Suzaku (朱雀): Sigma-based threat hunting and fast forensics timeline generator for cloud logs

Suzaku is an open-source tool, written in memory-safe Rust, designed for threat hunting and generating forensic timelines from cloud logs, with a primary focus on AWS CloudTrail (with Azure and GCP planned). It uses native Sigma detection rules to identify malicious activity among thousands of cloud API calls, filtering out noise to produce a concise, attack-relevant timeline. The output includes attacker activity summaries with key details like source IPs, geolocation, regions, and user agents to aid investigation and pivoting. Created by Yamato Security, Suzaku is positioned as a cloud-centric counterpart to Hayabusa (a Windows event log analyzer) and is available under the GNU AGPLv3 license, with comprehensive multi-language documentation and binaries available on its releases page. 

https://github.com/Yamato-Security/suzaku

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

Open-SPDD proposes an open framework for Spec-Driven Development workflows

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know