Turn Windows event logs into Sigma-backed threat-hunting timelines with Hayabusa
Parse Windows event logs into fast timelines and detection-rich outputs so agents can triage suspicious host activity, search for known patterns, and hand investigators reviewable artifacts.
Prerequisites
Hayabusa plus Windows event logs from a live system, offline collection, or enterprise collection pipeline.
Installation
Choose whichever fits your setup:
- Copy this skill folder into your local skills directory.
- Clone the repo and symlink or copy the skill into your agent workspace.
- Add the repo as a git submodule if you manage shared skills centrally.
- Install it through your internal provisioning or packaging workflow.
- Download the folder directly from GitHub and place it in your skills collection.
Install command or upstream instructions:
Download a Hayabusa release or build from source, then run its timeline and analysis commands against Windows EVTX files or collected event log directories.