Commit Graph

867 Commits

Author SHA1 Message Date
kazuminn
c8efa95447 Pivot Keyword List機能の追加 (#412)
* add get_pivot_keyword() func

* change function name and call it's function

* [WIP] support config file

* compilete output

* cargo fmt

* [WIP] add test

* add test

* support -o option in pivot

* add pivot mod

* fix miss

* pass test in pivot.rs

* add comment

* pass all test

* add fast return

* fix output

* add test config file

* review

* rebase

* cargo fmt

* test pass

* fix clippy in my commit

* cargo fmt

* little refactor

* change file input logic and config format

* [WIP] change output

* [wip] change deta structure

* change output & change data structure

* pass test

* add config

* cargo fmt & clippy & rebase

* fix cllipy

* delete /rules/ in .gitignore

* clean comment

* clean

* clean

* fix rebase miss

* fix rebase miss

* fix clippy

* file name output on -o to stdout

* add pivot_keywords.txt to ./config

* updated english

* Documentation update

* cargo fmt and clean

* updated translate japanese

* readme update

* readme update

Co-authored-by: DustInDark <nextsasasa@gmail.com>
Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-04-05 21:17:23 +09:00
itiB
90822aa563 Cargo fmt 2022-04-05 02:04:10 +09:00
itiB
9f8f12ec2f fix: level tuning's file name 2022-04-05 02:03:49 +09:00
itiB
015691e129 mv: IDS_REGEX to configs file 2022-04-05 01:59:56 +09:00
itiB
373dd0f8c7 Add: id, level validation 2022-04-05 01:53:24 +09:00
itiB
026d18a605 Add: Error handlings 2022-04-05 01:30:11 +09:00
itiB
6b08752120 Fix: Text overwrite was failed 2022-04-04 23:44:54 +09:00
itiB
5891a1aca1 WIP: Text overwrite failed... 2022-04-04 01:44:04 +09:00
itiB
6805bd6a0a Reface: split to options file 2022-04-04 00:31:21 +09:00
itiB
9149500b40 Add: level-tuning function 2022-04-03 23:41:32 +09:00
itiB
814f5a61cb cargo fmt 2022-04-03 22:01:40 +09:00
itiB
d38834e20e Add: input rule_level.txt files & read rules 2022-04-03 21:58:33 +09:00
itiB
a15bef4b30 Add: read Rule files 2022-04-03 21:58:33 +09:00
itiB
276889338d Add: --level-tuning option's outline 2022-04-03 21:57:50 +09:00
Yamato Security
545119bdfe Merge pull request #476 from Yamato-Security/bugfix/exculde_load_yml_in_git_folder#472
[Bugfix] exculde load yml in git folder#472
2022-03-31 03:22:07 +09:00
DustInDark
7c645010ee fixed process when yml file exist in .git folder
* ignore when yml file exist in .git folder
2022-03-30 21:02:14 +09:00
Yamato Security
66ac9dd00b Merge pull request #474 from Yamato-Security/update/rules_submodule_main
updated rules submodule(To main branch)
2022-03-30 20:54:23 +09:00
Yamato Security
c8e86c1c20 Merge pull request #475 from Yamato-Security/update/rules_submodule_develop
updated rules submodule(To develop branch)
2022-03-30 20:53:52 +09:00
DustInDark
2b8ee9e41c updated rules submodule: 2022-03-30 20:42:13 +09:00
DustInDark
230a481eaf updated rules submodule 2022-03-30 20:39:46 +09:00
DustInDark
425a629de7 Enhancement: add config config #456 (#471)
* added config option #456

* added process of option to speicifed config folder #456

following files adjust config option.

