Commit Graph

524 Commits

Author SHA1 Message Date
DustInDark
a04b63662c Bugfix/fixed alias to no detect rename binary rule (#406)
* added OriginalFileName alias #405

* removed not exist tag in sigma rule(OriginalFilename)

* fixed typo
2022-02-22 23:17:48 +09:00
Yamato Security
191acef8fe Merge pull request #403 from Yamato-Security/enhancement/config-update
Update config files
2022-02-22 18:20:42 +09:00
Alan Smithee
f9b02a65b6 fixed test to change regex detectlist_suspicous_services.txt 2022-02-22 08:42:23 +09:00
Tanaka Zakku
0260a223fd Update config files 2022-02-21 17:07:47 +09:00
itiB
4abbb24117 Merge pull request #400 from Yamato-Security/document/add-contents-table
Add: Table of Contents to README
2022-02-17 19:59:57 +09:00
DustInDark
58017e971f fixed detection lack when tab and enter control character in event record#395 (#396)
* fixed no detected bug when enter and tab control character in record data #395

* added remove \r \n \t character in utils.rs
* added call of utils.rs function in selectionnodes.rs

* added tests #395

* changed space control character function args #395

* fixed test due to function args changes #395

* changed replace method using regex #395

* changed regex by record_data_filter.txt #395

* added record_data_filter.txt #395

* fixed test #395

* added record_data_filter

- add Properties regex
- add ScriptBlockText regex
- add Payload regex
2022-02-17 05:07:15 +09:00
itiB
47c1d42daf Add: Table of Contents to README 2022-02-17 00:19:17 +09:00
DustInDark
0a559da580 Fixed Readme (#399)
* add shields to README-Japanese.md

* replaced README.md to README-English.md

* fixed tags url ref

* fixed reference typo

* fixed hayabusa logo view size

* fixed readme
2022-02-16 09:28:52 +09:00
DustInDark
19c44b4f66 added mitre attack data output in csv output (#397)
* added tags information in csv output #234

* fixed test due to change csvformat struct #234

* changed tag info separator #234

* changed separator #234

* changed tag info separator #234
2022-02-15 02:13:37 +09:00
DustInDark
df86958850 added live analysys feature (#398)
* added windows live analysis option #125

* added live analysis option #125

* fixed live analysys condition #125

* changed live analysis option #125

* added live-analysis option in readme #125

* fixed live-analysis check condition #125

* is_elevated crate is only windows #125

* fixed is_elevated build error #125

* fixed is_elevated library crate load

* fixed call way os dependencies crate #125

* fix build error on linux and removed unnecessary create #125

* fixed lack of load crate when build at windows #125

* Update error message

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-15 02:12:45 +09:00
DustInDark
9cb54a9192 Hotfix/no output colorcode in no true color#376 (#378)
* added color code emit_csv test

* replaced HashMap and HashSet to hashbrown #368

* removed debug output in test #368

* added color option #376

* fixed process of output check #376

* removed color output check from test #376

* english updates

* colored detections and rules count output by level #384

* refactoring in colored output process #384

* update usage #364 #376

* fixed markdown lint

* added windows terminal bug evasion way #382

* update readme

* fixed colored output test

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-09 09:29:36 +09:00
DustInDark
df30adfdef changed hashmap library to tuneup #368 (#369)
* added color code emit_csv test

* replaced HashMap and HashSet to hashbrown #368

* removed debug output in test #368

* fixed colored test
2022-02-09 01:59:39 +09:00
DustInDark
84de8d01af remove yaml ignore check#271 (#385)
* removed yaml ignore label check #271

* moved exclude rule filter check #271

* fixed colored test
2022-02-09 01:59:12 +09:00
Yamato Security
fbe40a90c7 Merge pull request #389 from Yamato-Security/enhancement/enable-fast-alloc
enabled fast-alloc
2022-02-03 08:43:03 +09:00
Tanaka Zakku
2fd63283f1 enabled fast-alloc 2022-02-02 20:32:17 +09:00
kazuminn
d1597b2322 ルール場所指定オプションでファイルを扱えるようにする (#364)
* add only rule file path in --rules

