Rapidly search and hunt through Windows forensic artifacts
Rapidly Search and Hunt through Windows Forensic Artefacts
chainsaw$ chainsaw search -i /path/to/eventlog.evtx -s 'process creation' --csv output.csv$ chainsaw hunt -i /path/to/logs/ -r rules/ --json results.json$ chainsaw dump /path/to/Security.evtx | head -50