Back to rankings

Yamato-Security/hayabusa

Rust

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

dfirthreathuntingwindowseventlogsrustsigmadetectionattackforensicsincident
Star Growth
Stars
3.3k
Forks
282
Weekly Growth
Issues
18
1k2k3k
Dec 2021Jun 2023Jan 2025Jul 2026
Artifactscrates.iocargo add hayabusa
README

Hayabusa Logo

Windows event log fast forensics timeline generator and threat hunting tool.
Written in memory-safe Rust by Yamato Security — the only open-source tool with full Sigma support, including v2 correlation rules.

📖 Read the Documentation →

Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية

🦅 About

Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool. It is multi-threaded for speed and consolidates events from a single host or thousands of systems into one CSV / JSON / JSONL timeline — ready for analysis in LibreOffice, Timeline Explorer, Elastic Stack, Timesketch and more. It can run live on a single system, gather logs for offline analysis, or hunt across the enterprise with Velociraptor.

📖 Documentation

All documentation now lives on a dedicated, searchable, multi-language site:

👉 yamato-security.github.io/hayabusa

Section
🚀 Getting Started Download, install and run Hayabusa
⌨️ Command Reference Every command and option, with examples
📊 Timeline Output Output profiles, fields and abbreviations
🧩 Rules Detection rules and Sigma compatibility
🔎 Importing & Analysis Elastic Stack, Timesketch, Timeline Explorer, jq

⬇️ Download

Grab the latest signed binaries from the Releases page, or see Getting Started for live-response packages and building from source.

🗂️ Looking for the old README?

The previous single-page README is preserved unchanged:

🤝 Contributing & License

Contributions and bug reports are very welcome — see Contributing & Support. Hayabusa is released under the GNU AGPLv3 license; detection rules are released under the Detection Rule License (DRL) 1.1.


Made with 🦅 by Yamato Security  ·  @SecurityYamato
Related repositories
toniblyx/my-arsenal-of-aws-security-tools

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

ShellApache License 2.0cloudauditing
9.5k1.6k
meirwah/awesome-incident-response

A curated list of tools for incident response

Apache License 2.0incident-responsesecurity
9.3k1.7k
LOLBAS-Project/LOLBAS

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

XSLTGNU General Public License v3.0lolbinslolscripts
lolbas-project.github.io
8.7k1.2k
zeek/zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

C++Otherbronetwork-monitoring
zeek.org
7.8k1.4k
cugu/awesome-forensics

⭐️ A curated list of awesome forensic analysis tools and resources

Creative Commons Zero v1.0 Universalcomputer-forensicsdigital-forensics
cugu.github.io/awesome-forensics/
5.1k757
clong/DetectionLab

Automate the creation of a lab environment complete with security tooling and logging best practices

HTMLMIT Licensevagrantvagrantfile
5k1k
intelowlproject/IntelOwl

IntelOwl: manage your Threat Intelligence at scale

PythonPyPIGNU Affero General Public License v3.0security-toolspython
intelowlproject.github.io
4.6k650
OTRF/ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

PythonPyPIMIT Licensethreat-huntingsysmon
4.6k855
TheHive-Project/TheHive

TheHive is a Collaborative Case Management Platform, now distributed as a commercial version

ScalaGNU Affero General Public License v3.0mispsecurity-incidents
strangebee.com
3.9k693
Neo23x0/Loki

Loki - Simple IOC and YARA Scanner

PythonPyPIGNU General Public License v3.0pythonyara
nextron-systems.com/compare-our-scanners/
3.8k615
WithSecureLabs/chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Rustcrates.ioGNU General Public License v3.0attackrust
3.6k300
google/timesketch

Collaborative forensic timeline analysis

PythonPyPIApache License 2.0forensicsdfir
3.4k658