This source did not publish a separate summary. Review SKILL.md before using the skill.
SKILL.md
Generating Forensic Timelines with Hayabusa
Overview
Hayabusa (隼, Japanese for "peregrine falcon") is a Sigma-based threat-hunting and fast-forensics timeline generator for Windows event logs, developed by Yamato Security in Rust. It parses .evtx files (offline or via live analysis of a local host), applies a large built-in library of Sigma detection rules plus Hayabusa-specific rules, and produces a single, readable, chronological timeline of high-signal events with severity levels, MITRE ATT&CK tactics, and rule references. This collapses thousands of raw event-log records into a prioritized incident timeline that an analyst can review quickly.
Hayabusa is purpose-built for DFIR triage. Instead of loading EVTX into a SIEM, an investigator runs a single binary against a directory of collected logs and gets a CSV or JSON timeline plus metrics (events per computer, per Event ID, per channel). Because detections are Sigma-based, coverage tracks the open detection-engineering community, and rules can be updated on demand with update-rules. The tool's output integrates with downstream analysis: CSV opens in Timeline Explorer, JSONL feeds into jq, and timesketch-* profiles export directly into Timesketch.
A frequent finding in Hayabusa timelines is malicious PowerShell — MITRE ATT&CK T1059.001 (Command and Scripting Interpreter: PowerShell) — surfaced via Sigma rules over Event ID 4104 (script-block logging), 4103, and Sysmon process creation. This skill maps to NIST CSF RS.AN-03 (analysis is performed to establish what has taken place during an incident).
When to Use
During incident-response triage, to turn a pile of collected .evtx files into a prioritized timeline.
When you need fast, SIEM-free detection over Windows event logs with community Sigma coverage.
To enumerate suspicious activity (PowerShell, account changes, lateral movement) across many hosts' logs.
To produce metrics (events per computer/Event ID/channel) and pivot keywords for deeper hunting.
To export an incident timeline into Timesketch or Timeline Explorer for collaborative analysis.
Prerequisites
Hayabusa binary. Download a pre-compiled release (Windows/Linux/macOS) from GitHub:
# Linux example
curl -LO https://github.com/Yamato-Security/hayabusa/releases/latest/download/hayabusa-3.0.0-lin-x64-gnu.zip
unzip hayabusa-*.zip && cd hayabusa-*
./hayabusa-3.0.0-lin-x64-gnu --version
Or build from source (rules are a submodule):
git clone https://github.com/Yamato-Security/hayabusa.git --recursive
cd hayabusa && cargo build --release
Collected Windows .evtx files (or run with --live-analysis on the host, as Administrator).
Updated detection rules:
./hayabusa update-rules
Optional: Timeline Explorer (Windows) or Timesketch for visualizing output; jq for JSONL.
Objectives
Build a CSV or JSON forensic timeline from a directory of .evtx files.
Update and tune the Sigma rule set used for detection.
Select an output profile appropriate to the investigation (minimal vs. verbose vs. timesketch).
Generate metrics (computer, Event ID, log) and pivot keywords for hunting leads.
Filter the timeline by minimum severity to focus triage.
Search logs for specific IOCs by keyword or regex.
MITRE ATT&CK Mapping
Technique ID
Official Name
Why Hayabusa Detects It
T1059.001
Command and Scripting Interpreter: PowerShell
Sigma rules over Event IDs 4104/4103 and Sysmon flag malicious PowerShell
T1059.003
Command and Scripting Interpreter: Windows Command Shell
Rules over process-creation events surface suspicious cmd usage
Profiles control detail. Use verbose to include MITRE ATT&CK tactics, tags, and the source rule/EVTX file; all-field-info to retain every original field.