# Turn Windows event logs into Sigma-backed threat-hunting timelines with Hayabusa

> Parse Windows event logs into fast timelines and detection-rich outputs so agents can triage suspicious host activity, search for known patterns, and hand investigators reviewable artifacts.

- Skill: `agentskillexchange/turn-windows-event-logs-into-sigma-backed-threat-hunting-tim` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/turn-windows-event-logs-into-sigma-backed-threat-hunting-tim`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/turn-windows-event-logs-into-sigma-backed-threat-hunting-tim/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/turn-windows-event-logs-into-sigma-backed-threat-hunting-tim

---


# Turn Windows event logs into Sigma-backed threat-hunting timelines with Hayabusa

Parse Windows event logs into fast timelines and detection-rich outputs so agents can triage suspicious host activity, search for known patterns, and hand investigators reviewable artifacts.

## Prerequisites

Hayabusa plus Windows event logs from a live system, offline collection, or enterprise collection pipeline.

## Installation

No source-backed install or usage instructions could be extracted automatically. Review the upstream project before running this skill in a sensitive workflow.

- Source: https://github.com/Yamato-Security/hayabusa

## Documentation

- https://github.com/Yamato-Security/hayabusa

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/turn-windows-event-logs-into-sigma-backed-threat-hunting-timelines-with-hayabusa/)

