Commit Graph

696 Commits

Author SHA1 Message Date
Alan Smithee
d1553e3ab1 changed crate load together 2022-02-27 21:02:43 +09:00
DustInDark
dc8d7f3522 Update issue templates #419 (#423)
* Update issue templates #419

Added bug report template

* removed unnecessary bug report #419
2022-02-27 12:25:49 +09:00
Yamato Security
fb007ee3a6 Small edits on help screen. (#417) 2022-02-27 09:04:30 +09:00
Yamato Security
5022e38b83 Added CHANGELOG (#418) 2022-02-27 08:59:10 +09:00
DustInDark
92c472d451 Hotfix/moved rule configs to hayabusa rules repo#409 (#414)
* fixed target config path #409

* fixed target config file path in test #409

* fixed rules target #409

* Documentation fix, deleted unneeded config files

* added workflow

* changed submodule option

* fixed worksflow to ref submodule

* fixed gitmodules

* fixed workflow

* check code insert

* added update submodules command

* test rules update

* removed test runs

* fixed error

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-26 18:19:19 +09:00
DustInDark
02b1d7f07c added update command #391 (#392)
* add git2 crate #391

* added Update option #391

* updated readme #391

* fixed cargo.lock

* fixed option if-statement #391

* changed utc short option and rule-update short option #391

* updated readme

* updated readme

* fixed -u long option & version number update #391

* added fast-forwarding rules repository #391

* updated command line option #391

* moved output logo prev update rule

* fixed readme #391

* removed recursive option in readme

* English message update.

* cargo fmt

* Added update command#391 submodule ver (#401)

* changed rules update from clone and pull to submodule update #391

* fixed document

* changed unnecessary clone recursively to clone only

* English message update. ( 4657c35e5c cherry-pick)

* added create rules folder when rules folder is not exist

* fixed gitmodules github-rules url from ssh to https

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>

* added caution case of update failed in readme #391

* fixed document

* added output error in case of loaded rule count is 0  #391 #392

 https://github.com/Yamato-Security/hayabusa/pull/392#issuecomment-1050276570

* --update-rules typo

* removed unused library call

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-26 18:18:03 +09:00
DustInDark
568ce6764c Document/describe wildcard is case insensitive#411 (#415)
* describe case-sensitive when use startswith,endswith,contains,re to
aboutrulecreation-japanese #411

* describe case-insensitive when not use startswith,endswith,contains,re to aboutrulecreation #411

* slight wording update

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-25 20:16:19 +09:00
DustInDark
0dc5de4b73 Bug/ Fixed error when target environment is not installed vcc redistribute package (#408)
* fixed error when target environment has not installed vcc redistribute package

* added cfg to static_vcruntime when target os is windows.
2022-02-25 10:07:12 +09:00
DustInDark
a04b63662c Bugfix/fixed alias to no detect rename binary rule (#406)
* added OriginalFileName alias #405

* removed not exist tag in sigma rule(OriginalFilename)

* fixed typo
2022-02-22 23:17:48 +09:00
Yamato Security
191acef8fe Merge pull request #403 from Yamato-Security/enhancement/config-update
Update config files
2022-02-22 18:20:42 +09:00
Alan Smithee
f9b02a65b6 fixed test to change regex detectlist_suspicous_services.txt 2022-02-22 08:42:23 +09:00
Tanaka Zakku
0260a223fd Update config files 2022-02-21 17:07:47 +09:00
itiB
4abbb24117 Merge pull request #400 from Yamato-Security/document/add-contents-table
Add: Table of Contents to README
2022-02-17 19:59:57 +09:00
DustInDark
58017e971f fixed detection lack when tab and enter control character in event record#395 (#396)
* fixed no detected bug when enter and tab control character in record data #395

* added remove \r \n \t character in utils.rs
* added call of utils.rs function in selectionnodes.rs

* added tests #395

* changed space control character function args #395

* fixed test due to function args changes #395

* changed replace method using regex #395

* changed regex by record_data_filter.txt #395

* added record_data_filter.txt #395

* fixed test #395

* added record_data_filter

- add Properties regex
- add ScriptBlockText regex
- add Payload regex
2022-02-17 05:07:15 +09:00
itiB
47c1d42daf Add: Table of Contents to README 2022-02-17 00:19:17 +09:00
DustInDark
0a559da580 Fixed Readme (#399)
* add shields to README-Japanese.md

* replaced README.md to README-English.md

* fixed tags url ref

* fixed reference typo

* fixed hayabusa logo view size

* fixed readme
2022-02-16 09:28:52 +09:00
DustInDark
19c44b4f66 added mitre attack data output in csv output (#397)
* added tags information in csv output #234

* fixed test due to change csvformat struct #234

* changed tag info separator #234

* changed separator #234

* changed tag info separator #234
2022-02-15 02:13:37 +09:00
DustInDark
df86958850 added live analysys feature (#398)
* added windows live analysis option #125

* added live analysis option #125

* fixed live analysys condition #125

* changed live analysis option #125

* added live-analysis option in readme #125

* fixed live-analysis check condition #125

* is_elevated crate is only windows #125

* fixed is_elevated build error #125

* fixed is_elevated library crate load

* fixed call way os dependencies crate #125

* fix build error on linux and removed unnecessary create #125

* fixed lack of load crate when build at windows #125

* Update error message

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-15 02:12:45 +09:00
DustInDark
9cb54a9192 Hotfix/no output colorcode in no true color#376 (#378)
* added color code emit_csv test

