README.md
June 29, 2026 · View on GitHub
Suzaku (朱雀) is a Sigma-based threat hunting and fast forensics timeline generator for cloud logs.
Created by Yamato Security and written in
Rust — imagine
Hayabusa, but for cloud logs.
📖 Read the Documentation →
Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية🦅 About
Suzaku (朱雀) — the "Vermilion Bird" that rules the southern heavens above the clouds — is a threat hunting and fast forensics timeline generator for cloud logs, written in memory-safe Rust. Think of Hayabusa but for cloud logs instead of Windows event logs, with native Sigma detection for AWS CloudTrail (Azure and GCP planned).
Among thousands of cloud API calls, Suzaku finds the attacks in the noise and gives you a DFIR timeline with only the events you need — plus summaries of attacker activity (source IPs, geo-location, regions, user agents) to pivot on.
📖 Documentation
All documentation now lives on a dedicated, searchable, multi-language site:
👉 yamato-security.github.io/suzaku
| Section | |
|---|---|
| 🚀 Getting Started | Download, install and run Suzaku |
| ⌨️ Command Reference | Analysis, DFIR Summary and DFIR Timeline commands |
| 🧩 Native Sigma Support | Sigma detection and correlation rules |
| 📦 Resources | Companion projects, changelog, contributing |
⬇️ Download
Grab the latest binaries from the Releases page, or see Getting Started for building from source.
🗂️ Looking for the old README?
The previous single-page README is preserved unchanged:
- 📄 OLD-README.md — English
- 📄 OLD-README-Japanese.md — 日本語
🤝 Contributing & License
Contributions and bug reports are welcome — see Contributing & Support. Suzaku is released under the GNU AGPLv3 license.