DustInDark
422c0eacdf
added error output feature when output file path already exist #303
2021-12-20 01:44:15 +09:00
DustInDark
807b438009
moved output_error_log_exist due to emit_csv test #301
2021-12-20 01:25:47 +09:00
DustInDark
300242099b
Merge branch 'main' into feature/output_errorlog#301
2021-12-20 01:05:48 +09:00
DustInDark
37575ed0bb
removed unused crate
2021-12-20 00:48:06 +09:00
DustInDark
0e0ceff861
created error log output feature #301
2021-12-20 00:46:04 +09:00
DustInDark
dbba49b815
Hotfix/not work count#278 ( #281 )
...
* fixed countup structure #278
* fixed countup structure and count up field logic #278
* fixed tests #278
* added no output aggregation detect message when output exist in rule yaml #232
* moved get_agg_condtion to rulenode function #278
* added field_values to output count fields data #232 #278
- fixed count logic #278
- fixed count test to adjust field_values add
- added count test
* fixed count output format #232
* fixed compile error
* fixed count output #232
- moved output check to create_count_output
- fixed yaml condition reference
- adjust top and tail multi space
* added create count output test #232
* removed count by file #278
- commented by @YamatoSecurity
* changed sort function to sort_unstable_by
* fixed typo
* adjust to comment #281
ref: https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767283508
* adjust comment #281
refs
-
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767285993
-
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767286713
* adjust coment #281
ref:
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767287831
* omitted code #281
* adjust comment #281
ref:
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767302595
* adjust comment #281
ref:
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767303168
* adjust comment
ref:
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767307535
* omitted unnecessary code #281
* adjust comment #281
ref:
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767288428
* adjust commnet #281
ref:
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767286731
* adjust comment #281
ref:
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767285716
* adjust comment #281
ref:
159191ec36 (r767288428)
* adjust test result #281
* removed debug print statement in testfunction
* adjust comment #281
ref
https://github.com/Yamato-Security/hayabusa/pull/281#discussion_r767286731
* fixed output by level #278 #284
- fixed result counting process when rule has no aggregation condition #278
- added total output by level #284
* removed unnecessary crate
* fixed output #284
* removed unnecessary total/unique sum process #284
* add testcase and fix testcase bug
* add testcase, add check to check_cout()
* fixed count logic #278
* fixed test parameter
* add testcase
* fmt
* fixed count field check process #278
* fix testcase #281
* fixed comment typo
* removed one time used variable in test case #281
* fixed count field check process #278
* changed insert position #278
* changed contributor list
* fixed contributors list`
* passed with timeframe case #278
* passed all count test #278
* removed debug print
* removed debug print
* removed debug print
* cargo fmt
* changed by0level output format #284
* reduce clone() #278 #281
* changed for loop to map #278 #281
* fixed compile error
* changed priority from output in yml to aggregation output case aggregation condition exist in rule. #232
* fixed testcase #232
* changed if-let to generics #278 #281
* fixed error when test to sample_evtx#278 #281
* changed if-let to generic #278 #281
* adjust unwrap none error #278 #281
* fixed compile error and test case failed #278
Co-authored-by: ichiichi11 <takai.wa.hajime@gmail.com >
2021-12-19 20:48:29 +09:00
Yamato Security
a023ba46a6
Usage menu update ( #302 )
...
* Usage menu update
* usage menuの微調整
* fixed options #302
- changed show-deprecated to enable-deprecated-rules
- changed csv-timeline to output
- change show-noisyalerts to enable-noisy-rules
* fixed option #302
- changed starttimeline to start-timeline
* fixed option #302
- changed q to quiet option
* fixed options #302
- changed endtimeline to end-timeline option
- changed threadnum to thread-number option
Co-authored-by: DustInDark <nextsasasa@gmail.com >
2021-12-19 20:03:39 +09:00
DustInDark
a1c3bd0596
Merge branch 'main' into feature/output_errorlog#301
2021-12-19 16:46:54 +09:00
DustInDark
97b12fc068
fixed logic #301
2021-12-19 16:43:35 +09:00
DustInDark
692fdae9a0
RevertedMerge: Feature/remove process speed#289 ( #299 )
...
