Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
$ npx skills add Yamato-Security/hayabusaAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
$ npx skills add Yamato-Security/hayabusaVolatility 3.0 development
$ npx skills add volatilityfoundation/volatility3UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
$ npx skills add tclahr/uacList of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
$ npx skills add toniblyx/my-arsenal-of-aws-security-toolsThe Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
$ npx skills add sleuthkit/sleuthkitCross-platform incident response and live forensics toolkit with built-in detection, structured analysis, and report generation — designed for fast, actionable security investigations.
$ npx skills add Johnng007/Live-ForensicatorA list of cyber-chef recipes and curated links
$ npx skills add mattnotmax/cyberchef-recipesCollection of forensic tools
$ npx skills add cristianzsh/forensictoolsOpen-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
$ npx skills add beenuar/AiSOCCortex: a Powerful Observable Analysis and Active Response Engine
$ npx skills add TheHive-Project/CortexRdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
$ npx skills add BSI-Bund/RdpCacheStitcherIntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
$ npx skills add certtools/intelmqA collection of resources for Threat Hunters
$ npx skills add A3sal0n/CyberThreatHuntingFAME Automates Malware Evaluation
$ npx skills add certsocietegenerale/fameA Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365
$ npx skills add darkquasar/AzureHunter⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident response processes
$ npx skills add SecurityBrewery/catalystHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Ir Rescue if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.