* noisy_rules.txt

* exclude_rules.txt

* fixed usage in readme
2022-03-30 15:26:58 +09:00
James / hach1yon
bca578b89e add equalsfield pipe (#467) 2022-03-30 11:49:20 +09:00
garigariganzy
7861174a93 Remove unnecessary code from timeline_event_info and rename files for… (#470)
* Remove unnecessary code from timeline_event_info and rename files for issue462

* Remove unnecessary code #462
2022-03-30 09:46:18 +09:00
DustInDark
fa86a9a027 Fearture/ added output update result#410 (#452)
* add git2 crate #391

* added Update option #391

* updated readme #391

* fixed cargo.lock

* fixed option if-statement #391

* changed utc short option and rule-update short option #391

* updated readme

* updated readme

* fixed -u long option & version number update #391

* added fast-forwarding rules repository #391

* updated command line option #391

* moved output logo prev update rule

* fixed readme #391

* removed recursive option in readme

* changed rules update from clone and pull to submodule update #391

* fixed document

* changed unnecessary clone recursively to clone only

* English message update.

* cargo fmt

* English message update. ( 4657c35e5c cherry-pick)

* added create rules folder when rules folder is not exist

* fixed gitmodules github-rules url from ssh to https

* added output of updated file #420

* fixed error #410

* changed update rule list seq

* added test

* fixed output #410

* fixed output and fixed output date field  when  modified field is lacked #410

* fixed compile error

* fixed output

- added enter after Latest rule update output
- added output when no exist new rule
- fixed Latest rule update date format
- changed output from 'Latest rule update' to 'Latest rules update'

* fixed compile error

* changed modified date source from rules folder to each yml rule file

* formatting use chrono in main.rs

* merge develop clippy ci

* fixed output when no update rule #410

- removed Latest rule update

- no output "Rules update successfully" when No rule changed

* Change English

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-03-29 13:09:54 +09:00
James / hach1yon
67cf88cddd fix degrade for pull req #464 (#468)
* fix degrade for pull req #464

* add trim
2022-03-27 22:26:42 +09:00
Yamato Security
b3476f6ad5 Merge pull request #466 from Yamato-Security/rule_submodule_update_main
Updated rule submodule in main branch
2022-03-26 19:14:05 +09:00
Yamato Security
e372605de6 Merge pull request #465 from Yamato-Security/rule_submodule_update
Updated rule submodule in develop branch
2022-03-26 19:13:43 +09:00
DustInDark
9b058bcbdc updated submodule 2022-03-26 18:13:38 +09:00
DustInDark
6e555f0832 updated submodule 2022-03-26 18:05:15 +09:00
James / hach1yon
b0e4247857 Feature/#440 refactoring #395 (#464) 2022-03-26 16:11:11 +09:00
Yamato Security
5e14263272 statistics event id update (#457) 2022-03-22 19:01:32 +09:00
DustInDark
e563224b52 added clippy workflow #428 (#429)
* added clippy workflow #428

* fixed action yaml to run clippy #428

* fixed indent

* fixed workflow

* fixed workflow error

* fixed indent

* changed no annotation #428

* adujusted annotation version

* fixed clippy::needless_match

* remove if let exception

* removed unnecessary permission check #428
2022-03-21 12:45:30 +09:00
Yamato Security
dae322cc8d Merge pull request #455 from Yamato-Security/documentation/addMacUsageEtc
readmeの更新
2022-03-19 17:32:45 +09:00
Tanaka Zakku
5f570b9e0d update 2022-03-19 13:41:01 +09:00
Tanaka Zakku
6f83a09c1f documentation update macOS usage etc 2022-03-19 13:08:20 +09:00
Yamato Security
50d0bf2c98 Merge pull request #454 from Yamato-Security/document/add_badges#453
Document/add badges#453
2022-03-18 17:00:38 +09:00
DustInDark
d57c7587f4 added repository maintenance levels badge #453 2022-03-17 18:41:24 +09:00
DustInDark
5b3c3bc47f added rust report card badges #453 2022-03-17 18:38:43 +09:00
DustInDark
e309e87e0d added temporary blackhat arsenal badge 2022-03-17 18:32:30 +09:00
DustInDark
7c7a86f7c9 Fixed Clippy Warnings (#451)
* fixed clippy warn

* fixed cargo clippy warnging

* fixed clippy warngings in clippy ver 0.1.59

* fixed clippy warnings clippy::unnecessary_to_owned
2022-03-17 08:43:48 +09:00
DustInDark
04b881cb66 changed downcast library from mopa to downcast_rs #447 (#450) 2022-03-11 14:49:47 +09:00
kazuminn
d49d6f6210 aliasキーがない場合もEvent.EventDataを自動で走査する (#442)
* add no event key

* support not-register-alias search

* added checking EventData when key do not match in alias #290

- added checking key in Event.EventData, if key is not exist in eventkey_alias.txt.

