BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Senrigan (千里眼) x Suzaku (朱雀): Threat Hunti
 ng & DFIR\n   for AWS — No SIEM\, Just Your Laptop\n   Tags: DEF CON Dem
 o Labs | Intermediate | Cloud | Defense/Blue Team |\n   Purple Team | Thre
 at Intel/Hunting | DEF CON Demo Labs\n   When: Saturday\, Aug 8\, 14:00 - 
 14:45 PDT\n   Where: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - [1]Ma
 p\n\n   Description:\n\n   Senrigan (千里眼) and Suzaku (朱雀) are tw
 o complementary\n   open-source tools that together form a complete threat
  hunting and\n   DFIR platform for AWS CloudTrail logs. Both are built by 
 Yamato\n   Security\, the volunteer-run Japanese security community behind
 \n   Hayabusa（隼）\, the widely adopted Windows event log fast-forensi
 cs\n   tool. Yamato Security provides free\, open-source DFIR tools and\n 
   resources to the community.\n\n   Building on Hayabusa's philosophy of f
 ast\, offline\, community\n   rule-based detection\, this toolset brings t
 he same approach to the\n   cloud. Security teams can hunt threats across 
 CloudTrail logs on a\n   single laptop — without a SIEM\, dedicated infr
 astructure\, or\n   licensing cost.\n\n   The two tools work together\, wi
 th Suzaku's detections flowing into\n   Senrigan for analysis. Senrigan\, 
 deployed via Docker Compose\, ingests\n   CloudTrail logs into DuckDB via 
 a Rust-based ingester\, then lets\n   analysts investigate them through 10
 0+ pre-built hunting queries and\n   80+ pre-built Apache Superset dashboa
 rd charts — no SQL or\n   CloudTrail schema knowledge required. Suzaku i
 s a high-performance\,\n   standalone Rust-based CLI that applies native S
 igma detection rules to\n   CloudTrail logs and generates a fast-forensics
  DFIR timeline —\n   surfacing attacks buried in the noise\, producing o
 nly the events\n   analysts need to investigate.\n\n   Speakers:Fukusuke T
 akahashi\,Zach Mathis\,Akira Nishikawa\n\n   SpeakerBio:  Fukusuke Takahas
 hi\n\n   Fukusuke Takahashi has been with NTTDATA-CERT (NTT DATA Group\n  
  Corporation's CSIRT) since 2018\, specializing in DFIR\, OSINT\, and\n   
 SOAR. He is one of the developers of Yamato Security's OSS tools. He\n   e
 njoys developing open-source Blue Team tools. He has presented at\n   conf
 erences such as FIRST Annual Conferences\, SECCON\, BSides Tokyo\,\n   HIT
 CON CMT\, SecTor and AUSCERT.\n\n   SpeakerBio:  Zach Mathis\n\n   Zach Ma
 this has been working in Japan doing offensive and defensive\n   security 
 work for Japanese companies since 2006. In 2012\, he founded\n   Yamato Se
 curity\, one of the largest hands-on hacker communities in\n   Japan. With
  other Yamato Security members\, he has been releasing free\n   and open s
 ource DFIR tools and resources since 2020.\n\n   SpeakerBio:  Akira Nishik
 awa\n\n   Akira Nishikawa started his career as a software engineer specia
 lizing\n   in embedded development. He worked as a freelance engineer in 2
 007\,\n   focusing on system development and operation for various compani
 es.\n   Since 2021\, he has been dedicated to fostering a security culture
  for\n   SaaS product security and improving service security. Additionall
 y\, he\n   is an AWS Community Builder as of 2024.\n\n   Links:\n       Gi
 thub (Senrigan) - [2]https://github.com/Yamato-Security/senrigan\n       G
 itHub (Suzaku) - [3]https://github.com/Yamato-Security/suzaku\n   '\n\n   
 1. #LVCCW_Level1_Hall3\n   2. https://github.com/Yamato-Security/senrigan\
 n   3. https://github.com/Yamato-Security/suzaku\n\n\n
DTEND:20260808T214500Z
DTSTART:20260808T210000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)
SUMMARY:Senrigan (千里眼) x Suzaku (朱雀): Threat Hunting & DFIR for A
 WS — No SIEM\, Just Your Laptop
END:VEVENT
END:VCALENDAR
