🍺 BREW Explorer

← all formulae

chainsaw

brew install chainsaw v2.16.0 GPL-3.0-only

Rapidly Search and Hunt through Windows Forensic Artefacts

37
30-day installs · #5327
144
90-day · #4784
496
365-day · #5131
3.6k
★ GitHub stars · updated 3mo ago

Build dependencies

GitHub topics

attack blueteam chainsaw countercept detection dfir forensics logs rust security sigma threat-hunting windows

Links

Raw metadata
{
  "aliases": [],
  "alternatives": [],
  "build_dependencies": [
    "rust"
  ],
  "categories": [],
  "caveats": null,
  "conflicts_with": [],
  "dependencies": [],
  "deprecated": 0,
  "deprecation_reason": null,
  "desc": "Rapidly Search and Hunt through Windows Forensic Artefacts",
  "disable_reason": null,
  "disabled": 0,
  "enrichment_fetched_at": "2026-06-20T23:36:18+00:00",
  "first_seen": "2026-06-20T23:34:18+00:00",
  "full_name": "chainsaw",
  "github_default_branch": "master",
  "github_last_commit_at": "2026-05-09T10:07:03Z",
  "github_readme_excerpt": "\n\u003cdiv align=\"center\"\u003e\n \u003cp\u003e\n  \u003ch1\u003e\n   Rapidly Search and Hunt through Windows Forensic Artefacts\n  \u003c/h1\u003e\n \u003c/p\u003e\n\u003cimg style=\"padding:0;vertical-align:bottom;\" height=\"76\" width=\"300\" src=\"images/chainsaw.png\"/\u003e\n\u003c/div\u003e\n\n---\nChainsaw provides a powerful \u2018first-response\u2019 capability to quickly identify threats within Windows forensic artefacts such as Event Logs and the MFT file. Chainsaw offers a generic and fast method of searching through event logs for keywords, and by identifying threats using built-in support for Sigma detection rules, and via custom Chainsaw detection rules.\n\n## Features\n\n - :dart: Hunt for threats using [Sigma](https://github.com/SigmaHQ/sigma) detection rules and custom Chainsaw detection rules\n - :mag: Search and extract forensic artefacts by string matching, and regex patterns\n - :date: Create execution timelines by analysing Shimcache artefacts and enriching them with Amcache data\n - :bulb: Analyse the SRUM database and provide insights about it\n - :arrow_down: Dump the raw content of forensic artefacts (MFT, registry hives, ESE databases)\n - :zap: Lightning fast, written in rust, wrapping the [EVTX parser](https://github.com/omerbenamram/evtx) library by [@OBenamram](https://twitter.com/obenamram?lang=en)\n - :feather: Clean and lightweight execution and output formats without unnecessary bloat\n - :fire: Document tagging (detection logic matching) provided by the [TAU Engine](https://github.com/WithSecureLabs/tau-engine) Library\n - :bookmark_tabs: Output results in a variety of formats, such as ASCII table format, CSV format, and JSON format\n - :computer: Can be run on MacOS, Linux and Windows\n---\n\n## Table Of Contents\n\n- [Features](#features)\n- [Why Chainsaw?](#why-chainsaw)\n- [Hunting Logic for Windows Event Logs](#hunting-logic-for-windows-event-logs)\n- [Quick Start Guide](#quick-start-guide)\n  - [Downloading and Running](#downloading-and-running)\n  - [Install/Build with Nix](#installbuild-with-nix)\n  - [EDR and AV Warnings](#edr-and-av-warn",
  "github_repo": "WithSecureLabs/chainsaw",
  "github_stars": 3568,
  "github_topics": [
    "attack",
    "blueteam",
    "chainsaw",
    "countercept",
    "detection",
    "dfir",
    "forensics",
    "logs",
    "rust",
    "security",
    "sigma",
    "threat-hunting",
    "windows"
  ],
  "homepage": "https://github.com/WithSecureLabs/chainsaw",
  "homepage_og_description": null,
  "homepage_og_image": null,
  "homepage_title": null,
  "installs_30d": 37,
  "installs_365d": 496,
  "installs_90d": 144,
  "keg_only": 0,
  "keg_only_reason": null,
  "last_seen": "2026-06-20T23:34:18+00:00",
  "license": "GPL-3.0-only",
  "llm_generated_at": null,
  "llm_model": null,
  "name": "chainsaw",
  "oldnames": [],
  "one_liner": null,
  "optional_dependencies": [],
  "rank_30d": 5327,
  "rank_365d": 5131,
  "rank_90d": 4784,
  "raw_hash": "f12a20b1abbf9dec",
  "recommended_dependencies": [],
  "revision": 0,
  "ruby_source_path": "Formula/c/chainsaw.rb",
  "tap": "homebrew/core",
  "test_dependencies": [],
  "uses_from_macos": [],
  "version_head": "HEAD",
  "version_stable": "2.16.0",
  "versioned_formulae": [],
  "why_use_this": null
}