Skip to content

Malware University

Class is in Session

  • About
    • Privacy Policy
  • Contact
  • Resources

Tag: EDR

Chainsaw

Posted on September 8, 2021 - September 8, 2021 by admin

A new tool called Chainsaw was released on August 14, 2021. It helps blue teams find potential threats in Windows event logs. It was originally made for environments without an endpoint detection and response (EDR) solution was not available during a compromise.

Windows event logs store system activity such as application activity and logins. Such information is vital to defenders and investigators in incident response scenarios. Manually combing through the raw logs is time consuming due to the potentially large volume of information.

Chainsaw is written in the Rust programming language. It parses the event logs to find suspicious strings or entries of interest indicating a possible threat. The Sigma signature format to allow analysts or outside contributors to describe log events in patterns which may be useful for finding potential malicious activity.

Posted in UtilitiesTagged blue teaming, chainsaw, EDR, incident response, sigma, threat detection, threat huntingLeave a comment

Recent Posts

  • Manual Scraping
  • Nitter Replacement
  • MFA Abuse in Splunk
  • Virtualbox Automation
  • Repository Poisoning

Recent Comments

    Archives

    • August 2024
    • July 2023
    • August 2022
    • March 2022
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • February 2021
    • December 2020
    • October 2020
    • September 2020
    • April 2020
    • March 2020
    • January 2020
    • July 2019
    • June 2019

    Categories

    • Campaign Analysis
    • Campaign Management
    • Code Analysis
    • Current Events
    • Malware Development
    • Techniques
    • Uncategorized
    • Utilities

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Proudly powered by WordPress | Theme: micro, developed by DevriX.