Skip to content

Threat Hunting & Endpoint Analysis

Collect, hunt, and time-line evidence from live hosts, disk images, and memory.

Velociraptor

binary

Endpoint visibility and DFIR at scale — one static binary, client or server.

Hayabusa

binary

Fast Windows event-log hunting with built-in Sigma-based detection rules.

Chainsaw

binary

Rapid triage of Windows forensic artefacts, shipped with its Sigma-mapped ruleset.

Zircolite

venv

Runs Sigma rules directly against EVTX/JSON logs, no SIEM required.

Plaso (log2timeline)

venv

Builds a unified super-timeline from disparate forensic artefacts.

Volatility3

venv

Memory-forensics framework for analyzing RAM captures.

Sysmon config

reference

SwiftOnSecurity's battle-tested Sysmon logging configuration, ready to deploy.

Sysinternals suite

staged

Autoruns, Process Monitor, Process Explorer, TCPView — staged, not run here.