* add error handling for metadata

* refactor

* add test

* rename test function
2022-01-31 12:09:25 +09:00
Yamato Security
c1abb2d900 Merge pull request #383 from Yamato-Security/feature/remove_csv_encode_stdoutput#381
removed csv quote when output result to stdout #381
2022-01-30 17:38:23 +09:00
Alan Smithee
f70be3419a removed csv quote when output result to stdout #381 2022-01-30 13:23:33 +09:00
Yamato Security
bbed0f1159 Merge pull request #379 from Yamato-Security/update-readme
Update-readme
2022-01-30 09:28:00 +09:00
Tanaka Zakku
a992a58497 readme update 2022-01-30 09:26:34 +09:00
Tanaka Zakku
c9bb43eb37 readme update 2022-01-30 09:22:17 +09:00
Tanaka Zakku
6bf4b59c6a readme update 2022-01-30 09:20:52 +09:00
Tanaka Zakku
3f8cf756c1 readme update 2022-01-30 09:16:20 +09:00
Tanaka Zakku
10858d574f update readme 2022-01-29 17:01:44 +09:00
Yamato Security
6828f80fe9 Merge pull request #377 from Yamato-Security/Delete-AV-detected-xls-files
Delete-AV-detected-xls-files
2022-01-28 18:25:16 +09:00
Tanaka Zakku
d2108f4e49 Deleted AV detected xls files 2022-01-28 18:01:15 +09:00
Yamato Security
c0466b1af3 Merge pull request #374 from Yamato-Security/updated-cargo-packages
Updated-cargo-packages
2022-01-28 17:38:50 +09:00
Tanaka Zakku
1bdc3b22f4 updated cargo packages 2022-01-28 15:36:49 +09:00
Yamato Security
90ca2cdbbd Merge pull request #371 from Yamato-Security/hotfix/error_after_cargo_update#370
specified clap version specified #370
2022-01-28 07:41:30 +09:00
Alan Smithee
957c0b09d3 specified clap version specified #370 2022-01-27 20:34:58 +09:00
DustInDark
b12029de5c Feature/colorlog#239 (#365)
* added color carete #239

* added hex library

* added color config file parser #239

* added color output feature #239

* changed fast hashmap library

* added color output description(Japanese) #239

* added color output description(English) #239

* fixed medium level typo

* removed white color font level #239

* added trim and loose colorcode condition #239

* fixed hex convert error panic #239

- output warn and go next iterator when happen hex convert panic

- added user input in hex convert warn output to use easily
2022-01-26 01:39:14 +09:00
kazuminn
15ee980711 exclude-rules.txtとnoisy-rules.txtをコメントに対応 (#362)
* add exclude files comments feature

* trim()

* add error handling and split function

* add id validation

* add comments

* cargo fmt

* fix error statment

* change -full.txt to .txt

* change alert to warn
2022-01-20 23:12:41 +09:00
itiB
2db8ff9f9a Merge pull request #360 from Yamato-Security/feature/separate_rules2submodule
make rule files to submodule #295
2022-01-20 00:19:25 +09:00
itiB
41910c0813 Update: README for submodule 2022-01-14 00:33:43 +09:00
itiB
f5afc0e488 Add: hayabusa-rules for submodule 2022-01-14 00:10:21 +09:00
itiB
8200e3482d rm: rule file from hayabusa branch 2022-01-14 00:09:01 +09:00
DustInDark
9c7353a2e9 Feature/except hidden file#335 (#339)
* added except hidden file load #335

* fixed except hidden file in collect evtx #335
2022-01-13 22:19:59 +09:00
Yamato Security
3e4660622c Merge pull request #354 from Yamato-Security/fix/typo
fix typo link
2021-12-25 19:17:09 +09:00
kazuminn
4ae2e196f1 fix typo link 2021-12-25 18:55:13 +09:00
Yamato Security
19f859e16e Merge pull request #353 from Yamato-Security/fix/rename-file
ドキュメントでの画像のリンク切れが発生していたのでファイル名変更で対応
2021-12-25 17:48:21 +09:00
Alan Smithee
97aa15078e renamed screenshot 2021-12-25 17:32:39 +09:00
Yamato Security
5cc94060e7 Merge pull request #351 from Yamato-Security/fix-broken-image-link-add-csv-timeline-analysis-pdfs
fix image broken link and add PDFs
2021-12-25 17:22:49 +09:00
Tanaka Zakku
0d48b12b23 fix japanese pdf link 2021-12-25 17:18:01 +09:00
Tanaka Zakku
dd2acfc061 fix image broken link and add PDFs 2021-12-25 16:58:15 +09:00
Yamato Security
fddcbc7e7d Merge pull request #350 from Yamato-Security/feature/fix_for_releasev1.0
Feature/fix for releasev1.0
v1.0.0
2021-12-25 10:38:05 +09:00
Tanaka Zakku
edd37039de readme fix 2021-12-25 10:36:41 +09:00
James Takai / hach1yon
182c1f1dfd change readme 2021-12-25 10:29:52 +09:00
James Takai / hach1yon
b4e34f8d31 update readme 2021-12-25 10:17:42 +09:00
James Takai / hach1yon
474ed513b1 readmeを色々修正 (#346)
* 色々修正

* ちょっと修正

* fix camelcase

* fix

* little fix

* fix

* Added section on running from bin directory

* fix jp

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2021-12-25 09:29:06 +09:00
Tanaka Zakku
d9624be752 delete extra white space 2021-12-24 14:56:23 +09:00