Skip to content

Hayabusa

SIEM & Threat Detection

Windows event log fast forensics timeline generator and threat‑hunting tool written in Rust with full Sigma rule support

Rust Latest v3.9.0 · 1mo ago Security brief →

Features

  • Generates consolidated CSV/JSON timelines from Windows event logs
  • Supports live and offline analysis of single or multiple systems
  • Integrates with Velociraptor for enterprise‑wide threat hunting
  • Full support for Sigma specification (including v2 correlation rules)
  • Written in memory‑safe Rust with multi‑threading for speed

Recent releases

View all 3 releases →
v3.9.0 New feature
Notable features
  • Support for MITRE ATT&CK v19
Full changelog

Anti-Virus False Positives

Warning: You will get false positives from certain anti-virus programs like Windows Defender and Web Browsers saying they have detected malicious files. They are detecting on Sigma .yml files that are not executable and just contain certain signatures from malware. They are not malicious. If you are running Hayabusa for live analysis and do not want to cause any anti-virus alerts, be sure to use the live response packages that use encoded Sigma rules.

3.9.0 [2026/04/29] - Showa Day Release

Enchancements:

Support for MITRE ATT&CK v19. (@fukusuket)

Other:

Added unit tests. (#1746) (@Fuzzdkk)

改善:

MITRE ATT&CK v19に対応した。(@fukusuket)

その他:

ユニットテストの追加。 (#1746) (@Fuzzdkk)

v3.8.1 Bug fix

Log analysis tool fixes issue with multiple progress bars displaying incorrectly during event log processing.

v3.8.0 Security relevant
Security fixes
  • XSS vulnerability in HTML report generation when scanning JSON logs

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
3,189
Forks
272
Languages
Rust RenderScript

Install & Platforms

Platforms
windows

Community & Support

Beta — feedback welcome: [email protected]