* replaced HashMap and HashSet to hashbrown #368

* removed debug output in test #368

* added color option #376

* fixed process of output check #376

* removed color output check from test #376

* english updates

* colored detections and rules count output by level #384

* refactoring in colored output process #384

* update usage #364 #376

* fixed markdown lint

* added windows terminal bug evasion way #382

* update readme

* fixed colored output test

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-02-09 09:29:36 +09:00
DustInDark
df30adfdef changed hashmap library to tuneup #368 (#369)
* added color code emit_csv test

* replaced HashMap and HashSet to hashbrown #368

* removed debug output in test #368

* fixed colored test
2022-02-09 01:59:39 +09:00
DustInDark
84de8d01af remove yaml ignore check#271 (#385)
* removed yaml ignore label check #271

* moved exclude rule filter check #271

* fixed colored test
2022-02-09 01:59:12 +09:00
Yamato Security
fbe40a90c7 Merge pull request #389 from Yamato-Security/enhancement/enable-fast-alloc
enabled fast-alloc
2022-02-03 08:43:03 +09:00
Tanaka Zakku
2fd63283f1 enabled fast-alloc 2022-02-02 20:32:17 +09:00
kazuminn
d1597b2322 ルール場所指定オプションでファイルを扱えるようにする (#364)
* add only rule file path in --rules

* add error handling for metadata

* refactor

* add test

* rename test function
2022-01-31 12:09:25 +09:00
Yamato Security
c1abb2d900 Merge pull request #383 from Yamato-Security/feature/remove_csv_encode_stdoutput#381
removed csv quote when output result to stdout #381
2022-01-30 17:38:23 +09:00
Yamato Security
ee05856181 Merge pull request #380 from Yamato-Security/main-readme-update
readme update
2022-01-30 17:28:50 +09:00
Alan Smithee
f70be3419a removed csv quote when output result to stdout #381 2022-01-30 13:23:33 +09:00
Tanaka Zakku
72864031cd readme update 2022-01-30 11:50:32 +09:00
Yamato Security
bbed0f1159 Merge pull request #379 from Yamato-Security/update-readme
Update-readme
2022-01-30 09:28:00 +09:00
Tanaka Zakku
a992a58497 readme update 2022-01-30 09:26:34 +09:00
Tanaka Zakku
c9bb43eb37 readme update 2022-01-30 09:22:17 +09:00
Tanaka Zakku
6bf4b59c6a readme update 2022-01-30 09:20:52 +09:00
Tanaka Zakku
3f8cf756c1 readme update 2022-01-30 09:16:20 +09:00
Tanaka Zakku
10858d574f update readme 2022-01-29 17:01:44 +09:00
Yamato Security
04d2cd3eae Merge pull request #375 from Yamato-Security/feature/add_release_drafter_template
added release drafter template
2022-01-28 18:29:55 +09:00
Yamato Security
6828f80fe9 Merge pull request #377 from Yamato-Security/Delete-AV-detected-xls-files
Delete-AV-detected-xls-files
2022-01-28 18:25:16 +09:00
Tanaka Zakku
d2108f4e49 Deleted AV detected xls files 2022-01-28 18:01:15 +09:00
Yamato Security
c0466b1af3 Merge pull request #374 from Yamato-Security/updated-cargo-packages
Updated-cargo-packages
2022-01-28 17:38:50 +09:00
Yamato Security
fc08aa5845 Merge pull request #373 from Yamato-Security/readme-update
readme update
2022-01-28 16:05:40 +09:00
DustInDark
8b9ad52dc2 Delete release-drafter.yml
occured workflow error previous merged template.
2022-01-28 16:01:23 +09:00
DustInDark
4a44cd319c added release draft template workflow
added workflow
2022-01-28 15:56:41 +09:00
DustInDark
10396ed78b Update release-drafter.yml
fixed title emoji
2022-01-28 15:54:14 +09:00
DustInDark
9643177536 added release drafter template
added Release Drafter template
2022-01-28 15:50:57 +09:00
Tanaka Zakku
1e1300f6db fixed WELA link 2022-01-28 15:41:16 +09:00
Tanaka Zakku
1bdc3b22f4 updated cargo packages 2022-01-28 15:36:49 +09:00
Tanaka Zakku
b56448a356 readme update 2022-01-28 14:03:59 +09:00
Yamato Security
90ca2cdbbd Merge pull request #371 from Yamato-Security/hotfix/error_after_cargo_update#370
specified clap version specified #370
2022-01-28 07:41:30 +09:00
Yamato Security
5da0f5e322 Merge pull request #372 from Yamato-Security/hotfix/compile_error_after_cargo_update#370
fixed clap library version specifed #370
2022-01-28 07:26:45 +09:00
Alan Smithee
ecc8828921 fixed clap library version specifed #370 2022-01-27 20:42:50 +09:00
Alan Smithee
957c0b09d3 specified clap version specified #370 2022-01-27 20:34:58 +09:00