← back

category

Endpoint detection and forensics

Query laptops and servers, hunt for threats on them and collect forensic evidence.

Side by side

Endpoint detection and forensics
ToolStarsLicenceTermsSelf-hostedLanguageLatestLast push
osquery24kOtherOpen sourceYesC++5.23.12026-10-06
GRR Rapid Response5.1kApache-2.0Open sourceYesPythonv.4.0.0.0-release2026-10-01
Velociraptor4.3kOtherOpen sourceYesGov0.77.32026-10-05
Chainsaw3.7kGPL-3.0Open sourceYesRustv2.16.52026-09-23
Hayabusa3.4kAGPL-3.0Open sourceYesRustv4.1.02026-10-04

5 tools

osquery

SQL powered operating system instrumentation, monitoring, and analytics.

Language
C++
Licence
Other
Stars
24k
Latest
5.23.1
Last push
2026-10-06
Chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Language
Rust
Licence
GPL-3.0
Stars
3.7k
Latest
v2.16.5
Last push
2026-09-23
Hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Language
Rust
Licence
AGPL-3.0
Stars
3.4k
Latest
v4.1.0
Last push
2026-10-04

What these tools replace