Zircolite is a standalone tool written in Python 3. It allows to use SIGMA rules on : MS Windows EVTX (EVTX, XML and JSONL format), Auditd logs, Sysmon for Linux and EVTXtract logs.
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs.