HAYABUSA
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Fast Windows event log forensics tool by Yamato Security. Threat hunting and timeline generation from EVTX files using Sigma rules.
INSTALLATION#
# Download from GitHub releases # https://github.com/Yamato-Security/hayabusa/releases # Extract and run (standalone binary) ./hayabusa # Linux/macOS hayabusa.exe # Windows
BASIC COMMANDS#
# CSV timeline (most common) hayabusa csv-timeline -d /path/to/evtx/ -o timeline.csv # JSON timeline hayabusa json-timeline -d /path/to/evtx/ -o timeline.jsonl # Logon summary hayabusa logon-summary -d /path/to/evtx/ -o logons.csv # Pivot keywords (extract useful IOCs) hayabusa pivot-keywords-list -d /path/to/evtx/ -o pivots.txt # Search hayabusa search -d /path/to/evtx/ -k "mimikatz" # Metrics (event ID statistics) hayabusa metrics -d /path/to/evtx/ # Computer metrics hayabusa computer-metrics -d /path/to/evtx/ # EID metrics (event ID frequency) hayabusa eid-metrics -d /path/to/evtx/ # Update rules hayabusa update-rules
FILTERING#
# By minimum severity hayabusa csv-timeline -d evtx/ -o out.csv --min-level medium # Levels: informational, low, medium, high, critical # By time range hayabusa csv-timeline -d evtx/ -o out.csv --timeline-start "2024-01-01 00:00:00" --timeline-end "2024-01-31 23:59:59" # By computer name hayabusa csv-timeline -d evtx/ -o out.csv --include-computer DC01 # Exclude noisy rules hayabusa csv-timeline -d evtx/ -o out.csv --exclude-status deprecated,unsupported # By event ID hayabusa csv-timeline -d evtx/ -o out.csv --include-eid 4624,4625,4688
OUTPUT OPTIONS#
# Profiles (column selection) hayabusa csv-timeline -d evtx/ -o out.csv -p timesketch # Timesketch format hayabusa csv-timeline -d evtx/ -o out.csv -p verbose # All fields hayabusa csv-timeline -d evtx/ -o out.csv -p super-verbose # Everything # UTC timestamps hayabusa csv-timeline -d evtx/ -o out.csv -U # GeoIP enrichment hayabusa csv-timeline -d evtx/ -o out.csv --geo-ip /path/to/GeoLite2-City.mmdb
TIPS#
- csv-timeline is the primary workflow command - Use --min-level high for quick triage - logon-summary gives immediate user activity overview - pivot-keywords-list extracts IOCs for further investigation - Timesketch profile exports directly to Timesketch - Update rules regularly for latest detections - Faster than Chainsaw for large EVTX datasets - Combine with Chainsaw for comprehensive coverage - GeoIP enrichment adds location context to logins - Works on both live systems and offline EVTX collections