Yamato-Security/hayabusa

Rust
macOSWindows

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

dfirthreathuntingwindowseventlogsrustsigmadetectionattackforensicsincident
스타 성장
스타
3.3k
포크
293
주간 성장
+7
이슈
18
1k2k3k
2021년 12월2023년 7월2025년 2월2026년 9월
아티팩트crates.io
README

Hayabusa Logo

Windows event log fast forensics timeline generator and threat hunting tool.
Written in memory-safe Rust by Yamato Security — the only open-source tool with full Sigma support, including v2 correlation rules.

📖 Read the Documentation →

Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية

🦅 About

Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool. It is multi-threaded for speed and consolidates events from a single host or thousands of systems into one CSV / JSON / JSONL timeline — ready for analysis in LibreOffice, Timeline Explorer, Elastic Stack, Timesketch and more. It can run live on a single system, gather logs for offline analysis, or hunt across the enterprise with Velociraptor.

📖 Documentation

All documentation now lives on a dedicated, searchable, multi-language site:

👉 yamato-security.github.io/hayabusa

Section
🚀 Getting Started Download, install and run Hayabusa
⌨️ Command Reference Every command and option, with examples
📊 Timeline Output Output profiles, fields and abbreviations
🧩 Rules Detection rules and Sigma compatibility
🔎 Importing & Analysis Elastic Stack, Timesketch, Timeline Explorer, jq

⬇️ Download

Grab the latest signed binaries from the Releases page, or see Getting Started for live-response packages and building from source.

🗂️ Looking for the old README?

The previous single-page README is preserved unchanged:

🤝 Contributing & License

Contributions and bug reports are very welcome — see Contributing & Support. Hayabusa is released under the GNU AGPLv3 license; detection rules are released under the Detection Rule License (DRL) 1.1.


Made with 🦅 by Yamato Security  ·  @SecurityYamato
관련 저장소
toniblyx/my-arsenal-of-aws-security-tools

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

ShellawesomeApache License 2.0cloudauditing
9.5k1.6k
meirwah/awesome-incident-response

A curated list of tools for incident response

awesomeApache License 2.0incident-responsesecurity
9.4k1.7k
LOLBAS-Project/LOLBAS

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

XSLTawesomeGNU General Public License v3.0lolbinslolscripts
lolbas-project.github.io
8.8k1.2k
zeek/zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

C++Otherbronetwork-monitoring
zeek.org
7.9k1.4k
cugu/awesome-forensics

⭐️ A curated list of awesome forensic analysis tools and resources

awesomeCreative Commons Zero v1.0 Universalcomputer-forensicsdigital-forensics
cugu.github.io/awesome-forensics/
5.2k771
clong/DetectionLab

Automate the creation of a lab environment complete with security tooling and logging best practices

HTMLMIT Licensevagrantvagrantfile
5k1k
intelowlproject/IntelOwl

IntelOwl: manage your Threat Intelligence at scale

PythonPyPIGNU Affero General Public License v3.0security-toolspython
intelowlproject.github.io
4.7k670
OTRF/ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

PythonPyPIMIT Licensethreat-huntingsysmon
4.7k864
TheHive-Project/TheHive

TheHive is a Collaborative Case Management Platform, now distributed as a commercial version

ScalaGNU Affero General Public License v3.0mispsecurity-incidents
strangebee.com
3.9k694
Neo23x0/Loki

Loki - Simple IOC and YARA Scanner

PythonPyPIcliGNU General Public License v3.0pythonyara
nextron-systems.com/compare-our-scanners/
3.8k615
WithSecureLabs/chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Rustcrates.iocliGNU General Public License v3.0attackrust
3.7k305
google/timesketch

Collaborative forensic timeline analysis

PythonPyPIApache License 2.0forensicsdfir
3.4k663