* cargo fmt

* fixed panic when filter files does not exists

* fixed errorlog format when filter config files does not exist

Co-authored-by: DustInDark <nextsasasa@gmail.com>
2022-03-11 13:24:43 +09:00
Yamato Security
1e6e597330 Opensslを静的にコンパイルするためにCargo.tomlの設定変更 (#437)
* cargo update - openssl static

* updated cargo

* macos2apple

* cargo update

* cargo update
2022-03-10 21:04:07 +09:00
Yamato Security
6659576211 readme update screenshots etc (#448) 2022-03-10 11:24:39 +09:00
Yamato Security
af3550dd39 Merge pull request #446 from Yamato-Security/fix/fix_rules_submodule_commit
fixed rules submodule targe #444
2022-03-08 19:36:21 +09:00
Alan Smithee
3fa8faa97a fixed rules submodule targe #444 2022-03-08 18:10:38 +09:00
DustInDark
7d909a7438 Merge main and output fix#443#444 (#445)
* removed tools/sigmac (#441)

* removed tools/sigmac

- moved tools/sigmac to hayabusa-rules repo

* fixed doc link tools/sigmac

* fixed submodule track

* fixed submodule track from latest to v1.1.0 tag

* fixed link

* erased enter #444

* erased enter #444

* reverted logo enter

* fixed rules submodule target commit #444

Co-authored-by: Yamato Security <71482215+YamatoSecurity@users.noreply.github.com>
2022-03-08 17:55:11 +09:00
DustInDark
bb1f5f619d Fix/fix clippy warn (#434)
- Fixed following Clippy Warnings(previous warning count: 671 -> after: 4)
  - clippy::needless_return
  - clippy::println_empty_string
  - clippy::redundant_field_names
  - clippy::single_char_pattern
  - clippy::len_zero
  - clippy::iter_nth_zero
  - clippy::bool_comparison
  - clippy::question_mark
  - clippy::needless_collect
  - clippy::unnecessary_unwrap
  - clippy::ptr_arg
  - clippy::needless_collect
  - clippy::needless_borrow
  - clippy::new_without_default
  - clippy::assign_op_pattern
  - clippy::bool_assert_comparison
  - clippy::into_iter_on_ref
  - clippy::deref_addrof
  - clippy::while_let_on_iterator
  - clippy::match_like_matches_macro
  - clippy::or_fun_call
  - clippy::useless_conversion
  - clippy::let_and_return
  - clippy::redundant_clone
  - clippy::redundant_closure
  - clippy::cmp_owned
  - clippy::upper_case_acronyms
  - clippy::map_identity
  - clippy::unused_io_amount
  - clippy::assertions_on_constants
  - clippy::op_ref
  - clippy::useless_vec
  - clippy::vec_init_then_push
  - clippy::useless_format
  - clippy::bind_instead_of_map
  - clippy::bool_comparison
  - clippy::clone_on_copy
  - clippy::too_many_arguments
  - clippy::module_inception
  - fixed clippy::needless_lifetimes
  - fixed clippy::borrowed_box (Thanks for helping by hach1yon!)
2022-03-07 08:38:05 +09:00
DustInDark
b3cfedf4a5 removed tools/sigmac (#441)
* removed tools/sigmac

- moved tools/sigmac to hayabusa-rules repo

* fixed doc link tools/sigmac

* fixed submodule track

* fixed submodule track from latest to v1.1.0 tag

* fixed link
2022-03-05 22:26:22 +09:00
Yamato Security
db857f81af Merge pull request #425 from Yamato-Security/develop
v1.1.0 Release
v1.1.0
2022-03-03 09:09:48 +09:00