awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Yamato-Security avatar

Yamato-Security/hayabusa

0
View on GitHub↗
3,027 stars·256 forks·Rust·agpl-3.0·17 views

Hayabusa

Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats.

The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations.

The tool's broader capabilities include security log enrichment via geolocation, Base64 string decoding, and the calculation of event volume metrics. It further supports threat detection through logon activity summarization, critical system identification, and keyword-based pivot analysis to correlate related security events.

Features

  • Timeline Generators - Provides a specialized utility to extract event log data into chronological records for digital forensics and incident response.
  • Windows Event Log Analyzers - Searches and analyzes Windows event logs to find security threats or evidence of malicious activity.
  • Forensic Event Correlation - Parses event logs into a chronological sequence of activities to reconstruct a timeline of security events.
  • Rule-Based Detection Engines - Functions as a detection engine that applies threat patterns to logs and synchronizes rules from remote repositories.
  • Log Event Signatures - Matches event log entries against a curated library of patterns to identify suspicious behavior and security threats.
  • Incident Investigation Tools - Analyzes suspicious data and correlates event metrics to understand the scope of a security breach.
  • Threat Detection - Uses predefined rules to identify suspicious behavior and tunes alerts to minimize false positives.
  • Threat Hunting Workflows - Analyzes Windows event logs to proactively detect security threats and suspicious behavior using a rule-based library.
  • Digital Forensics - Creates chronological records of system events to reconstruct the sequence of an attack for digital forensics.
  • Remote Configuration Synchronization - Synchronizes local detection rules and risk thresholds by pulling the latest configurations from a remote repository.
  • Authentication Activity Summaries - Aggregates successful and failed logon attempts by username to identify potential authentication abuse.
  • Detection Sensitivity Tuning - Allows adjusting risk levels within configurations to reduce false positives and prioritize critical security alerts.
  • Remote Rule Synchronization - Updates local detection rules and configuration files from a remote repository to keep threat patterns current.
  • Critical Asset Identification - Detects domain controllers and file servers to increase alert priority for events originating from those hosts.
  • Log Event Enrichment - Adds geographical context and system roles to IP addresses and hostnames within event logs.
  • IP Geolocation Enrichment - Enriches network log entries by mapping IP addresses to physical locations using external geolocation databases.
  • Log Analysis Tools - Generates forensic timelines from Windows event logs.
  • Windows Artifact Analysis - Sigma-based threat hunting and timeline generation for event logs.
  • Forensics and Incident Response - Threat hunting and timeline generator for Windows logs.
  • Digital Forensics - Fast Windows event log analysis tool for threat hunting.

Star history

Star history chart for yamato-security/hayabusaStar history chart for yamato-security/hayabusa

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Hayabusa

Similar open-source projects, ranked by how many features they share with Hayabusa.
  • jpcertcc/logontracerJPCERTCC avatar

    JPCERTCC/LogonTracer

    3,136View on GitHub↗

    LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to

    Pythonactive-directoryblueteamdfir
    View on GitHub↗3,136
  • withsecurelabs/chainsawWithSecureLabs avatar

    WithSecureLabs/chainsaw

    3,446View on GitHub↗

    Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa

    Rustattackblueteamchainsaw
    View on GitHub↗3,446
  • falcosecurity/falcofalcosecurity avatar

    falcosecurity/falco

    8,670View on GitHub↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    View on GitHub↗8,670
  • ahmedkhlief/apt-hunterahmedkhlief avatar

    ahmedkhlief/APT-Hunter

    1,408View on GitHub↗

    APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

    Python
    View on GitHub↗1,408
See all 30 alternatives to Hayabusa→

Frequently asked questions

What does yamato-security/hayabusa do?

Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats.

What are the main features of yamato-security/hayabusa?

The main features of yamato-security/hayabusa are: Timeline Generators, Windows Event Log Analyzers, Forensic Event Correlation, Rule-Based Detection Engines, Log Event Signatures, Incident Investigation Tools, Threat Detection, Threat Hunting Workflows.

What are some open-source alternatives to yamato-security/hayabusa?

Open-source alternatives to yamato-security/hayabusa include: jpcertcc/logontracer — LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a… withsecurelabs/chainsaw — Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It… falcosecurity/falco — Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and… wagga40/zircolite. ahmedkhlief/apt-hunter — APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT… yamato-security/wela — WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a…