← All cheat sheets

HAYABUSA

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Fast Windows event log forensics tool by Yamato Security. Threat
hunting and timeline generation from EVTX files using Sigma rules.

INSTALLATION#

# Download from GitHub releases
# https://github.com/Yamato-Security/hayabusa/releases

# Extract and run (standalone binary)
./hayabusa                                  # Linux/macOS
hayabusa.exe                                # Windows

BASIC COMMANDS#

# CSV timeline (most common)
hayabusa csv-timeline -d /path/to/evtx/ -o timeline.csv

# JSON timeline
hayabusa json-timeline -d /path/to/evtx/ -o timeline.jsonl

# Logon summary
hayabusa logon-summary -d /path/to/evtx/ -o logons.csv

# Pivot keywords (extract useful IOCs)
hayabusa pivot-keywords-list -d /path/to/evtx/ -o pivots.txt

# Search
hayabusa search -d /path/to/evtx/ -k "mimikatz"

# Metrics (event ID statistics)
hayabusa metrics -d /path/to/evtx/

# Computer metrics
hayabusa computer-metrics -d /path/to/evtx/

# EID metrics (event ID frequency)
hayabusa eid-metrics -d /path/to/evtx/

# Update rules
hayabusa update-rules

FILTERING#

# By minimum severity
hayabusa csv-timeline -d evtx/ -o out.csv --min-level medium
# Levels: informational, low, medium, high, critical

# By time range
hayabusa csv-timeline -d evtx/ -o out.csv --timeline-start "2024-01-01 00:00:00" --timeline-end "2024-01-31 23:59:59"

# By computer name
hayabusa csv-timeline -d evtx/ -o out.csv --include-computer DC01

# Exclude noisy rules
hayabusa csv-timeline -d evtx/ -o out.csv --exclude-status deprecated,unsupported

# By event ID
hayabusa csv-timeline -d evtx/ -o out.csv --include-eid 4624,4625,4688

OUTPUT OPTIONS#

# Profiles (column selection)
hayabusa csv-timeline -d evtx/ -o out.csv -p timesketch    # Timesketch format
hayabusa csv-timeline -d evtx/ -o out.csv -p verbose       # All fields
hayabusa csv-timeline -d evtx/ -o out.csv -p super-verbose # Everything

# UTC timestamps
hayabusa csv-timeline -d evtx/ -o out.csv -U

# GeoIP enrichment
hayabusa csv-timeline -d evtx/ -o out.csv --geo-ip /path/to/GeoLite2-City.mmdb

TIPS#

  - csv-timeline is the primary workflow command
  - Use --min-level high for quick triage
  - logon-summary gives immediate user activity overview
  - pivot-keywords-list extracts IOCs for further investigation
  - Timesketch profile exports directly to Timesketch
  - Update rules regularly for latest detections
  - Faster than Chainsaw for large EVTX datasets
  - Combine with Chainsaw for comprehensive coverage
  - GeoIP enrichment adds location context to logins
  - Works on both live systems and offline EVTX collections