Hello 13Cubed. Thank you for this amazing video. I have a couple of questions regarding Chainsaw. Does Chainsaw work with Windows logs only, or does it work with other OS logs? Also, can it take (.json) logs or plain text logs (.log) as an input? Or is it specific for .evtx logs only?
It's a cross-platform tool, but it's designed for Windows forensic artifacts. And yes, Chainsaw v2 introduces "support for loading and parsing Event Logs in both JSON and XML format."
Not sure why this was in my recommended, but it was actually quite interesting. Thank's for showcasing this, subbed!
Awesome 👌 Thank for your time and I will explore more on this.
Going to have to add this tool to the repertoire
Awsome! Thanks for sharing the knowlege
Great job on this video.. súper profesional
awesome. thnx
This with velociraptor is gg
@@Lordyzagat velociraptor ir tool
can you also do a preview/walkthrough for the Hayabusa tool by Yamato-Security.
it looks like they are almost the same.
What happen to the syntax the commands to not work
Hello 13Cubed.
Thank you for this amazing video.
I have a couple of questions regarding Chainsaw.
Does Chainsaw work with Windows logs only, or does it work with other OS logs?
Also, can it take (.json) logs or plain text logs (.log) as an input? Or is it specific for .evtx logs only?
It's a cross-platform tool, but it's designed for Windows forensic artifacts. And yes, Chainsaw v2 introduces "support for loading and parsing Event Logs in both JSON and XML format."
@@13Cubed Thank you.
can you please provide a link to log database that you used
Hi, unfortunately that test database has been long since removed.
Please share the Latest and safest source link to download chainsaw .
github.com/WithSecureLabs/chainsaw/releases
Pretty cool.. Nice
does this require sysmon to be effective?
No, but Sysmon is certainly highly beneficial.
This seems to be out of date now with their update.
Such is life with RUclips... will consider making an update at some point.
none of these commands work for me. amazing
What error do you receive when you try? I need a little more detail if you want to solve the issue.