Skip to content

Add Hayabusa module to generate a CSV timeline compatible with Timesketch#1101

Merged
AndrewRathbun merged 4 commits into
EricZimmerman:masterfrom
z3f1r0:master
Mar 12, 2026
Merged

Add Hayabusa module to generate a CSV timeline compatible with Timesketch#1101
AndrewRathbun merged 4 commits into
EricZimmerman:masterfrom
z3f1r0:master

Conversation

@z3f1r0
Copy link
Copy Markdown
Contributor

@z3f1r0 z3f1r0 commented Mar 11, 2026

Description

Added a Hayabusa module to generate a timeline in CSV format ready for import into Timesketch.
This enables faster event log analysis by quickly transforming Windows events into a format suitable for rapid timeline-based investigations.

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

  • I have generated a unique GUID for my Target(s)/Module(s)
  • I have placed the Target(s)/Module(s) in an appropriate subfolder in Targets or Modules. If one doesn't exist, I have either added it to the Misc folder or created a relevant subfolder with justification
  • I have set or updated the version of my Target(s)/Module(s)
  • I have verified that KAPE parses the Target(s)/Module(s) successfully via kape.exe, using --tlist/--mlist and corrected any errors
  • I have validated my Target(s)/Module(s) against test data and verified they are working as intended
  • [ X] I have made an attempt to document the artifacts within the Target(s) or Module(s) I am submitting. If documentation doesn't exist, I have placed N/A underneath the Documentation header
  • For Targets, I have consulted either the Target Guide, Target Template, Compound Target Guide, or Compound Target Template to ensure my Target(s) follow the same format
  • [ X] For Modules, I have consulted either the Module Guide, Module Template, Compound Module Guide, or Compound Module Template to ensure my Module(s) follow the same format

If your submission involves an SQLite database, have you considered making an SQLECmd Map for the SQLite database? If you make a Map, please add the SQLite database to the SQLiteDatabases.tkape Compound Target.

Thank you for your submission and for contributing to the DFIR community!

@AndrewRathbun AndrewRathbun self-assigned this Mar 12, 2026
@AndrewRathbun AndrewRathbun added the enhancement New feature or request label Mar 12, 2026
@AndrewRathbun AndrewRathbun merged commit 38c1a57 into EricZimmerman:master Mar 12, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants