discovered 03 Aug 2026
sigwood
→ View on GitHubsigwood is a local-first command-line tool designed for threat hunting by analyzing existing log files from sources such as Zeek, DNS servers, and syslogs. Its primary use case is to detect anomalies, including beaconing, suspicious DNS queries, and unusual activity within a user’s network, without requiring any external deployment or configuration. Notable features include its simple installation process, a suite of detectors for various events, and the ability to run directly on logs without needing to send data to the cloud.