yamato-security/hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 53 minutes ago
Added to GitGenius on September 20th, 2026
Created on September 18th, 2020
Open Issues & Pull Requests: 18 (+0)
GitHub issues: Enabled
Number of forks: 295
Total Stargazers: 3,357 (+0)
Total Subscribers: 45 (+0)

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 15
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 808 days
Stale 30+ days: 14
Stale 90+ days: 13

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • bug (85)
  • enhancement (81)
  • Priority:Low (15)
  • under-investigation (15)
  • invalid (9)
  • documentation (5)
  • pending (5)
  • Priority:Medium (1)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Hayabusa is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Hayabusa addresses the challenge of analyzing Windows event logs at scale during incident response and forensic investigations. It processes event logs using Sigma detection rules, which are open-source, community-maintained signatures for identifying suspicious activity. The tool generates forensic timelines while simultaneously hunting for threats, allowing security teams to both reconstruct what happened and detect indicators of compromise in a single pass. It is written in Rust, providing memory safety and performance characteristics suited to processing large volumes of log data.

Organizations should adopt Hayabusa if they need to perform rapid threat hunting or forensic analysis on Windows environments and want to leverage the Sigma rule ecosystem. It suits teams already invested in Sigma rules or those building detection pipelines around community-driven signatures.

The project shows consistent development activity with regular updates to the codebase. Maintenance includes ongoing refinement of core functionality and responsiveness to issues raised by users. The tool receives contributions that expand its capabilities and improve its handling of edge cases in event log processing.