Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
Zircolite — A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs | Kitploit
उपकरण/GitHubGitHub/wagga40/zircolite
ForensicsThreat IntelligenceIncident ResponseLog Analysis
GitHubwagga40/zircolite

Zircolite

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

रिपॉजिटरी देखें
841115363 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Standalone SIGMA-Based Detection Tool for EVTX, Auditd, Sysmon for Linux, XML, CSV, or JSONL/NDJSON Logs

python version

Zircolite is a standalone tool written in Python 3 that allows you to use SIGMA rules on:

  • MS Windows EVTX (EVTX, XML, and JSONL formats)
  • Auditd logs
  • Sysmon for Linux
  • EVTXtract
  • CSV and XML logs
  • JSON Array logs

Key Features

  • Fast: 452,554 events against 4,319 Sigma rules in 11.6 s, and 1.7 million events in 105 s — the fastest of the three on both test corpora, ahead of Hayabusa and Chainsaw, both of them Rust tools. See the benchmark.
  • Automatic Log Type Detection: Automatically identifies log formats and timestamp fields using magic bytes, content analysis, and regex-based fallback -- no need to specify format flags in most cases.
  • Multiple Input Formats: Supports various log formats including EVTX, JSON Lines, JSON Arrays, CSV, XML, and more. Compressed or archived logs (gzip, bzip2, ZIP, 7-Zip) are supported; use --archive-password for encrypted ZIP/7z.
  • Native Sigma Support: Zircolite can directly use native Sigma rules (YAML) by converting them with pySigma.
  • Sigma Correlations: Counts, value statistics and temporal sequences — absence conditions and chains included — across every input file, each alert reported with the events behind it.
  • SIGMA Backend: It is based on a SIGMA backend (SQLite) and does not use internal SIGMA-to-something conversion.
  • Advanced Log Manipulation: It can manipulate input logs by splitting fields and applying transformations, allowing for more flexible and powerful log analysis.
  • Field Transforms: Apply custom Python transformations to fields during processing (e.g., Base64 decoding, hex-to-ASCII conversion).
  • Flexible Export: Zircolite can export results to multiple formats using Jinja templates, including JSON, CSV, JSONL, Splunk, Elastic, OpenSearch, Timesketch, SARIF, ATT&CK Navigator, and more.
  • Rich Terminal Output: Detection results displayed in severity-sorted tables with MITRE ATT&CK technique IDs, ATT&CK tactics heatmap, rule coverage metrics, and clickable output file links.

You can use Zircolite directly with Python, or download a standalone binary that needs no Python installation.

Documentation is available here (dedicated site) or here (repository directory).

Requirements / Installation

[!NOTE] Everything in this section applies only when running Zircolite from source. The standalone binaries and the Docker image carry their own Python, every dependency and the compiled kernel: they need no Python, no package manager and no C compiler.

The project has been tested with Python 3.10 and above. Dependencies are declared in pyproject.toml; install them from the cloned repository with PDM (pdm install), uv (uv sync) or Poetry (poetry install).

The examples below run python3 zircolite.py: activate the environment the tool created, or prefix them with pdm run, uv run or poetry run.

Dependencies

  • Required: orjson, xxhash, rich, rich-argparse, RestrictedPython, requests, urllib3, pySigma, evtx (pyevtx-rs), jinja2, lxml, chardet, psutil, pyyaml, py7zr, ijson, pyahocorasick, pyroaring
  • py7zr is imported only when a .7z input is opened; ZIP, gzip and bzip2 use the standard library.

⚠️ Install a C compiler first

Installing from source compiles Zircolite's flattening kernel with Cython — but only if a C compiler is already there. Without one the install still succeeds and every run flattens events in Python instead, which is slower. The binaries and the Docker image are built with the kernel already compiled, so this does not concern them.

So install the toolchain before pdm install:

PlatformPrerequisite
Debian, Ubuntuapt install build-essential python3-dev
RHEL, Fedora, Rockydnf install gcc python3-devel
Alpineapk add build-base python3-dev
macOSxcode-select --install
WindowsBuild Tools for Visual Studio ("Desktop development with C++")

Cython itself needs no installing: it is a build-time requirement, fetched into an isolated build environment and never added to your environment.

Standalone binaries

Every release publishes a self-contained package per platform. Each carries its own Python and every dependency, so nothing has to be installed first.

TargetArchiveRuns on
linux-x64Zircolite-<version>-linux-x64.zipglibc 2.28 or later: RHEL 8, Debian 10, Ubuntu 20.04 and newer
linux-arm64Zircolite-<version>-linux-arm64.zipglibc 2.28 or later
macos-arm64Zircolite-<version>-macos-arm64.zipmacOS 15 or later, Apple silicon
windows-x64Zircolite-<version>-windows-x64.zipWindows 10 or later
windows-arm64Zircolite-<version>-windows-arm64.zipWindows 10 or later, ARM64

Intel Macs and musl-based distributions such as Alpine have no binary; use Python or Docker there.

unzip Zircolite-<version>-linux-x64.zip
cd Zircolite-<version>-linux-x64
./Zircolite --events sysmon.evtx --ruleset rules/rules_windows_merged.json

In the examples below, replace python3 zircolite.py with the path to the executable.

The binaries are not code-signed. macOS quarantines a download made with a browser, the extracted files inherit the flag, and Gatekeeper then blocks the executable and every library in _internal/. Clear it from the whole directory, recursively, before the first run:

xattr -dr com.apple.quarantine Zircolite-<version>-macos-arm64

Quick Start

Check out (old) tutorials made by others (EN, ES, and FR) here.

EVTX Files

Help is available with:

# Don't forget to prefix with "pdm run" or "uv run" or "poetry run" when needed
python3 zircolite.py -h

If your EVTX files have the extension ".evtx":

# python3 zircolite.py --evtx <EVTX FOLDER or EVTX FILE> --ruleset <SIGMA RULESET> [--ruleset <OTHER RULESET>]
python3 zircolite.py --evtx sysmon.evtx --ruleset rules/rules_windows_merged.json

--ruleset can be left out: Zircolite then uses rules/rules_windows_merged.json, which covers Sysmon and the generic Windows channels.

Using Native Sigma Rules (YAML)

You can use native Sigma rules (YAML) directly:

# Single YAML rule
python3 zircolite.py --evtx sample.evtx --ruleset path/to/rule.yml

# Directory of Sigma rules
python3 zircolite.py --evtx sample.evtx --ruleset ./sigma/rules/windows/process_creation

# With pySigma pipelines
python3 zircolite.py --evtx sample.evtx --ruleset rule.yml --pipeline sysmon --pipeline windows-logsources

--pipeline-list shows the installed pipelines. Naming one that is not installed stops the run with exit code 2, before any rule is converted.

Other Log Formats

Zircolite auto-detects the log format in most cases, so explicit format flags are optional:

टूल डाउनलोड करें