Zircolite

Log analyzer

A standalone tool for analyzing and detecting security-related events in various Linux logs using SIGMA rules

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

GitHub

684 stars
25 watching
91 forks
Language: Python
last commit: almost 2 years ago
Linked from 1 awesome list

auditddetectionevtxevtxtractforensicsforensics-toolspysigmapython3sigmasigma-rulessysmon

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
sigmahq/sigmaA standardized format for describing log events to facilitate detection and analysis of security threats8,490
dogoncouch/logespA security-focused application built with Python Django to manage and analyze log data from various sources.198
dogoncouch/logdissectAnalyzes log files and other data from various sources and formats.148
jensvoid/lorgA tool to analyze and detect security incidents in web application logs209
confluentinc/confluent-sigmaA tool for analyzing and visualizing log events using structured rules53
agilescientific/striplogLithology and stratigraphic log analysis tool using Python205
thiber-org/userlineAutomates analysis of Windows Security Events to identify user logon relations241
erickramirezds/cass_log_toolsA collection of scripts for analyzing and summarizing Apache Cassandra logs.9
nshalabi/sysmontoolsUtilities for analyzing and visualizing Windows event logs from Sysmon, helping users track and monitor system activity.1,492
swall0w/torchstatAn analyzer tool for neural networks built on PyTorch1,468
yamato-security/welaAnalyzes Windows Event Logs to identify security-related events and provides forensic tools for incident response.769
monaxgt/parsefieldsTool for analyzing and structuring log data from JSON-like sources7
jpcertcc/sysmonsearchAnalyzes Sysmon event logs to detect suspicious activity and visualize process and network correlations.419
kugg/irule-detectorDetects and analyzes command injection vulnerabilities in iRules written in the Tool Command Language (Tcl), allowing for identification of potential security flaws.5
esrlabs/chipmunkA tool for analyzing and searching logfiles in large files611