Chainsaw
Forensics & Incident ResponseChainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows event logs.
Features
- Hunt threats using Sigma detection rules and custom Chainsaw rules
- Search forensic artefacts with string matching and regex patterns
- Create execution timelines from Shimcache and Amcache data
- Analyse SRUM database for insights
Recent releases
View all 6 releases →
v2.16.0
New feature
Notable features
- Adds an EVTX summary command
Full changelog
This release contains the following changes of note:
- Adds an EVTX summary command (https://github.com/WithSecureLabs/chainsaw/pull/231)
- Brings in some fixes from the MFT library (https://github.com/WithSecureLabs/chainsaw/issues/211)
v2.15.0
New feature
Notable features
- Gap analysis to detect potential gaps in event logs
Full changelog
This release contains the following changes of note:
- A new type of analysis, gap analysis which will look for potential gaps in event logs, thanks to @Fuzzdkk (#228).
- Bumps dependencies.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Install & Platforms
Platforms
linux
macos
windows