<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>evtx</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/1715/feed"/>
    <updated>2026-06-14T23:25:34+00:00</updated>
    <id>https://links.biapy.com/guest/tags/1715/feed</id>
            <entry>
            <id>https://links.biapy.com/links/3575</id>
            <title type="text"><![CDATA[Zircolite]]></title>
            <link rel="alternate" href="https://wagga40.github.io/Zircolite/#/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3575"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Zircolite is a standalone tool written in Python 3. It allows to use SIGMA rules on : MS Windows EVTX (EVTX, XML and JSONL format), Auditd logs, Sysmon for Linux and EVTXtract logs.

- [Zircolite @ GitHub](https://github.com/wagga40/Zircolite).]]>
            </summary>
            <updated>2025-08-29T01:53:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4321</id>
            <title type="text"><![CDATA[Zircolite]]></title>
            <link rel="alternate" href="https://github.com/wagga40/Zircolite" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4321"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs.

- [Comment effectuer une investigation numérique sur les journaux d’évènements Windows avec Zircolite ? @ IT-Connect :fr:](https://www.it-connect.fr/zircolite-investigation-numerique-journaux-securite-windows/).]]>
            </summary>
            <updated>2025-08-29T03:58:19+00:00</updated>
        </entry>
    </feed>
