
Chainsaw
Chainsaw is a free open-source first-response tool used to search and hunt through Windows event logs and other forensic artifacts for incident responders.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 10 October 2026
- Links
- GitHub
What it is
A Rust command-line program that triages exported Windows forensic files on a laptop, without needing a SIEM. It matches Sigma detection rules and its own rules against event logs, and can also search the MFT, Shimcache, Amcache, and SRUM.
What it helps with
- Running detection-rule hunts against a pile of EVTX files during incident response
- Searching logs by string or regex when you need a quick keyword pass
- Building execution timelines from Shimcache and Amcache
- Dumping raw content from the MFT, registry hives, and ESE databases
Who it's for
Incident responders and threat hunters triaging Windows forensic collections from systems they are authorized to investigate.
Worth knowing
Pick Chainsaw when you need offline triage of several artifact types, not just event logs. Hayabusa is the better pick when the job is fast rule-based hunting across EVTX alone.
Can it write results to CSV or JSON?
Yes, it can output ASCII tables, CSV, or JSON.
Do detection rules ship inside the binary?
No, you point it at a rules directory you keep up to date, though release packages with rules are also offered.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.