# WithSecureLabs/chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Repository: https://github.com/WithSecureLabs/chainsaw
Canonical: https://ross.abutalabs.com/products/chainsaw
Language: Rust
License: GPL-3.0
License Family: copyleft
Topics: attack, rust, security, threat-hunting, blueteam, chainsaw, detection, dfir, forensics, logs, sigma, windows, countercept
Last push: 2026-08-25T19:12:42+00:00

## Health v2 (maintenance only)
Score: 99/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 99, longevity 100
- inputs: {"age_days": 1846, "days_push": 8, "days_rel": 8, "gap_med": 11, "n_releases_24m": 18}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3648, forks 303 (observed 2026-08-28T04:08:12.964214+00:00)

## What it is
Chainsaw is a Rust-based CLI tool for rapidly searching and hunting through Windows forensic artefacts such as Event Logs, MFT, and registry hives. It supports Sigma detection rules and custom detection logic to identify threats during incident response.

## Use cases
- hunt for threats in Windows event logs using Sigma rules
- search forensic artefacts for keywords and regex patterns
- build execution timelines from Shimcache and Amcache
- analyse SRUM database usage data
- dump raw content of MFT and registry hives
- first-response triage during incident response

## When to choose
- you need fast offline analysis of Windows event logs and forensic artefacts
- you want Sigma rule support in a lightweight CLI without a SIEM
- you're doing DFIR first-response on an endpoint without EDR coverage

## When to avoid
- you need continuous real-time endpoint monitoring or EDR capabilities
- you require centralized log aggregation across a fleet of machines
- you need non-Windows forensic artefact support

## Facets
- artifact type: cli-tool
- maturity: active
- function: search-engine, security, parser, cli
- domain: security, developer-tools
- platform: windows, cli, rust
- tags: dfir, threat-hunting, forensics, sigma-rules, event-logs, incident-response, blueteam, mft, shimcache, srum, command-line, linux, macos

## Member repositories
- WithSecureLabs/chainsaw (main) score 99

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:12.964214+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:31:42.459874+00:00, confidence not recorded.
  - readme: https://github.com/WithSecureLabs/chainsaw (fetched 2026-08-28T04:08:12.964214+00:00, sha ada8e755887d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
