Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool created by the Yamato Security group in Japan. It is written in Rust, supports multi-threading for speed, and offers Sigma-compatible detection rules in YML format for easy customization and extensibility. It can be used for live analysis on single systems, offline analysis on multiple systems, or enterprise-wide threat hunting with Velociraptor, providing a consolidated CSV timeline output for analysis in various tools like LibreOffice, Timeline Explorer, Elastic Stack, and Timesketch.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A digital investigation platform for parsing, searching, and visualizing evidences with advanced analytics capabilities.
A comprehensive guide to incident response and computer forensics, covering the entire lifecycle of incident response and remediation.
A command-line tool for searching and extracting strings from files with various options like ASCII and Unicode string search.
MalConfScan is a Volatility plugin for extracting configuration data of known malware and analyzing memory images.
A high-performance digital forensics exploitation tool for extracting structured information from various inputs without parsing file system structures.
A software utility with forensic tools for smartphones, offering powerful data extraction and decoding capabilities.
A tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container, aiding in digital forensic triage.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.