Commit Graph

867 Commits

Author SHA1 Message Date
Yamato Security
631496cf41 Update contributors.txt 2022-03-03 08:54:16 +09:00
Alan Smithee
6694b9b4d5 Merge branch 'main' into develop 2022-03-02 20:19:27 +09:00
Yamato Security
cf4bdd00c7 Merge pull request #435 from Yamato-Security/readme-update---32bit-cross-compile-add
Readme update  32bit cross compile add
2022-03-02 19:16:32 +09:00
Alan Smithee
d498d3114b Merge branch 'readme-update---32bit-cross-compile-add' of github.com:Yamato-Security/hayabusa into readme-update---32bit-cross-compile-add 2022-03-02 18:29:31 +09:00
Alan Smithee
5d4c465bcc fixed janapese usage readme 2022-03-02 18:28:44 +09:00
Alan Smithee
b43f41e7f2 fixed command option in usage
- UTC option is changed from -u to -U
- Run onlive Windows machine is adjusted -l (--live-analysis)
2022-03-02 18:21:55 +09:00
Tanaka Zakku
7bc845ea81 cross compile command fix 2022-03-02 18:14:28 +09:00
Tanaka Zakku
5fdcd40179 usage update 2022-03-02 17:02:19 +09:00
Tanaka Zakku
4572bb98f4 add linux compile comment 2022-03-02 16:19:25 +09:00
Tanaka Zakku
02628526ec use standard cargo build to compile 2022-03-02 13:34:33 +09:00
Tanaka Zakku
bd4f433b73 readme update - 32bit compile add 2022-03-02 10:13:45 +09:00
Yamato Security
f183c4352f Merge pull request #433 from Yamato-Security/hotfix/failed_twice_update_rule#432
Hotfix/failed twice update rule#432
2022-03-01 08:19:33 +09:00
Alan Smithee
0fdabf0d70 added process of remove submodule cache #432 2022-03-01 03:17:55 +09:00
Alan Smithee
6e5b24282f cargo fmt 2022-02-28 18:27:06 +09:00
Alan Smithee
c3c9423b74 fixed clippy warn 2022-02-28 18:25:54 +09:00
Alan Smithee
28ded269de fixed process case of not exist hayabusa .git folder #432 2022-02-28 18:24:49 +09:00
Yamato Security
b0434726ca readme update mac compile error (#431) 2022-02-28 15:23:32 +09:00
Yamato Security
65eb818f9b unique rules to detections (#426) 2022-02-28 10:16:39 +09:00
Yamato Security
087529ee91 readme update-RuleDocToHayabusRulesRepo BugSub (#427) 2022-02-28 10:14:27 +09:00
Yamato Security
1cd3680a3a Merge pull request #424 from Yamato-Security/hotfix/not_update_submodule_update#422
Hotfix/not update submodule update#422
2022-02-28 06:24:22 +09:00
Alan Smithee
b22798fddd added merge process when submodule update option #422 2022-02-27 21:04:33 +09:00
Alan Smithee
d1553e3ab1 changed crate load together 2022-02-27 21:02:43 +09:00
DustInDark
dc8d7f3522 Update issue templates #419 (#423)
* Update issue templates #419

Added bug report template

* removed unnecessary bug report #419
2022-02-27 12:25:49 +09:00
Yamato Security
fb007ee3a6 Small edits on help screen. (#417) 2022-02-27 09:04:30 +09:00
Yamato Security
5022e38b83 Added CHANGELOG (#418) 2022-02-27 08:59:10 +09:00
DustInDark
92c472d451 Hotfix/moved rule configs to hayabusa rules repo#409 (#414)
* fixed target config path #409

* fixed target config file path in test #409

* fixed rules target #409

* Documentation fix, deleted unneeded config files

* added workflow

* changed submodule option

* fixed worksflow to ref submodule

* fixed gitmodules

* fixed workflow

* check code insert

* added update submodules command

* test rules update

* removed test runs

* fixed error

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-26 18:19:19 +09:00
DustInDark
02b1d7f07c added update command #391 (#392)
* add git2 crate #391

* added Update option #391

* updated readme #391

* fixed cargo.lock

* fixed option if-statement #391

* changed utc short option and rule-update short option #391

* updated readme

* updated readme

* fixed -u long option & version number update #391

* added fast-forwarding rules repository #391

* updated command line option #391

* moved output logo prev update rule

* fixed readme #391

* removed recursive option in readme

* English message update.

* cargo fmt

* Added update command#391 submodule ver (#401)

* changed rules update from clone and pull to submodule update #391

* fixed document

* changed unnecessary clone recursively to clone only

* English message update. ( 4657c35e5c cherry-pick)

* added create rules folder when rules folder is not exist

* fixed gitmodules github-rules url from ssh to https

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>

* added caution case of update failed in readme #391

* fixed document

* added output error in case of loaded rule count is 0  #391 #392

 https://github.com/Yamato-Security/hayabusa/pull/392#issuecomment-1050276570

* --update-rules typo

* removed unused library call

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-26 18:18:03 +09:00
DustInDark
568ce6764c Document/describe wildcard is case insensitive#411 (#415)
* describe case-sensitive when use startswith,endswith,contains,re to
aboutrulecreation-japanese #411

