BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Senrigan (千里眼) x Suzaku (朱雀): Threat Hunti
 ng & DFIR\n   for AWS — No SIEM\, Just Your Laptop\n   Tags: DEF CON Dem
 o Labs | Intermediate | Cloud | Defense/Blue Team |\n   Purple Team | Thre
 at Intel/Hunting | DEF CON Demo Labs\n   When: Friday\, Aug 7\, 10:00 - 10
 :45 PDT\n   Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - [1]Map\
 n\n   Description:\n\n   Senrigan (千里眼) and Suzaku (朱雀) are two 
 complementary\n   open-source tools that together form a complete threat h
 unting and\n   DFIR platform for AWS CloudTrail logs. Both are built by Ya
 mato\n   Security\, the volunteer-run Japanese security community behind\n
    Hayabusa（隼）\, the widely adopted Windows event log fast-forensics
 \n   tool. Yamato Security provides free\, open-source DFIR tools and\n   
 resources to the community.\n\n   Building on Hayabusa's philosophy of fas
 t\, offline\, community\n   rule-based detection\, this toolset brings the
  same approach to the\n   cloud. Security teams can hunt threats across Cl
 oudTrail logs on a\n   single laptop — without a SIEM\, dedicated infras
 tructure\, or\n   licensing cost.\n\n   The two tools work together\, with
  Suzaku's detections flowing into\n   Senrigan for analysis. Senrigan\, de
 ployed via Docker Compose\, ingests\n   CloudTrail logs into DuckDB via a 
 Rust-based ingester\, then lets\n   analysts investigate them through 100+
  pre-built hunting queries and\n   80+ pre-built Apache Superset dashboard
  charts — no SQL or\n   CloudTrail schema knowledge required. Suzaku is 
 a high-performance\,\n   standalone Rust-based CLI that applies native Sig
 ma detection rules to\n   CloudTrail logs and generates a fast-forensics D
 FIR timeline —\n   surfacing attacks buried in the noise\, producing onl
 y the events\n   analysts need to investigate.\n\n   Speakers:Fukusuke Tak
 ahashi\,Zach Mathis\,Akira Nishikawa\n\n   SpeakerBio:  Fukusuke Takahashi
 \n\n   Fukusuke Takahashi has been with NTTDATA-CERT (NTT DATA Group\n   C
 orporation's CSIRT) since 2018\, specializing in DFIR\, OSINT\, and\n   SO
 AR. He is one of the developers of Yamato Security's OSS tools. He\n   enj
 oys developing open-source Blue Team tools. He has presented at\n   confer
 ences such as FIRST Annual Conferences\, SECCON\, BSides Tokyo\,\n   HITCO
 N CMT\, SecTor and AUSCERT.\n\n   SpeakerBio:  Zach Mathis\n\n   Zach Math
 is has been working in Japan doing offensive and defensive\n   security wo
 rk for Japanese companies since 2006. In 2012\, he founded\n   Yamato Secu
 rity\, one of the largest hands-on hacker communities in\n   Japan. With o
 ther Yamato Security members\, he has been releasing free\n   and open sou
 rce DFIR tools and resources since 2020.\n\n   SpeakerBio:  Akira Nishikaw
 a\n\n   Akira Nishikawa started his career as a software engineer speciali
 zing\n   in embedded development. He worked as a freelance engineer in 200
 7\,\n   focusing on system development and operation for various companies
 .\n   Since 2021\, he has been dedicated to fostering a security culture f
 or\n   SaaS product security and improving service security. Additionally\
 , he\n   is an AWS Community Builder as of 2024.\n\n   Links:\n       Gith
 ub (Senrigan) - [2]https://github.com/Yamato-Security/senrigan\n       Git
 Hub (Suzaku) - [3]https://github.com/Yamato-Security/suzaku\n   '\n\n   1.
  #LVCCW_Level1_Hall3\n   2. https://github.com/Yamato-Security/senrigan\n 
   3. https://github.com/Yamato-Security/suzaku\n\n\n
DTEND:20260807T174500Z
DTSTART:20260807T170000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)
SUMMARY:Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for A
 WS — No SIEM\, Just Your Laptop
END:VEVENT
END:VCALENDAR
