Skip to content

Hayabusa

SIEM & Threat Detection

Windows event log fast forensics timeline generator and threat hunting tool written in Rust

Rust Latest v3.10.0 · 22d ago Security brief →

Features

  • Generates CSV / JSON / JSONL timelines from Windows event logs
  • Multi‑threaded for fast processing of single hosts or thousands of systems
  • Full Sigma rule support (including v2 correlation rules)
  • Works live on a host, offline, or with Velociraptor for enterprise hunting

Recent releases

View all 4 releases →
Review required
v3.10.0 Breaking risk
Auth

|neq support + ATT&CK counts + Markdown fix

v3.9.0 New feature
Notable features
  • Support for MITRE ATT&CK v19
Full changelog

Anti-Virus False Positives

Warning: You will get false positives from certain anti-virus programs like Windows Defender and Web Browsers saying they have detected malicious files. They are detecting on Sigma .yml files that are not executable and just contain certain signatures from malware. They are not malicious. If you are running Hayabusa for live analysis and do not want to cause any anti-virus alerts, be sure to use the live response packages that use encoded Sigma rules.

3.9.0 [2026/04/29] - Showa Day Release

Enchancements:

Support for MITRE ATT&CK v19. (@fukusuket)

Other:

Added unit tests. (#1746) (@Fuzzdkk)

改善:

MITRE ATT&CK v19に対応した。(@fukusuket)

その他:

ユニットテストの追加。 (#1746) (@Fuzzdkk)

v3.8.1 Bug fix

Log analysis tool fixes issue with multiple progress bars displaying incorrectly during event log processing.

v3.8.0 Security relevant
Security fixes
  • XSS vulnerability in HTML report generation when scanning JSON logs

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
3,257
Forks
280
Languages
Rust Python CSS

Install & Platforms

Platforms
windows

Beta — feedback welcome: [email protected]