel workers (--no-parallel turns them off), and the rule sets differ, so detection counts do not compare. See Benchmark for memory, setup and how to reproduce it.

Tutorials, written for earlier versions:

References:

Zircolite also runs inside KAPE and Velociraptor.

License

Categories