Yamato-Security/hayabusa
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs. observed · 2026-08-28
Health v2 · maintenance only
94/100
- Activity 99
- Release rhythm 84
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 36.5
- age_days: 2175
- days_rel: 30
- days_push: 11
- n_releases_24m: 17
Adoption not part of the score
3324 stars · 291 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Hayabusa is a fast, Rust-based Windows event log analysis tool that generates forensic timelines and performs threat hunting using Sigma detection rules, including full support for Sigma v2 correlation rules. It is developed by Yamato Security and widely used in DFIR and incident response workflows.
Use cases
- generate a forensics timeline from Windows event logs
- hunt for threats in Windows security event logs
- run Sigma detection rules against evtx files
- analyze Windows event logs during incident response
- detect lateral movement and suspicious logon activity
- quickly triage a compromised Windows endpoint
- convert Windows event logs into a readable attack timeline
When to choose
- you need fast, local analysis of Windows event logs without a SIEM
- you want full Sigma rule support including correlation rules
- you are performing DFIR triage and need a timeline quickly
- you want a memory-safe, cross-platform CLI written in Rust
When to avoid
- you need real-time continuous monitoring or alerting from a central SIEM
- you need to analyze non-Windows log sources
- you require a GUI-driven investigation platform
Facets
cli-tool · maturity active
security search-engine developer-tools security windows windows cli rust sigma-rules dfir incident-response event-log-analysis timeline-generation detection-rules mitre-attack threat-hunting forensics linux macos
1 source
- readme: https://github.com/Yamato-Security/hayabusa · fetched 2026-08-28 · 740db0a90004
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Yamato-Security/hayabusa | main | 94 |
For agents
markdown · JSON · MCP: product_card(name="Yamato-Security/hayabusa")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem