Suzaku (朱雀) is a Sigma-based threat hunting and fast forensics timeline generator for cloud logs.
Created by Yamato Security and written in
Rust — imagine
Hayabusa, but for cloud logs.
Suzaku (朱雀) — the "Vermilion Bird" that rules the southern heavens above the clouds — is a threat hunting and fast forensics timeline generator for cloud logs, written in memory-safe Rust. Think of Hayabusa but for cloud logs instead of Windows event logs, with native Sigma detection for AWS CloudTrail (Azure and GCP planned).
Among thousands of cloud API calls, Suzaku finds the attacks in the noise and gives you a DFIR timeline with only the events you need — plus summaries of attacker activity (source IPs, geo-location, regions, user agents) to pivot on.
All documentation now lives on a dedicated, searchable, multi-language site:
| Section | |
|---|---|
| 🚀 Getting Started | Download, install and run Suzaku |
| ⌨️ Command Reference | Analysis, DFIR Summary and DFIR Timeline commands |
| 🧩 Native Sigma Support | Sigma detection and correlation rules |
| 📦 Resources | Companion projects, changelog, contributing |
Grab the latest binaries from the Releases page, or see Getting Started for building from source.
The previous single-page README is preserved unchanged:
- 📄 OLD-README.md — English
- 📄 OLD-README-Japanese.md — 日本語
Contributions and bug reports are welcome — see Contributing & Support. Suzaku is released under the GNU AGPLv3 license.
