Skip to content

Zircolite

SIEM & Threat Detection

A standalone Python tool that applies SIGMA detection rules to diverse log formats (EVTX, Auditd, Sysmon for Linux, CSV, XML, JSON) with automatic format detection and flexible export options

Python Latest v3.7.6 · 1mo ago Security brief →

Features

  • Automatic log type detection using magic bytes, content analysis, and regex fallback
  • Supports multiple input formats including EVTX, JSON Lines, JSON Arrays, CSV, XML, and compressed/archived logs
  • Native Sigma rule support via pySigma conversion without internal translation
  • Flexible export to JSON, CSV, Splunk, Elastic, Zinc, Timesketch, etc. using Jinja templates
  • Rich terminal output with severity-sorted tables, ATT&CK heatmaps, and post‑run suggestions

Recent releases

View all 15 releases →
No immediate action
v3.7.6 Maintenance

Multi‑stage Docker build

No immediate action
v3.7.5 Bug fix

Performance improvements

Review required
v3.7.1 New feature

Template append flag

No immediate action
v3.7.0 New feature

Graceful Ctrl+C shutdown

v3.6.3 Bug fix

A patch to the streaming module fixes a runtime error, improving reliability for data pipelines that process continuous streams.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
831
Forks
114
Languages
Python Go Template Dockerfile

Install & Platforms

Install via
pip
Platforms
linux macos arm64

Beta — feedback welcome: [email protected]