* removed process-speed view in progress bar #289
* insert changed code after resolve conflict #289
2021-12-19 15:36:24 +09:00
DustInDark
55c05c6d38
adjusted alert function arg add #301
2021-12-19 13:56:34 +09:00
DustInDark
7e00ab00fe
added output alert message to error file #391
2021-12-19 13:55:03 +09:00
James Takai / hach1yon
cbbcb4c068
Feature/re tuning and bugfix for regexes keyword ( #293 )
...
* re-tuning
* not effective
* re-tuning
* set key
* fix bug and fix testcase.
* fmt
2021-12-18 11:13:51 +09:00
DustInDark
17b6b97aa3
Revert "removed process-speed view in progress bar #289 ( #292 )" ( #298 )
...
This reverts commit 2626ef8e49 .
2021-12-18 11:12:28 +09:00
DustInDark
2626ef8e49
removed process-speed view in progress bar #289 ( #292 )
2021-12-18 11:06:45 +09:00
itiB
05076e4fec
Merge branch 'main' into feature/start_finish_time
2021-12-16 20:12:01 +09:00
James Takai / hach1yon
fd200c54b0
tuning ( #280 )
...
* remove unnecessary to_string
* remove unnecessary RWLock
* change hashmap crate
* remove unneccesarry to_string
* fmt
* remove rustc warning
* remove unnecessary to_string
* remove unnecessary comment
* remove unused functions
* remove unneccesary code.
* change compile option
* fmt
* remove unneccesarry split
* fmt
* remove unneccesary Option
2021-12-14 16:57:49 +09:00
DustInDark
3fae98934b
Feature/change level option#250 ( #259 )
...
* fixed level option #250
* changed output
2021-12-13 01:52:21 +09:00
itiB
906319bae5
Merge branch 'main' into feature/start_finish_time
2021-12-11 15:30:22 +09:00
James Takai / hach1yon
d3574134f7
fix max record number ( #279 )
2021-12-11 01:45:47 +09:00
kazuminn
a00a114101
refactor : rename variables and fix typo and add test ( #270 )
2021-12-10 23:01:47 +09:00
Yamato Security
5da9dc748f
Merge pull request #248 from Yamato-Security/feature/fill_no_use_rules
...
feature : exclude rules by their ID in case of duplicates, etc...
2021-12-09 06:41:15 +09:00
kazuminn
b9831ca38a
add test for exclude rules
2021-12-09 00:57:40 +09:00
DustInDark
493c5ddec1
Trivia/eastereggs#212 ( #266 )
...
* add ninja arts #212
* add takoyakiday eggs #212
* add christmas eggs #212
* add happy newyear eggs #212
* changed encode from UTF-8 BOM to UTF-8
* add output easteregg #212
- changed analysis datetime from Utc to Local
- added output easteregg #213
* changed happynewyear arts #212
* fix ninja day #212
* fix christmas #212
2021-12-07 01:52:27 +09:00
itiB
a1ec06cc6c
rm: comments
2021-12-07 00:52:57 +09:00
itiB
4bb445d4f5
Add: time filter
2021-12-07 00:50:00 +09:00
itiB
cc7697a319
Merge branch 'main' into feature/start_finish_time
2021-12-06 23:07:08 +09:00
James Takai / hach1yon
2222211ccd
Merge branch 'main' into feature/fill_no_use_rules
2021-12-04 19:31:35 +09:00
ichiichi11
191d1df9f0
add exclude files and fix bugs.
2021-12-04 19:23:50 +09:00
ichiichi11
9169214553
fix bug.
2021-12-04 19:09:41 +09:00
ichiichi11
c961c3768c
change from hashmap to hashset and remove unnecessary copy.
2021-12-04 18:46:11 +09:00
DustInDark
8b9dac961a
added progress bar #199 ( #247 )
2021-12-03 10:12:31 +09:00
kazuminn
446e540d6f
merge main into feature/fill_no_use_rules
2021-12-02 00:49:54 +09:00
kazuminn
838a935d34
pass test
2021-12-02 00:33:19 +09:00
kazuminn
341a5e4f86
feature fillter no use rules
2021-11-30 22:54:36 +09:00
James Takai / hach1yon
2febaa9b73
add target event filtering. ( #242 )
2021-11-28 19:02:27 +09:00
DustInDark
84f17323da
Hotfix/load rule level changed info to informational#237#238 ( #240 )
...
