Skip to content
@Yamato-Security

Yamato Security 大和セキュリティ

Hi there まいど! 👋

About Yamato Security

Yamato Security is a security group created by Zach Mathis (@yamatosecurity) in 2012. At first, the main purpose was to provide security training to build a local security community in Western Japan but has grown to provide training, CTF events, webinars, etc... across the country for thousands of people.

Now, with a group of volunteer members, we are providing free open source DFIR tools such as Hayabusa, WELA, Takajo, Suzaku, etc...

Please contact us if you want to help out and contribute.

Main Projects

  • Hayabusa - (隼) A sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
  • Takajo - (鷹匠) An analyzer for Hayabusa results.
  • Suzaku - (朱雀) A sigma-based threat hunting and fast forensics timeline generator for cloud logs.
  • WELA - ゑ羅(ウェラ)(Windows Event Log Auditor): An auditing and configuration tool for Windows event logs.
  • Yamato Security's Windows Event Log Configuration Guide For DFIR And Threat Hunting - Documentation for how to configure proper Windows audit log settings and which categories and Event IDs are important to monitor.
  • Presentations - Presentations in English and Japanese.

Popular repositories Loading

  1. hayabusa hayabusa Public

    Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

    Rust 3.4k 299

  2. WELA-deprecated WELA-deprecated Public

    WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)

    PowerShell 776 76

  3. EnableWindowsLogSettings EnableWindowsLogSettings Public

    Documentation and scripts to properly enable Windows event logs.

    Batchfile 722 66

  4. hayabusa-rules hayabusa-rules Public

    Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.

    Python 226 35

  5. suzaku suzaku Public

    Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.

    Rust 224 15

  6. takajo takajo Public

    Takajō (鷹匠) is a Hayabusa results analyzer.

    Nim 166 13

Repositories

Showing 10 of 26 repositories
  • suzaku Public

    Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.

    Yamato-Security/suzaku's past year of commit activity
    Rust 224 AGPL-3.0 15 5 0 Updated Oct 5, 2026
  • hayabusa Public

    Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

    Yamato-Security/hayabusa's past year of commit activity
    Rust 3,380 AGPL-3.0 299 18 1 Updated Oct 4, 2026
  • hayabusa-encoded-rules Public

    Encoded Hayabusa and Sigma rules to avoid anti-virus false positives and reduce files stored on target systems.

    Yamato-Security/hayabusa-encoded-rules's past year of commit activity
    Rust 9 0 1 0 Updated Oct 4, 2026
  • senrigan Public

    Offline, open-source AWS CloudTrail DFIR & threat hunting platform — 120+ built-in hunts, 100+ Superset dashboard charts, AI chat, and an AWS Config resource graph.

    Yamato-Security/senrigan's past year of commit activity
    Python 23 AGPL-3.0 3 4 0 Updated Oct 3, 2026
  • hayabusa-rules Public

    Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.

    Yamato-Security/hayabusa-rules's past year of commit activity
    Python 226 35 2 0 Updated Oct 2, 2026
  • WELA Public

    WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing and configuring Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR), providing visibility into system activity and security events.

    Yamato-Security/WELA's past year of commit activity
    PowerShell 122 MIT 13 38 6 Updated Oct 1, 2026
  • irflow-timeline-windows Public Forked from r3nzsec/irflow-timeline

    Windows port of irflow-timeline

    Yamato-Security/irflow-timeline-windows's past year of commit activity
    JavaScript 0 Apache-2.0 53 0 0 Updated Sep 30, 2026
  • irflow-timeline-linux Public Forked from r3nzsec/irflow-timeline

    Linux port of irflow-timeline

    Yamato-Security/irflow-timeline-linux's past year of commit activity
    JavaScript 1 Apache-2.0 53 0 0 Updated Sep 30, 2026
  • EventLog-Baseline-Guide Public

    Windows Event Log Audit Configuration Baselines and Guidelines. Automated monitoring of audit policy settings across different security frameworks.

    Yamato-Security/EventLog-Baseline-Guide's past year of commit activity
    Batchfile 13 MIT 3 0 0 Updated Sep 19, 2026
  • SENGOAD Public

    戦国時代テーマのGOAD環境

    Yamato-Security/SENGOAD's past year of commit activity
    PowerShell 0 GPL-3.0 2 0 0 Updated Sep 18, 2026

People

This organization has no public members. You must be a member to see who’s a part of this organization.