README.md

June 29, 2026 · View on GitHub

Suzaku Logo

Suzaku (朱雀) is a Sigma-based threat hunting and fast forensics timeline generator for cloud logs.
Created by Yamato Security and written in Rust — imagine Hayabusa, but for cloud logs.

📖 Read the Documentation →

Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية

🦅 About

Suzaku (朱雀) — the "Vermilion Bird" that rules the southern heavens above the clouds — is a threat hunting and fast forensics timeline generator for cloud logs, written in memory-safe Rust. Think of Hayabusa but for cloud logs instead of Windows event logs, with native Sigma detection for AWS CloudTrail (Azure and GCP planned).

Among thousands of cloud API calls, Suzaku finds the attacks in the noise and gives you a DFIR timeline with only the events you need — plus summaries of attacker activity (source IPs, geo-location, regions, user agents) to pivot on.

📖 Documentation

All documentation now lives on a dedicated, searchable, multi-language site:

👉 yamato-security.github.io/suzaku

Section
🚀 Getting StartedDownload, install and run Suzaku
⌨️ Command ReferenceAnalysis, DFIR Summary and DFIR Timeline commands
🧩 Native Sigma SupportSigma detection and correlation rules
📦 ResourcesCompanion projects, changelog, contributing

⬇️ Download

Grab the latest binaries from the Releases page, or see Getting Started for building from source.

🗂️ Looking for the old README?

The previous single-page README is preserved unchanged:

🤝 Contributing & License

Contributions and bug reports are welcome — see Contributing & Support. Suzaku is released under the GNU AGPLv3 license.


Made with 🦅 by Yamato Security  ·  @SecurityYamato