Chainsaw: hunt with detection rules
chainsaw_huntScan evidence files with Sigma and Chainsaw detection rules to return aggregate detection counts by rule, level, host, channel, event ID, and hour, plus a preview.
Instructions
Hunt evidence with Sigma and Chainsaw detection rules.
Runs chainsaw hunt over the given paths, stores every detection as JSONL under a
server-minted result handle, and returns aggregate counts (by rule, level, host,
channel, event ID, hour) with a small preview. Prefer this over reading raw events.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| kinds | No | Restrict loaded rules to these kinds: chainsaw, sigma. | |
| paths | Yes | Evidence files or directories, relative to an allowed evidence root or absolute inside one. Directories are searched recursively. | |
| sigma | No | Apply the bundled Sigma rules through the mapping file. | |
| fields | No | Dotted paths or shorthand names to project in the inline preview; see chainsaw_result_fields. Omit for the standard shorthand columns. | |
| levels | No | Restrict rules to these levels: critical, high, medium, low, info. | |
| mapping | No | Mapping file name inside the mappings directory. Default sigma-event-logs-all.yml; sigma-event-logs-legacy.yml for pre-Sysmon logs. | |
| preview | No | Detections to include inline (0-100). | |
| to_time | No | Drop documents newer than this, format YYYY-MM-DDTHH:MM:SS. | |
| statuses | No | Restrict loaded rules to these statuses: stable, experimental. | |
| timezone | No | Render timestamps in this IANA timezone (default UTC). | |
| extension | No | Only load files with this extension, e.g. evtx. | |
| from_time | No | Drop documents older than this, format YYYY-MM-DDTHH:MM:SS. | |
| extra_rules | No | Additional Chainsaw-format rule directories: 'custom' for analyst-saved rules, or 'chainsaw/<subdir>' such as 'chainsaw/evtx/lateral_movement'. | |
| skip_errors | No | Continue past unreadable files instead of failing the hunt. | |
| load_unknown | No | Let chainsaw try to parse files it cannot identify. | |
| chainsaw_rules | No | Apply the bundled Chainsaw rules (rules/ directory). | |
| sigma_collections | No | Sigma collections or sub-trees to load, e.g. ['rules'], ['rules', 'rules-threat-hunting'] or ['rules/windows/process_creation']. Default: ['rules']. Use chainsaw_rule_stats to see what is installed. |