wagga40 / Zircolite

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
671 stars 91 forks source link

Add xxhash with events #45

Closed ZikyHD closed 1 year ago

ZikyHD commented 1 year ago

Add xxhash to easily go back to the event that caused the alert