Skip to content

Yamato-Security/suzaku

Repository files navigation

Suzaku Logo

Suzaku (朱雀) is a Sigma-based threat hunting and fast forensics timeline generator for cloud logs.
Created by Yamato Security and written in Rust — imagine Hayabusa, but for cloud logs.

Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية

🦅 About

Suzaku (朱雀) — the "Vermilion Bird" that rules the southern heavens above the clouds — is a threat hunting and fast forensics timeline generator for cloud logs, written in memory-safe Rust. Think of Hayabusa but for cloud logs instead of Windows event logs, with native Sigma detection for AWS CloudTrail (Azure and GCP planned).

Among thousands of cloud API calls, Suzaku finds the attacks in the noise and gives you a DFIR timeline with only the events you need — plus summaries of attacker activity (source IPs, geo-location, regions, user agents) to pivot on.

📖 Documentation

All documentation now lives on a dedicated, searchable, multi-language site:

Section
🚀 Getting Started Download, install and run Suzaku
⌨️ Command Reference Analysis, DFIR Summary and DFIR Timeline commands
🧩 Native Sigma Support Sigma detection and correlation rules
📦 Resources Companion projects, changelog, contributing

⬇️ Download

Grab the latest binaries from the Releases page, or see Getting Started for building from source.

🗂️ Looking for the old README?

The previous single-page README is preserved unchanged:

🤝 Contributing & License

Contributions and bug reports are welcome — see Contributing & Support. Suzaku is released under the GNU AGPLv3 license.


Made with 🦅 by Yamato Security  ·  @SecurityYamato

About

Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.

Topics

Resources

License

Stars

182 stars

Watchers

1 watching

Forks

Packages

 
 
 

Contributors