Chainsaw cuts through Windows event logs faster than you can say "lateral movement."
When you're triaging a Windows compromise and drowning in EVTX files, Chainsaw by WithSecure is the tool that gets you answers in seconds, not hours. It's built for speed — rip through gigabytes of event logs, hunt for known-bad patterns, and surface the signals that matter.
Three reasons it lives in every IR toolkit:
1. Native Sigma support — drop in community detection rules and run them at scale across entire log sets. No conversion, no friction.
2. Hunting mode — search for specific event IDs, usernames, process names, or IP addresses across thousands of EVTX files in one pass. Perfect for pivoting on IOCs during active investigations.
3. Flexible output — table view for quick triage, CSV/JSON for feeding into your SIEM or timeline tools. Chainsaw plays well with the rest of your stack.
Real-world use case: You've got a suspected domain admin compromise. Chainsaw lets you hunt for 4624 logons with that account across every domain controller in minutes, then export matches as JSON and correlate with process execution logs from Sysmon. Pair it with Hayabusa for deeper hunting and you've got a complete Windows log analysis pipeline.
Grab it from the WithSecure Labs GitHub. If you're doing Windows IR without Chainsaw, you're working too hard.
#DFIRTools #IncidentResponse