Suzaku (朱雀) is a Sigma-based threat hunting and fast forensics timeline generator for cloud logs.
Created by Yamato Security and written in
Rust — imagine
Hayabusa, but for cloud logs.
Suzaku (朱雀) — the "Vermilion Bird" that rules the southern heavens above the clouds — is a threat hunting and fast forensics timeline generator for cloud logs, written in memory-safe Rust. Think of Hayabusa but for cloud logs instead of Windows event logs, with native Sigma detection for AWS CloudTrail, Azure/Entra ID/M365, and Google Workspace.
Among thousands of cloud API calls, Suzaku finds the attacks in the noise and gives you a DFIR timeline with only the events you need — plus summaries of attacker activity (source IPs, geo-location, regions, user agents) to pivot on.
All documentation now lives on a dedicated, searchable, multi-language site:
| Section | |
|---|---|
| 🚀 Getting Started | Download, install and run Suzaku |
| ⌨️ Command Reference | Analysis, DFIR Summary and DFIR Timeline commands |
| 🧩 Native Sigma Support | Sigma detection and correlation rules |
| 📦 Resources | Companion projects, changelog, contributing |
Grab the latest binaries from the Releases page, or see Getting Started for building from source.
The previous single-page README is preserved unchanged:
- 📄 OLD-README.md — English
- 📄 OLD-README-Japanese.md — 日本語
Contributions and bug reports are welcome — see Contributing & Support. Suzaku is released under the GNU AGPLv3 license.
