
Hayabusa
Hayabusa is a free open-source Windows event log tool used to build fast forensics timelines and hunt for attacker activity for incident responders.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 7 October 2026
What it is
A multi-threaded Rust command-line program that reads .evtx files from one host or thousands and writes every detection to one CSV, JSON, or JSONL file. It supports the Sigma rule format, including correlation rules, and comes with more than 4,000 curated rules that a built-in command keeps current.
What it helps with
- Grading each alert from informational up to critical
- Summarizing logons, event IDs, and computers to spot outliers
- Recovering event records left in slack space inside .evtx files
Who it's for
Incident responders, forensic analysts, and threat hunters examining Windows event logs from systems they own or are authorized to investigate.
Worth knowing
A scan wizard offers rule sets from a low-noise core up to experimental and threat hunting rules. Some antivirus products flag the plain rule files, so Windows live-response packages carry them encoded in one file.
Can it scan a running machine?
Yes, with Administrator rights it reads the local Windows log folder, and it also accepts logs exported as JSON.
Does it need a Windows workstation?
No, prebuilt binaries cover Windows, Linux, and macOS on Intel and ARM.
Do the rules share the program's license?
No, the program is AGPL-3.0, while the detection rules use the Detection Rule License 1.1.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.