{"repo":"WithSecureLabs/chainsaw","free":true,"listed":false,"github":"https://github.com/WithSecureLabs/chainsaw","clone":"git clone https://github.com/WithSecureLabs/chainsaw.git","description":"Rapidly Search and Hunt through Windows Forensic Artefacts","language":"Rust","stars":3633,"topics":["attack","rust","security","threat-hunting","blueteam","chainsaw","detection","dfir","forensics","logs"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"Rapidly Search and Hunt through Windows Forensic Artefacts --- Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows forensic artefacts such as Event Logs and the MFT file. Chainsaw offers a generic and fast method of searching through event logs for keywords, and by identifying threats using built-in support for Sigma detection rules, and via custom Chainsaw detection rules. Features - :dart: Hunt for threats using Sigma detection rules and custom Chainsaw detection rules - :mag: Search and extract forensic artefacts by string matching, and regex patterns - :date: Create execution timelines by analysing Shimcache artefacts and enriching them with Amcache data - :bulb: Analyse the SRUM database and provide insights about it - :arrow down: Dump the raw content of forensic artefacts (MFT, registry hives, ESE databases) - :zap: Lightning fast, written in rust, wrapping the EVTX parser library by @OBenamram - :feather: Clean and lightweight execution and output formats without unnecessary bloat - :fire: Document tagging (detection logic matching) provided by the TAU Engine Library - :bookmark tabs: Output results in a variety of formats, such as ASCII table format, CSV format, and JSON format - :computer: Can be run on MacOS, Linux and Windows --- Table Of Contents - Features - Why Chainsaw? - Hunting Logic for Windows Event Logs - Quick Start Guide - Downloading and Running - Install/Build with Nix - EDR and AV Warnings - What change","default_branch":null,"files":null,"tree":[],"storefront":"/r/WithSecureLabs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/WithSecureLabs/chainsaw/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}