Skip to content

Repository files navigation

Suzaku Logo

Suzaku (朱雀) is a Sigma-based threat hunting and fast forensics timeline generator for cloud logs.
Created by Yamato Security and written in Rust — imagine Hayabusa, but for cloud logs.

Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية

🦅 About

Suzaku (朱雀) — the "Vermilion Bird" that rules the southern heavens above the clouds — is a threat hunting and fast forensics timeline generator for cloud logs, written in memory-safe Rust. Think of Hayabusa but for cloud logs instead of Windows event logs, with native Sigma detection for AWS CloudTrail, Azure/Entra ID/M365, and Google Workspace.

Among thousands of cloud API calls, Suzaku finds the attacks in the noise and gives you a DFIR timeline with only the events you need — plus summaries of attacker activity (source IPs, geo-location, regions, user agents) to pivot on.

📖 Documentation

All documentation now lives on a dedicated, searchable, multi-language site:

Section
🚀 Getting Started Download, install and run Suzaku
⌨️ Command Reference Analysis, DFIR Summary and DFIR Timeline commands
🧩 Native Sigma Support Sigma detection and correlation rules
📦 Resources Companion projects, changelog, contributing

⬇️ Download

Grab the latest binaries from the Releases page, or see Getting Started for building from source.

🗂️ Looking for the old README?

The previous single-page README is preserved unchanged:

🤝 Contributing & License

Contributions and bug reports are welcome — see Contributing & Support. Suzaku is released under the GNU AGPLv3 license.


Made with 🦅 by Yamato Security  ·  @SecurityYamato

About

Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.

Topics

Resources

Stars

223 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages