BigHugger
sk Skill · mukul975

generating-forensic-timelines-with-hayabusa

Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK mappings, and per-host/per-Event-ID metrics. Use during DFIR triage to turn raw event logs into a fast, SIEM-free incident timeline, or to export results into Timesketch or Timeline Explorer for collaborative analysis.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashwindows-event-logsthreat-huntingtimelineevtxPythonforensicssigmadfirhayabusa
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python