← All cheat sheets

CHAINSAW

Plain-text reference · 2 KB. Read it, search it (Ctrl-F) or print it.

Windows event log analysis tool for DFIR. Hunts through EVTX files
using Sigma rules and built-in detection logic.

INSTALLATION#

# Download binary from GitHub releases
# https://github.com/WithSecureLabs/chainsaw/releases

# Cargo (Rust)
cargo install chainsaw

BASIC USAGE#

# Hunt with Sigma rules
chainsaw hunt /path/to/evtx/ -s /path/to/sigma/rules/ --mapping mappings/sigma-event-logs-all.yml

# Hunt with built-in rules
chainsaw hunt /path/to/evtx/ --rules chainsaw/rules/

# Hunt with both
chainsaw hunt /path/to/evtx/ -s sigma-rules/ --mapping mappings/sigma-event-logs-all.yml --rules chainsaw/rules/

# Search for specific string
chainsaw search "mimikatz" /path/to/evtx/
chainsaw search "powershell" /path/to/evtx/

# Dump all events
chainsaw dump /path/to/evtx/

# Dump specific event ID
chainsaw dump /path/to/evtx/ --event-id 4624

OUTPUT#

chainsaw hunt /path/to/evtx/ -s sigma/ --json -o results.json
chainsaw hunt /path/to/evtx/ -s sigma/ --csv -o results.csv
chainsaw hunt /path/to/evtx/ -s sigma/ -o results.txt

# Filter by timestamp
chainsaw hunt /path/to/evtx/ -s sigma/ --from "2024-01-01T00:00:00" --to "2024-01-31T23:59:59"

TIPS#

  - Use Sigma rules for standardized detections
  - Built-in rules cover common attack patterns
  - Much faster than manual EVTX review
  - Supports lateral movement, persistence, execution detection
  - --json output for SIEM/ticketing integration
  - Combine with Hayabusa for complementary coverage
  - Filter by time range to reduce noise
  - search command finds any string across all EVTX files
  - dump command useful for specific event ID extraction
  - Regularly update Sigma rules for latest detections

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.