Chainsaw: Open-source tool for Windows forensic hunting

Chainsaw is an open-source first-responder tool for quickly detecting threats in Windows forensic artifacts. It can be used in event logs and the MFT file.

It enables quick keyword searches in event logs and detects threats using built-in Sigma detection rules as well as custom detection rules.

Discover more articles in search results.

Chainsaw features

  • Threat hunting using Sigma detection rules as well as custom detection rules
  • Forensic search and extraction with string matching and regex patterns
  • Build execution schedules by parsing Shimcache artifacts and enriching them with Amcache data
  • Analyze the SRUM database and get the necessary information
  • Dump of forensic raw content (MFT, registry hives, ESE databases)
  • Fast, written in rust, contains the EVTX parser library
  • Clean and lightweight execution and output formats without unnecessary bloat
  • Document tagging provided by the TAU Engine Library
  • Output results in a variety of formats including ASCII table format, CSV format and JSON format

Chainsaw is available free on GitHub. It can run on Linux, macOS and Windows.


Google preferences

Leave a Comment

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).