{"adoption": {"forks": 291, "observed_at": "2026-08-28T04:07:56.361275+00:00", "stars": 3324}, "canonical_url": "https://ross.abutalabs.com/products/hayabusa", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.", "domain": ["security", "windows"], "enriched": true, "function": ["security", "search-engine", "developer-tools"], "health_score": 99, "homepage": null, "language": "Rust", "license": "AGPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["Yamato-Security/hayabusa"], "name": "Yamato-Security/hayabusa", "platform": ["windows", "cli", "rust"], "pushed_at": "2026-08-22T11:21:17+00:00", "repo": "Yamato-Security/hayabusa", "stars": 3324, "tags": ["sigma-rules", "dfir", "incident-response", "event-log-analysis", "timeline-generation", "detection-rules", "mitre-attack", "threat-hunting", "forensics", "linux", "macos"], "topics": ["dfir", "threat", "hunting", "windows", "event", "logs", "rust", "sigma", "detection", "attack", "forensics", "incident", "response", "hayabusa", "yamato", "security", "cybersecurity", "incident-response", "security-automation", "threat-hunting"], "urls": [], "use_cases": ["generate a forensics timeline from Windows event logs", "hunt for threats in Windows security event logs", "run Sigma detection rules against evtx files", "analyze Windows event logs during incident response", "detect lateral movement and suspicious logon activity", "quickly triage a compromised Windows endpoint", "convert Windows event logs into a readable attack timeline"], "what_it_is": "Hayabusa is a fast, Rust-based Windows event log analysis tool that generates forensic timelines and performs threat hunting using Sigma detection rules, including full support for Sigma v2 correlation rules. It is developed by Yamato Security and widely used in DFIR and incident response workflows.", "when_to_avoid": ["you need real-time continuous monitoring or alerting from a central SIEM", "you need to analyze non-Windows log sources", "you require a GUI-driven investigation platform"], "when_to_choose": ["you need fast, local analysis of Windows event logs without a SIEM", "you want full Sigma rule support including correlation rules", "you are performing DFIR triage and need a timeline quickly", "you want a memory-safe, cross-platform CLI written in Rust"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/hayabusa", "repo": "Yamato-Security/hayabusa", "role": "main", "score": 94}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:07:56.361275+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-29T18:41:48.165864+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "740db0a900042b19a29bad7ed3cb2eaae54c8862cf3428aa7dce60dfa7611e6a", "fetched_at": "2026-08-28T04:07:56.361275+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Yamato-Security/hayabusa"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 99, "longevity": 100, "rhythm": 84}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2175, "days_push": 11, "days_rel": 30, "gap_med": 36.5, "n_releases_24m": 17}, "score": 94, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}