* describe case-insensitive when not use startswith,endswith,contains,re to aboutrulecreation #411

* slight wording update

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-25 20:16:19 +09:00
DustInDark
0dc5de4b73 Bug/ Fixed error when target environment is not installed vcc redistribute package (#408)
* fixed error when target environment has not installed vcc redistribute package

* added cfg to static_vcruntime when target os is windows.
2022-02-25 10:07:12 +09:00
DustInDark
a04b63662c Bugfix/fixed alias to no detect rename binary rule (#406)
* added OriginalFileName alias #405

* removed not exist tag in sigma rule(OriginalFilename)

* fixed typo
2022-02-22 23:17:48 +09:00
Yamato Security
191acef8fe Merge pull request #403 from Yamato-Security/enhancement/config-update
Update config files
2022-02-22 18:20:42 +09:00
Alan Smithee
f9b02a65b6 fixed test to change regex detectlist_suspicous_services.txt 2022-02-22 08:42:23 +09:00
Tanaka Zakku
0260a223fd Update config files 2022-02-21 17:07:47 +09:00
itiB
4abbb24117 Merge pull request #400 from Yamato-Security/document/add-contents-table
Add: Table of Contents to README
2022-02-17 19:59:57 +09:00
DustInDark
58017e971f fixed detection lack when tab and enter control character in event record#395 (#396)
* fixed no detected bug when enter and tab control character in record data #395

* added remove \r \n \t character in utils.rs
* added call of utils.rs function in selectionnodes.rs

* added tests #395

* changed space control character function args #395

* fixed test due to function args changes #395

* changed replace method using regex #395

* changed regex by record_data_filter.txt #395

* added record_data_filter.txt #395

* fixed test #395

* added record_data_filter

- add Properties regex
- add ScriptBlockText regex
- add Payload regex
2022-02-17 05:07:15 +09:00
itiB
47c1d42daf Add: Table of Contents to README 2022-02-17 00:19:17 +09:00
DustInDark
0a559da580 Fixed Readme (#399)
* add shields to README-Japanese.md

* replaced README.md to README-English.md

* fixed tags url ref

* fixed reference typo

* fixed hayabusa logo view size

* fixed readme
2022-02-16 09:28:52 +09:00
DustInDark
19c44b4f66 added mitre attack data output in csv output (#397)
* added tags information in csv output #234

* fixed test due to change csvformat struct #234

* changed tag info separator #234

* changed separator #234

* changed tag info separator #234
2022-02-15 02:13:37 +09:00
DustInDark
df86958850 added live analysys feature (#398)
* added windows live analysis option #125

* added live analysis option #125

* fixed live analysys condition #125

* changed live analysis option #125

* added live-analysis option in readme #125

* fixed live-analysis check condition #125

* is_elevated crate is only windows #125

* fixed is_elevated build error #125

* fixed is_elevated library crate load

* fixed call way os dependencies crate #125

* fix build error on linux and removed unnecessary create #125

* fixed lack of load crate when build at windows #125

* Update error message

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-15 02:12:45 +09:00
DustInDark
9cb54a9192 Hotfix/no output colorcode in no true color#376 (#378)
* added color code emit_csv test

* replaced HashMap and HashSet to hashbrown #368

* removed debug output in test #368

* added color option #376

* fixed process of output check #376

* removed color output check from test #376

* english updates

* colored detections and rules count output by level #384

* refactoring in colored output process #384

* update usage #364 #376

* fixed markdown lint

* added windows terminal bug evasion way #382

* update readme

* fixed colored output test

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-09 09:29:36 +09:00
DustInDark
df30adfdef changed hashmap library to tuneup #368 (#369)
* added color code emit_csv test

* replaced HashMap and HashSet to hashbrown #368

* removed debug output in test #368

* fixed colored test
2022-02-09 01:59:39 +09:00
DustInDark
84de8d01af remove yaml ignore check#271 (#385)
* removed yaml ignore label check #271

* moved exclude rule filter check #271

* fixed colored test
2022-02-09 01:59:12 +09:00
Yamato Security
fbe40a90c7 Merge pull request #389 from Yamato-Security/enhancement/enable-fast-alloc
enabled fast-alloc
2022-02-03 08:43:03 +09:00
Tanaka Zakku
2fd63283f1 enabled fast-alloc 2022-02-02 20:32:17 +09:00
kazuminn
d1597b2322 ルール場所指定オプションでファイルを扱えるようにする (#364)
* add only rule file path in --rules

* add error handling for metadata

* refactor

* add test

* rename test function
2022-01-31 12:09:25 +09:00
Yamato Security
c1abb2d900 Merge pull request #383 from Yamato-Security/feature/remove_csv_encode_stdoutput#381
removed csv quote when output result to stdout #381
2022-01-30 17:38:23 +09:00
Yamato Security
ee05856181 Merge pull request #380 from Yamato-Security/main-readme-update
readme update
2022-01-30 17:28:50 +09:00
Alan Smithee
f70be3419a removed csv quote when output result to stdout #381 2022-01-30 13:23:33 +09:00
Tanaka Zakku
72864031cd readme update 2022-01-30 11:50:32 +09:00
Yamato Security
bbed0f1159 Merge pull request #379 from Yamato-Security/update-readme
Update-readme
2022-01-30 09:28:00 +09:00