wagga40 / Zircolite

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
680 stars 91 forks source link

Zircolite package #87

Open a-vine opened 2 months ago

a-vine commented 2 months ago

I've been using your project for a few months as part of a pipeline designed to reconstruct attack scenarios from heterogeneous raw logs (Windows and Linux). So far I've made a wrapper for Zircolite, but it's not very clean. Is it possible to make Zircolite a PyPi package so that it can be integrated more easily and cleanly into other projects?

wagga40 commented 1 month ago

Hi, sorry for the late response. Zircolite was on PyPi but as a cli tool and not a library, it was a little bit messy so I decided to remove it. To have something clean and available on Pypi, some parts of Zircolite must be rewritten. To be honest, I am working on it but there are some things I want to release before :