Skip to main content

a sigma rule detection engine based on sqlite

Project description

zargunlite

Zargunlite is a sigma rule detection engine based on sqlite.

The core logic is inspired by Zircolite project and it is full compatible with plain sqlite queries or zircolite format rules generated by official pySigma-backend-sqlite .

This project is implemented in pure Python, with strict type annotation, well packaging and basic test coverage, making it more suitable for integration into other projects as a library.

Description

Install zargunlite from PyPI (requires python>=3.10):

pip3 install zargunlite

See tests/test_core.py for some usage sample.

Notice this project will continuously be in a very early state until version 1.0.0 release.
Currently it is mainly for personal use because Zircolite does not has a PyPI package. There is also an issue raised by other user and fortunately the author is working on it.
This project plans to add more features supported by Zircolite while keeps easy to be integrated as a library.

License

All the code is licensed under the GNU Lesser General Public License

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

zargunlite-0.1.0.tar.gz (18.9 kB view details)

Uploaded Source

Built Distribution

zargunlite-0.1.0-py3-none-any.whl (14.8 kB view details)

Uploaded Python 3

File details

Details for the file zargunlite-0.1.0.tar.gz.

File metadata

  • Download URL: zargunlite-0.1.0.tar.gz
  • Upload date:
  • Size: 18.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.1.1 CPython/3.12.7

File hashes

Hashes for zargunlite-0.1.0.tar.gz
Algorithm Hash digest
SHA256 a168726274f8c64e3348ca45bede994bf3e84440271af980b9189a02ae6e0c1b
MD5 31bcbae6de8736508c85159345a7f827
BLAKE2b-256 86cde4cdb031546d92c5b32ab29bc8d6608fa7987adcd9ebc5b2bd31ef6b5ef3

See more details on using hashes here.

File details

Details for the file zargunlite-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: zargunlite-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 14.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/5.1.1 CPython/3.12.7

File hashes

Hashes for zargunlite-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 96d2e9d7beb467139ee0276a97ca8324d42b6baad819a5a13515fa4fc605addc
MD5 8d1434ce54ab2724cfac8e1e495e4070
BLAKE2b-256 45016aa5cf756d3a95a87fcc363ec984a56aa432e9fbbb59e7935a5333bb467c

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page