Feature Question: Zircolite
Good Morning. In Zircolite page (on Artifact Exchange) you said "This artifact currently supports usage of the built-in rulesets. Support for custom ruleset usage will be added in the future.". Can you tell me the estimated time for this feature add? Thanks in advance.
I'll see if I can get it added in the next week or so. 😄
This is super-intersting. It would be awesome to launch specific SIGMA-based Zircolite rules as Velociraptor hunts. @weslambert have you got news about this? Besides that, do you need any help in this effort. I have a pretty huge lab to roll out new experimental features and test them... just let me know?
Sorry, this slipped off my radar. Should have it updated very soon!
Sorry, this slipped off my radar. Should have it updated very soon!
Awesome! Let me repeat : should you think having a second huge lab could be useful, don't hesitate to ask.
I made a quick change here: https://github.com/Velocidex/velociraptor-docs/pull/312. Let me know if that performs as you would expect.
If this is still an issue for 0.6.7-4 please reopen