Skip to content
Change the repository type filter

All

    Repositories list

    • hayabusa-encoded-rules

      Public
      Encoded Hayabusa and Sigma rules to avoid anti-virus false positives and reduce files stored on target systems.
      Rust
      0910Updated Jan 10, 2026Jan 10, 2026
    • WELA

      Public
      Windows Event Log Auditor
      PowerShell
      36350Updated Jan 10, 2026Jan 10, 2026
    • Windows Event Log Audit Configuration Baselines and Guidelines. Automated monitoring of audit policy settings across different security frameworks.
      Batchfile
      2800Updated Jan 9, 2026Jan 9, 2026
    • hayabusa-rules

      Public
      Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.
      Python
      2621230Updated Dec 25, 2025Dec 25, 2025
    • takajo

      Public
      Takajō (鷹匠) is a Hayabusa results analyzer.
      Nim
      9149170Updated Dec 19, 2025Dec 19, 2025
    • hayabusa

      Public
      Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
      Rust
      2593k350Updated Dec 15, 2025Dec 15, 2025
    • A fork of the evtx Rust crate for Hayabusa
      Rust
      21241Updated Dec 13, 2025Dec 13, 2025
    • 21211Updated Dec 9, 2025Dec 9, 2025
    • suzaku

      Public
      Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.
      Rust
      816230Updated Dec 7, 2025Dec 7, 2025
    • 22000Updated Nov 19, 2025Nov 19, 2025
    • Sample evtx files to use for testing hayabusa detection rules
      56400Updated Nov 5, 2025Nov 5, 2025
    • IT-Yokai

      Public
      Collection of IT Yōkai (妖怪) (traditional Japanese supernatural beings)
      1700Updated Oct 31, 2025Oct 31, 2025
    • Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.
      Python
      01640Updated Oct 22, 2025Oct 22, 2025
    • This repository generates rules to be used with WELA for auditing Windows event log audit settings.
      Rust
      0500Updated Oct 9, 2025Oct 9, 2025
    • Documentation and scripts to properly enable Windows event logs.
      Batchfile
      5865130Updated Oct 3, 2025Oct 3, 2025
    • Sample cloud logs to test with Suzaku.
      2400Updated Sep 29, 2025Sep 29, 2025
    • A fork of the Rust library for parsing and evaluating Sigma rules
      Rust
      7110Updated Jul 28, 2025Jul 28, 2025
    • .github

      Public
      0100Updated Apr 21, 2025Apr 21, 2025
    • WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
      PowerShell
      8278190Updated Feb 3, 2023Feb 3, 2023
    • RustyBlue

      Public archive
      RustyBlue is a rust implementation of DeepblueCLI, a forensics log analyzer for finding evidence of compromise from windows event logs.
      Rust
      67200Updated Oct 13, 2022Oct 13, 2022