macOS
brew install chainsawlocal Homebrew formula metadata
brew
chainsaw のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。
インストール
brew install chainsawlocal Homebrew formula metadata
nix profile install nixpkgs#chainsawnixpkgs package indexes · pkgs/by-name/ch/chainsaw/package.nix · ソース: api.github.com
sudo zypper install apache-chainsawopenSUSE Tumbleweed package metadata · apache-chainsaw · ソース: download.opensuse.org
概要
Rapidly Search and Hunt through Windows Forensic Artefacts
履歴
Chainsaw is a WithSecure Labs command-line tool for rapid Windows forensic triage. It searches event logs and other Windows artefacts, applies Sigma and custom detection rules, and emits investigator-friendly output formats.
WithSecure Countercept created Chainsaw for incident-response cases where endpoint telemetry or a SIEM was not available, so analysts needed fast standalone processing of Windows artefacts. The public GitHub repository was created in August 2021 and v1.0.0 was released later that month.
The project evolved from an all-in-one threat-hunting bundle toward a tool that expects users to keep Sigma rules and sample event logs separately. The README notes that Chainsaw v2 stopped including Sigma Rules and EVTX-Attack-Samples as submodules so users could track those projects independently.
Chainsaw is distributed through GitHub releases, Nix, and the Homebrew formula named chainsaw. That packaging path matters because the tool is useful as a portable first-response binary on analyst workstations and ephemeral response systems.
GitHub release metadata shows active maintenance from v1.0.0 in 2021 through v2 releases in 2026.
Typical use is to run chainsaw against Windows event-log collections, optionally supplying a Sigma rules directory and a mapping file such as mappings/sigma-event-logs-all.yml. The README documents output formats including table, CSV, and JSON, plus timeline generation from Shimcache enriched with Amcache data.
Chainsaw is notable in package-manager culture because it packages modern Rust DFIR tooling for a workflow that often used heavier SIEM stacks such as Splunk or ELK. It also shows the Sigma ecosystem becoming something local CLIs can consume directly.
セキュリティ状態
chainsaw に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。
エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。
実行可能ファイル
| コマンド | 種類 | 公開範囲 | メモ |
|---|---|---|---|
chainsaw | cli | グローバル実行可能ファイル |
鮮度
これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。
https://github.com/WithSecureLabs/chainsaw
インストールメタデータ
| パッケージキー | brew:chainsaw |
|---|---|
| バージョン | 2.16.2 |
| パッケージマネージャ | Homebrew |
| パッケージマネージャページ | https://formulae.brew.sh/formula/chainsaw |
| ホームページ | https://github.com/WithSecureLabs/chainsaw |
| リポジトリ | https://github.com/WithSecureLabs/chainsaw |
| 上流ドキュメント | https://github.com/WithSecureLabs/chainsaw#readme |
| ライセンス | GPL-3.0-only |
| ソースアーカイブ | https://github.com/WithSecureLabs/chainsaw/archive/refs/tags/v2.16.2.tar.gz |
| 最終更新 | 2026-07-09T10:07:08Z |
| Pulse | updated |
| ビルド依存関係 | rust |
| Bottle | 利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | 未定義 |
| サービス | 宣言なし |
レジストリ情報
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | chainsaw |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
ソースデータベース一致
一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。
chainsaw
nix profile install nixpkgs#chainsawapache-chainsaw 2.1.0-5.8
Apache Chainsaw
https://logging.apache.org/chainsaw
sudo zypper install apache-chainsawソース経路
このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。
View the package source record on GitHub.