Skip to content
Change the repository type filter

All

    Repositories list

    • hayabusa

      Public
      Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
      Rust
      2532.9k361Updated Nov 2, 2025Nov 2, 2025
    • hayabusa-rules

      Public
      Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.
      Python
      2620830Updated Nov 2, 2025Nov 2, 2025
    • hayabusa-encoded-rules

      Public
      Encoded Hayabusa and Sigma rules to avoid anti-virus false positives and reduce files stored on target systems.
      Rust
      01010Updated Nov 2, 2025Nov 2, 2025
    • WELA

      Public
      Windows Event Log Auditor
      PowerShell
      25061Updated Nov 2, 2025Nov 2, 2025
    • takajo

      Public
      Takajō (鷹匠) is a Hayabusa results analyzer.
      Nim
      9146150Updated Oct 31, 2025Oct 31, 2025
    • IT-Yokai

      Public
      Collection of IT Yōkai (妖怪) (traditional Japanese supernatural beings)
      1500Updated Oct 31, 2025Oct 31, 2025
    • Windows Event Log Audit Configuration Baselines and Guidelines. Automated monitoring of audit policy settings across different security frameworks.
      Batchfile
      2600Updated Oct 30, 2025Oct 30, 2025
    • suzaku-rules

      Public
      21110Updated Oct 29, 2025Oct 29, 2025
    • hayabusa-evtx

      Public
      A fork of the evtx Rust crate for Hayabusa
      Rust
      2940Updated Oct 27, 2025Oct 27, 2025
    • suzaku

      Public
      Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.
      Rust
      815250Updated Oct 24, 2025Oct 24, 2025
    • Documentation and tools to curate Sigma rules for Windows event logs into easier to parse rules.
      Python
      01640Updated Oct 22, 2025Oct 22, 2025
    • WELA-RulesGenerator

      Public
      This repository generates rules to be used with WELA for auditing Windows event log audit settings.
      Rust
      0500Updated Oct 9, 2025Oct 9, 2025
    • EnableWindowsLogSettings

      Public
      Documentation and scripts to properly enable Windows event logs.
      Batchfile
      5763930Updated Oct 3, 2025Oct 3, 2025
    • suzaku-sample-data

      Public
      Sample cloud logs to test with Suzaku.
      1400Updated Sep 29, 2025Sep 29, 2025
    • sigma-rust

      Public
      A fork of the Rust library for parsing and evaluating Sigma rules
      Rust
      4110Updated Jul 28, 2025Jul 28, 2025
    • .github

      Public
      0100Updated Apr 21, 2025Apr 21, 2025
    • Presentations

      Public
      21900Updated Apr 2, 2025Apr 2, 2025
    • hayabusa-sample-evtx

      Public
      Sample evtx files to use for testing hayabusa detection rules
      36101Updated Nov 4, 2024Nov 4, 2024
    • WELA-deprecated

      Public
      WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
      PowerShell
      8277790Updated Feb 3, 2023Feb 3, 2023
    • RustyBlue

      Public archive
      RustyBlue is a rust implementation of DeepblueCLI, a forensics log analyzer for finding evidence of compromise from windows event logs.
      Rust
      67200Updated Oct 13, 2022Oct 13, 2022