CHAINSAW
Windows event log analysis tool for DFIR. Hunts through EVTX files using Sigma rules and built-in detection logic.
INSTALLATION#
# Download binary from GitHub releases # https://github.com/WithSecureLabs/chainsaw/releases # Cargo (Rust) cargo install chainsaw
BASIC USAGE#
# Hunt with Sigma rules chainsaw hunt /path/to/evtx/ -s /path/to/sigma/rules/ --mapping mappings/sigma-event-logs-all.yml # Hunt with built-in rules chainsaw hunt /path/to/evtx/ --rules chainsaw/rules/ # Hunt with both chainsaw hunt /path/to/evtx/ -s sigma-rules/ --mapping mappings/sigma-event-logs-all.yml --rules chainsaw/rules/ # Search for specific string chainsaw search "mimikatz" /path/to/evtx/ chainsaw search "powershell" /path/to/evtx/ # Dump all events chainsaw dump /path/to/evtx/ # Dump specific event ID chainsaw dump /path/to/evtx/ --event-id 4624
OUTPUT#
chainsaw hunt /path/to/evtx/ -s sigma/ --json -o results.json chainsaw hunt /path/to/evtx/ -s sigma/ --csv -o results.csv chainsaw hunt /path/to/evtx/ -s sigma/ -o results.txt # Filter by timestamp chainsaw hunt /path/to/evtx/ -s sigma/ --from "2024-01-01T00:00:00" --to "2024-01-31T23:59:59"
TIPS#
- Use Sigma rules for standardized detections - Built-in rules cover common attack patterns - Much faster than manual EVTX review - Supports lateral movement, persistence, execution detection - --json output for SIEM/ticketing integration - Combine with Hayabusa for complementary coverage - Filter by time range to reduce noise - search command finds any string across all EVTX files - dump command useful for specific event ID extraction - Regularly update Sigma rules for latest detections
CHAINSAW CHEATSHEET ==================== Source: https://cheatsheet.johlem.net Windows event log analysis tool for DFIR. Hunts through EVTX files using Sigma rules and built-in detection logic. INSTALLATION ------------- # Download binary from GitHub releases # https://github.com/WithSecureLabs/chainsaw/releases # Cargo (Rust) cargo install chainsaw BASIC USAGE ------------ # Hunt with Sigma rules chainsaw hunt /path/to/evtx/ -s /path/to/sigma/rules/ --mapping mappings/sigma-event-logs-all.yml # Hunt with built-in rules chainsaw hunt /path/to/evtx/ --rules chainsaw/rules/ # Hunt with both chainsaw hunt /path/to/evtx/ -s sigma-rules/ --mapping mappings/sigma-event-logs-all.yml --rules chainsaw/rules/ # Search for specific string chainsaw search "mimikatz" /path/to/evtx/ chainsaw search "powershell" /path/to/evtx/ # Dump all events chainsaw dump /path/to/evtx/ # Dump specific event ID chainsaw dump /path/to/evtx/ --event-id 4624 OUTPUT ------- chainsaw hunt /path/to/evtx/ -s sigma/ --json -o results.json chainsaw hunt /path/to/evtx/ -s sigma/ --csv -o results.csv chainsaw hunt /path/to/evtx/ -s sigma/ -o results.txt # Filter by timestamp chainsaw hunt /path/to/evtx/ -s sigma/ --from "2024-01-01T00:00:00" --to "2024-01-31T23:59:59" TIPS ----- - Use Sigma rules for standardized detections - Built-in rules cover common attack patterns - Much faster than manual EVTX review - Supports lateral movement, persistence, execution detection - --json output for SIEM/ticketing integration - Combine with Hayabusa for complementary coverage - Filter by time range to reduce noise - search command finds any string across all EVTX files - dump command useful for specific event ID extraction - Regularly update Sigma rules for latest detections
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.