# Yamato-Security/hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Repository: https://github.com/Yamato-Security/hayabusa
Canonical: https://ross.abutalabs.com/products/hayabusa
Language: Rust
License: AGPL-3.0
License Family: copyleft
Topics: dfir, threat, hunting, windows, event, logs, rust, sigma, detection, attack, forensics, incident, response, hayabusa, yamato, security, cybersecurity, incident-response, security-automation, threat-hunting
Last push: 2026-08-22T11:21:17+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 84, longevity 100
- inputs: {"age_days": 2175, "days_push": 11, "days_rel": 30, "gap_med": 36.5, "n_releases_24m": 17}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3324, forks 291 (observed 2026-08-28T04:07:56.361275+00:00)

## What it is
Hayabusa is a fast, Rust-based Windows event log analysis tool that generates forensic timelines and performs threat hunting using Sigma detection rules, including full support for Sigma v2 correlation rules. It is developed by Yamato Security and widely used in DFIR and incident response workflows.

## Use cases
- generate a forensics timeline from Windows event logs
- hunt for threats in Windows security event logs
- run Sigma detection rules against evtx files
- analyze Windows event logs during incident response
- detect lateral movement and suspicious logon activity
- quickly triage a compromised Windows endpoint
- convert Windows event logs into a readable attack timeline

## When to choose
- you need fast, local analysis of Windows event logs without a SIEM
- you want full Sigma rule support including correlation rules
- you are performing DFIR triage and need a timeline quickly
- you want a memory-safe, cross-platform CLI written in Rust

## When to avoid
- you need real-time continuous monitoring or alerting from a central SIEM
- you need to analyze non-Windows log sources
- you require a GUI-driven investigation platform

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, search-engine, developer-tools
- domain: security, windows
- platform: windows, cli, rust
- tags: sigma-rules, dfir, incident-response, event-log-analysis, timeline-generation, detection-rules, mitre-attack, threat-hunting, forensics, linux, macos

## Member repositories
- Yamato-Security/hayabusa (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:56.361275+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:41:48.165864+00:00, confidence not recorded.
  - readme: https://github.com/Yamato-Security/hayabusa (fetched 2026-08-28T04:07:56.361275+00:00, sha 740db0a90004)
- Data as of 2026-08-30T08:39:29.467469+00:00.
