
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs


Zircolite is a standalone tool written in Python 3 that allows you to use SIGMA rules on:
--archive-password for encrypted ZIP/7z.You can use Zircolite directly with Python, or download a standalone binary that needs no Python installation.
Documentation is available here (dedicated site) or here (repository directory).
[!NOTE] Everything in this section applies only when running Zircolite from source. The standalone binaries and the Docker image carry their own Python, every dependency and the compiled kernel: they need no Python, no package manager and no C compiler.
The project has been tested with Python 3.10 and above. Dependencies are declared in
pyproject.toml; install them from the cloned repository with
PDM (pdm install), uv
(uv sync) or Poetry (poetry install).
The examples below run python3 zircolite.py: activate the environment the tool created,
or prefix them with pdm run, uv run or poetry run.
orjson, xxhash, rich, rich-argparse, RestrictedPython, requests, urllib3, pySigma, evtx (pyevtx-rs), jinja2, lxml, chardet, psutil, pyyaml, py7zr, ijson, pyahocorasick, pyroaringpy7zr is imported only when a .7z input is opened; ZIP, gzip and bzip2 use the standard library.Installing from source compiles Zircolite's flattening kernel with Cython — but only if a C compiler is already there. Without one the install still succeeds and every run flattens events in Python instead, which is slower. The binaries and the Docker image are built with the kernel already compiled, so this does not concern them.
So install the toolchain before pdm install:
| Platform | Prerequisite |
|---|---|
| Debian, Ubuntu | apt install build-essential python3-dev |
| RHEL, Fedora, Rocky | dnf install gcc python3-devel |
| Alpine | apk add build-base python3-dev |
| macOS | xcode-select --install |
| Windows | Build Tools for Visual Studio ("Desktop development with C++") |
Cython itself needs no installing: it is a build-time requirement, fetched into an isolated build environment and never added to your environment.
Every release publishes a self-contained package per platform. Each carries its own Python and every dependency, so nothing has to be installed first.
| Target | Archive | Runs on |
|---|---|---|
linux-x64 | Zircolite-<version>-linux-x64.zip | glibc 2.28 or later: RHEL 8, Debian 10, Ubuntu 20.04 and newer |
linux-arm64 | Zircolite-<version>-linux-arm64.zip | glibc 2.28 or later |
macos-arm64 | Zircolite-<version>-macos-arm64.zip | macOS 15 or later, Apple silicon |
windows-x64 | Zircolite-<version>-windows-x64.zip | Windows 10 or later |
windows-arm64 | Zircolite-<version>-windows-arm64.zip | Windows 10 or later, ARM64 |
Intel Macs and musl-based distributions such as Alpine have no binary; use Python or Docker there.
unzip Zircolite-<version>-linux-x64.zip
cd Zircolite-<version>-linux-x64
./Zircolite --events sysmon.evtx --ruleset rules/rules_windows_merged.json
In the examples below, replace python3 zircolite.py with the path to the executable.
The binaries are not code-signed. macOS quarantines a download made with a browser, the
extracted files inherit the flag, and Gatekeeper then blocks the executable and every
library in _internal/. Clear it from the whole directory, recursively, before the first
run:
xattr -dr com.apple.quarantine Zircolite-<version>-macos-arm64
Check out (old) tutorials made by others (EN, ES, and FR) here.
Help is available with:
# Don't forget to prefix with "pdm run" or "uv run" or "poetry run" when needed
python3 zircolite.py -h
If your EVTX files have the extension ".evtx":
# python3 zircolite.py --evtx <EVTX FOLDER or EVTX FILE> --ruleset <SIGMA RULESET> [--ruleset <OTHER RULESET>]
python3 zircolite.py --evtx sysmon.evtx --ruleset rules/rules_windows_merged.json
--ruleset can be left out: Zircolite then uses rules/rules_windows_merged.json, which
covers Sysmon and the generic Windows channels.
You can use native Sigma rules (YAML) directly:
# Single YAML rule
python3 zircolite.py --evtx sample.evtx --ruleset path/to/rule.yml
# Directory of Sigma rules
python3 zircolite.py --evtx sample.evtx --ruleset ./sigma/rules/windows/process_creation
# With pySigma pipelines
python3 zircolite.py --evtx sample.evtx --ruleset rule.yml --pipeline sysmon --pipeline windows-logsources
--pipeline-list shows the installed pipelines. Naming one that is not installed stops
the run with exit code 2, before any rule is converted.
Zircolite auto-detects the log format in most cases, so explicit format flags are optional: