Skip to main content

Overview

Hayabusa is a fast forensics timeline generator and threat hunting tool specifically designed for Windows event logs. Written in memory-safe Rust, it leverages multi-threading for maximum speed and is the only open-source tool offering complete support for the Sigma specification, including correlation rules. It can parse Sigma rules, with a curated set available in the hayabusa-rules repository, and can be used for live analysis, offline investigations, or enterprise-wide threat hunting with tools like Velociraptor. The comprehensive output can be easily analyzed in various forensic tools.

User Feedback


Rate the Costs fields
12345
12345
12345
12345
12345
12345
12345