Add: wagga40/Zircolite to DFIR section

This commit is contained in:
pe3zx 2021-04-11 19:14:31 +07:00
parent 0fee41049b
commit 0dbd10c698

View File

@ -1444,6 +1444,10 @@ This repository is created as an online bookmark for useful links, resources and
<td><a href="https://wazuh.com/">Wazuh</a></td>
<td>Open Source Host and Endpoint Security</td>
</tr>
<tr>
<td><a href="https://github.com/wagga40/Zircolite">wagga40/Zircolite</a></td>
<td>A standalone SIGMA-based detection tool for EVTX.</td>
</tr>
<tr>
<td><a href="https://github.com/williballenthin/EVTXtract">williballenthin/EVTXtract</a></td>
<td>EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.</td>