chainsaw
Installation
SKILL.md
Chainsaw
Rapid first-response hunting across Windows artifacts with Sigma + Chainsaw rules.
When to use
- You have exported
.evtxlogs and need fast threat triage. - You need ScriptBlock/Defender/service/task detection without SIEM.
- You want timeline-oriented findings in CSV/JSON for incident notes.
- You suspect selective EVTX tampering and need record/time gap checks.
Core workflow
- Validate artifact scope (which channels and time range are present).
- Run
huntwith Sigma + mapping and optionally Chainsaw rules. - Export to CSV/JSON and pivot on key EventIDs.
- If tampering is suspected, run
analyse gaps. - Correlate detections with process, registry, and network evidence.