Skip to content

Tags: killvxk/Zircolite

Tags

1.4.0

Toggle 1.4.0's commit message
Added the ability to filter events by date, and to filter rule by name

Updated readme & rulesets

1.3.5

Toggle 1.3.5's commit message
Changed event forwarding. It is now possible to forward to Splunk HEC

Changed Field names to keep case
Added a "showall" option to view all executed rules
Removed "fields" option
Added a "stream" option to forward event after each detection
Updated readme with Splunk HEC

1.3.1

Toggle 1.3.1's commit message
Updated rules

1.3.0

Toggle 1.3.0's commit message
Updated rulesets

1.3.0b

Toggle 1.3.0b's commit message
Changed the file filters functionality (new args : select & avoid)

Updated the readme with details on file filters

1.2.5

Toggle 1.2.5's commit message
Updated sigmac config & updated rules

Updated rules readme
Bump version to 1.2.5

1.2.3

Toggle 1.2.3's commit message
Corrected results for rules with aggregate, updated rules

1.2.2

Toggle 1.2.2's commit message
Updated rules with last sigma repo update

1.2.1

Toggle 1.2.1's commit message
Updated SIGMAC config files and rules. Removed a lot of false positive

1.2.0

Toggle 1.2.0's commit message
Moved zircolite_mp