wagga40 / Zircolite

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
671 stars 91 forks source link

Zircolite.kape #42

Closed conexioninversa closed 1 year ago

conexioninversa commented 1 year ago

Hi, I am a big fan of the tool. I'm lovin 'it. works very very well. Congratulations.

I wanted to inform you that I have created a module for kape so that the blue team community can use your tool. It's been available a few hours ago at:

https://github.com/EricZimmerman/KapeFiles/tree/master/Modules/Apps/GitHub

Also, if you don't mind, I'll create a fork of Zircolite and add some additions that may be interesting and powerful collaborate in the improvement of Zircolite.

Great job, the community needs tools like yours to help investigate more easily. Thank you

wagga40 commented 1 year ago

That's very nice of you !

You can fork the project, it is one of the reason of posting it on GitHub. Pull Requests will be welcomed warmly 😁