Chainsaw

Operate Chainsaw — a fast Windows event log (EVTX) analysis tool with Sigma rule integration for rapid threat hunting and incident response. Use when analyzing Windows event logs for lateral movement, credential access, persistence, execution, or defense evasion artifacts. Covers installation (cargo, releases), hunt mode with Sigma rules, search mode, dump mode, supported formats (EVTX, JSON), output formats (ASCII table, CSV, JSON), writing custom detection rules, key detection categories, and incident response triage workflows.

jperezduerto 296e011 14.1 KB Updated

File contents

jperezduerto/redhound-arsenal/tree/main/chainsaw commit 296e01138b

Frequently asked questions

npx skillmds@latest add jperezduerto/chainsaw