chainsaw

Installation
SKILL.md

Chainsaw

Rapid first-response hunting across Windows artifacts with Sigma + Chainsaw rules.

When to use

  • You have exported .evtx logs and need fast threat triage.
  • You need ScriptBlock/Defender/service/task detection without SIEM.
  • You want timeline-oriented findings in CSV/JSON for incident notes.
  • You suspect selective EVTX tampering and need record/time gap checks.

Core workflow

  1. Validate artifact scope (which channels and time range are present).
  2. Run hunt with Sigma + mapping and optionally Chainsaw rules.
  3. Export to CSV/JSON and pivot on key EventIDs.
  4. If tampering is suspected, run analyse gaps.
  5. Correlate detections with process, registry, and network evidence.
Installs
6
GitHub Stars
22
First Seen
Jun 16, 2026
chainsaw — aeondave/malskill