issues
search
wagga40
/
Zircolite
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
671
stars
91
forks
source link
v2.7.0
#30
Closed
wagga40
closed
2 years ago
wagga40
commented
2 years ago
Auditd support
New coloured output with rule levels
Updated readme (docs will be updated too...)
New rulesets : the default ruleset is now limited to high and critical rules