* changed INFO to informational #237
- INFO in rule level is changed to informational
* changed level load default rule from LOW to INFORMATIONAL #238
* fixed level description in doc and help menu #238
* removed test files
* removed test check file
2021-11-28 18:27:58 +09:00
Yamato Security
bc230f7cd5
英語修正 ( #236 )
...
* 英語修正
* cargo fmt
* fixed test assertion string data
Co-authored-by: DustInDark <nextsasasa@gmail.com >
2021-11-27 11:21:55 +09:00
DustInDark
b48f774b93
Feature/output unique detection#209 ( #225 )
...
* checked contributors #141
- because RustyBlue code contributor(not hayabusa contributor) was mixed in hayabusa contributor
* changed yaml count name
* changed ruletype string #157
* fixed output of parse error #157
* fixed output
* added level unique detection output #209
2021-11-24 21:15:43 +09:00
itiB
b2692ef983
Add: input function for start/end option
2021-11-24 00:09:41 +09:00
itiB
034f9c0957
Add: sigma rules ( #175 )
2021-11-22 08:45:44 +09:00
DustInDark
b53342218c
Feature/output logo#206 ( #222 )
...
* add output logo #206
* added newline and orgnization name #206
* add output rule count #200
* Changed yml summarize the totals for each folder hierarchy. #157
* added analyzing evtx file count output #157
* added loaded rule count output #157
* added quiet option #206
2021-11-21 15:16:44 +09:00
DustInDark
86321a4502
Feature/output read rule directory#201 ( #221 )
...
* fixed filepath evtx extension #162
* added rules option to config usage #201
* fixed filepath evtx extension rule #162
* added rules directory read feature #201
* added test case #201
* fixed usage set #201
* removed all check rule #201
* fixed rule read function data #201
2021-11-20 14:01:50 +09:00
DustInDark
199a8231c1
v1.0でリリースしない機能の削除、contributorsの表示、levelオプションのデフォルト値修正 #141 #211 ( #218 )
...
* changed default level to Low #211
* fixed usage #211
* erased Lang option #195
* changed output credit to contributors #141
* Removed contributor information for uncreated features and features that will not be introduced in v1.0. #141
* removed slack notification feature #202
- removed config option
- removed artifact slack notification call
* removed description of slack notification #202
* fixed default level to Low #211
* removed description about slack notification #202
2021-11-20 09:56:59 +09:00
DustInDark
e2ac686c3f
Feature/verbose output rule and file#188 ( #219 )
...
* added verbose output rule and evtx path #188
* fixed typo
* changed yaml read error to warn message #188
- added AlertMessage::warn
- yaml read error changed from error to warn
2021-11-20 09:10:17 +09:00
James
22c8302c4c
change from stdout to stderr. ( #190 )
2021-11-12 13:21:14 +09:00
DustInDark
66b8f2de9e
Feature/risk level condition#45 ( #186 )
...
* add risk level filter arguments #45
* fix default level in help #45
* add test yaml files #45
* refactoring and fix level argument usage.
* cargo fmt --all
Co-authored-by: ichiichi11 <takai.wa.hajime@gmail.com >
2021-11-11 23:47:29 +09:00
DustInDark
be04a0410e
Hotfix/hidden file read159 ( #180 )
...
* added error output of no evtx extension in filepath and directory args #159
* fixed error of hidden file read #159
- file extension is limited to yml when load of rule
* fix for no extension rule file.
Co-authored-by: ichiichi11 <takai.wa.hajime@gmail.com >
2021-11-10 22:55:20 +09:00
DustInDark
b278f12cec
Feature/output elapsedtime153 ( #172 )
...
* add output process count of detects events #151
* add output process count of detects event when output stdio #151
* add format enter
* add output elapsed time #153
* fixed output position #153
2021-11-10 19:38:04 +09:00
James
1bdf6943ff
update ( #171 )
2021-11-09 00:50:15 +09:00