Suzaku (朱雀): Sigma-based threat hunting and fast forensics timeline generator for cloud logs
Suzaku is an open-source tool, written in memory-safe Rust, designed for threat hunting and generating forensic timelines from cloud logs, with a primary focus on AWS CloudTrail (with Azure and GCP planned). It uses native Sigma detection rules to identify malicious activity among thousands of cloud API calls, filtering out noise to produce a concise, attack-relevant timeline. The output includes attacker activity summaries with key details like source IPs, geolocation, regions, and user agents to aid investigation and pivoting. Created by Yamato Security, Suzaku is positioned as a cloud-centric counterpart to Hayabusa (a Windows event log analyzer) and is available under the GNU AGPLv3 license, with comprehensive multi-language documentation and binaries available on its releases page.
Comments
Post a Comment