Ross ROSS = Recommend OSS · open-source software intelligence for agents

WithSecureLabs/chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts observed · 2026-08-28

github.com/WithSecureLabs/chainsaw · Rust · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

99/100

  • Activity 99
  • Release rhythm 99
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 11
  • age_days: 1846
  • days_rel: 8
  • days_push: 8
  • n_releases_24m: 18

Full methodology

Adoption not part of the score

3648 stars · 303 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Chainsaw is a Rust-based CLI tool for rapidly searching and hunting through Windows forensic artefacts such as Event Logs, MFT, and registry hives. It supports Sigma detection rules and custom detection logic to identify threats during incident response.

Use cases

  • hunt for threats in Windows event logs using Sigma rules
  • search forensic artefacts for keywords and regex patterns
  • build execution timelines from Shimcache and Amcache
  • analyse SRUM database usage data
  • dump raw content of MFT and registry hives
  • first-response triage during incident response

When to choose

  • you need fast offline analysis of Windows event logs and forensic artefacts
  • you want Sigma rule support in a lightweight CLI without a SIEM
  • you're doing DFIR first-response on an endpoint without EDR coverage

When to avoid

  • you need continuous real-time endpoint monitoring or EDR capabilities
  • you require centralized log aggregation across a fleet of machines
  • you need non-Windows forensic artefact support

Facets

cli-tool · maturity active

search-engine security parser cli security developer-tools windows cli rust dfir threat-hunting forensics sigma-rules event-logs incident-response blueteam mft shimcache srum command-line linux macos

1 source

Member repositories

RepositoryRoleHealth v2
WithSecureLabs/chainsawmain99

For agents

markdown · JSON · MCP: product_card(name="WithSecureLabs/chainsaw")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem