Introducing Chainsaw, a free tool to identify threats in Windows event logs.
F-Secure has open sourced a new tool for incident response teams and other security professionals called Chainsaw -- designed as a "first-response" capability to quickly identify threats within Windows event logs. (The Stack is adding it to our list of free security tools from reputable sources with real utility for enterprise security: Chainsaw joins Bloodhound, Infection Monkey, OpenCTI and others on that list...) Developed by James D, who is the lead threat hunter at F-Secure’s managed detection and response unit Countercept, Chainsaw offers a "generic and fast method of searching through event logs for keywords, and by identifying threats using built-in detection logic and via support for Sigma detection rules" -- written in Rust and accessible via command line, it's likely to be particularly for IR and Blue Teams responding to breaches. As the F-Secure team noted in a blog: "At the time of writing, there are very few open-source, standalone tools that provide a simple and fast met
F-Secure has open sourced a new tool for incident response teams and other security professionals called Chainsaw -- designed as a "first-response" capability to quickly identify threats within Windows event logs. ( The Stack is adding it to our list of free security tools from reputable sources with real utility for enterprise security: Chainsaw joins Bloodhound , Infection Monkey , OpenCTI and others on that list ...) Developed by James D , who is the lead threat hunter at F-Secure’s managed detection and response unit Countercept, Chainsaw offers a "generic and fast method of searching thro
Explore this link on the map →related reading
- Security incident disclosure — July 2026huggingface.co
- RunReveal is now in Open Betablog.runreveal.com
- New IDR Log Search Enhancements | Rapid7 Blograpid7.com
- Fundamentals to Security Alert Automation: SOAR Your Own Way | by Ryan G. Cox | Mediummedium.com
- UEBA Superpowers: Enhance Security Visibility with Rich Insights to Take Rapid Action Against Threats | Splunksplunk.com
- Customer Stories & Case Studies | Pantherpanther.com
- Introducing Sift: Automated Threat Huntinggreynoise.io
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- Best practices for creating custom detection rules with Datadog Cloud SIEM | Datadogdatadoghq.com