% FOX HUNT(1) Version 5 | Fox Documentation
fox — The Forensic Examiner's Swiss Army Knife
| fox hunt [flags ...] [local | paths ...]
Hunt suspicious activities by carving events from file(s). Please be aware that, using the --sort flag will buffer all found events in memory. For large sets of data this could be very slow and take a serious amount of memory. All timestamps will be normalized to UTC.
-a, --all
: Show logs with all severities.
-s, --sort
: Show logs sorted by timestamp.
-u, --uniq
: Show logs that are unique by XXH3 hash. The calculated hash has 64-bits and is highly unlikely, but still possible, to collide with the another key.
-j, --json
: Show logs as JSON objects.
-l, --jsonl
: Show logs as JSON lines.
-t, --triage
: Show logs in Triage format. Implies --sort and --uniq flags.
-p, --parquet
: Save logs as Parquet file.
-N, --min=time
: Minimum event time in RFC3339 format. Example: 2026-12-31T12:00:00.0Z.
-X, --max=time
: Maximum event time in RFC3339 format. Example: 2026-12-31T12:00:00.0Z.
-R, --rule=file
: Filter using Sigma rules file.
-U, --url=url
: Stream events using CEF schema to url.
-E, --ecs=url
: Stream events using ECS schema to url.
-H, --hec=url
: Stream events using HEC schema to url.
-A, --auth=token
: Use auth token with HEC streaming. Must be specified without the 'Splunk' prefix.
Globbing paths to open or '-' to read from STDIN(4). If local is specified as path, a built-in list of known locations will be processed.
$ fox hunt -t *.dd
: Hunt down critical events.
$ fox hunt -ap local
: Save local events as Parquet.
$ fox hunt -E http://127.0.0.1:8080 *.evtx
: Send events to an Elastic Stack.
Please submit any issues with fox to the project's bug tracker: <_https://foxforensics.eu/issues_>
Please visit the project's homepage at: <https://foxforensics.eu>
fox(1), sort(1), uniq(1)