Commit Graph

1435 Commits

Author SHA1 Message Date
DustInDark
3a1eeca555 Merge branch 'feature/level-tuning#390' of github.com:Yamato-Security/hayabusa into feature/level-tuning#390 2022-04-07 01:56:00 +09:00
DustInDark
b8c442ca22 inserted debug data 2022-04-07 01:55:03 +09:00
itiB
f3a679d845 Add: Flush method. 2022-04-07 01:44:02 +09:00
itiB
4056975b1d Add: add test_files/config/level_tuning.txt 2022-04-07 01:33:35 +09:00
itiB
e119ba8f14 Fix: test file's path was incorrect 2022-04-07 01:24:26 +09:00
DustInDark
d6efb5107a reduce output mitre attack detail tachnique No. by config file (#483)
* reduced mitre attck tag output by config file #477

* prepared 1.2.0 version toml

* added test files and mitre attck strategy tag file #477

* fixed cargo.toml version

* updated cargo.lock

* output tag english update

* cargo fmt

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-04-07 00:47:08 +09:00
DustInDark
e715935bb6 fixed level-tuning option usage from required to option 2022-04-07 00:17:51 +09:00
DustInDark
a35e8ad5cb fixed config to show level-tuning option 2022-04-07 00:08:32 +09:00
DustInDark
6931724ec4 fixed comment out processing in level_tuning.txt 2022-04-06 23:30:32 +09:00
DustInDark
0c27b13c85 added run args rules path to check test easy #390 2022-04-06 23:28:55 +09:00
DustInDark
3b4c4dd36e fixed convert miss change to low level 2022-04-06 22:47:28 +09:00
DustInDark
cd8c856d05 changed level_tuning.txt header from next_level to new_level 2022-04-06 22:46:35 +09:00
DustInDark
dab91e5e61 fixed level tuning test and added test files #390 2022-04-06 22:34:32 +09:00
DustInDark
a5bf79cf83 Fixed output stop when control char exist in windows terminal (#485)
* added control character filter in details #382

* fixed document

- removed fixed windows teminal caution in readme
2022-04-06 08:40:28 +09:00
itiB
11b5a3d394 Use
#[cfg(test)]
2022-04-06 02:04:23 +09:00
itiB
04c0e6ae07 Cargo fmt 2022-04-06 01:55:19 +09:00
itiB
52bc918cfb Add: README.md 2022-04-06 01:54:09 +09:00
itiB
51f8d405f8 Add: test 2022-04-06 01:34:48 +09:00
kazuminn
c8efa95447 Pivot Keyword List機能の追加 (#412)
* add get_pivot_keyword() func

* change function name and call it's function

* [WIP] support config file

* compilete output

* cargo fmt

* [WIP] add test

* add test

* support -o option in pivot

* add pivot mod

* fix miss

* pass test in pivot.rs

* add comment

* pass all test

* add fast return

* fix output

* add test config file

* review

* rebase

* cargo fmt

* test pass

* fix clippy in my commit

* cargo fmt

* little refactor

* change file input logic and config format

* [WIP] change output

* [wip] change deta structure

* change output & change data structure

* pass test

* add config

* cargo fmt & clippy & rebase

* fix cllipy

* delete /rules/ in .gitignore

* clean comment

* clean

* clean

* fix rebase miss

* fix rebase miss

* fix clippy

* file name output on -o to stdout

* add pivot_keywords.txt to ./config

* updated english

* Documentation update

* cargo fmt and clean

* updated translate japanese

* readme update

* readme update

Co-authored-by: DustInDark <nextsasasa@gmail.com>
Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-04-05 21:17:23 +09:00
itiB
90822aa563 Cargo fmt 2022-04-05 02:04:10 +09:00
itiB
9f8f12ec2f fix: level tuning's file name 2022-04-05 02:03:49 +09:00
itiB
015691e129 mv: IDS_REGEX to configs file 2022-04-05 01:59:56 +09:00
itiB
373dd0f8c7 Add: id, level validation 2022-04-05 01:53:24 +09:00
itiB
026d18a605 Add: Error handlings 2022-04-05 01:30:11 +09:00
itiB
6b08752120 Fix: Text overwrite was failed 2022-04-04 23:44:54 +09:00
itiB
5891a1aca1 WIP: Text overwrite failed... 2022-04-04 01:44:04 +09:00
itiB
6805bd6a0a Reface: split to options file 2022-04-04 00:31:21 +09:00
itiB
9149500b40 Add: level-tuning function 2022-04-03 23:41:32 +09:00
itiB
814f5a61cb cargo fmt 2022-04-03 22:01:40 +09:00
itiB
d38834e20e Add: input rule_level.txt files & read rules 2022-04-03 21:58:33 +09:00
itiB
a15bef4b30 Add: read Rule files 2022-04-03 21:58:33 +09:00
itiB
276889338d Add: --level-tuning option's outline 2022-04-03 21:57:50 +09:00
Yamato Security
545119bdfe Merge pull request #476 from Yamato-Security/bugfix/exculde_load_yml_in_git_folder#472
[Bugfix] exculde load yml in git folder#472
2022-03-31 03:22:07 +09:00
DustInDark
7c645010ee fixed process when yml file exist in .git folder
* ignore when yml file exist in .git folder
2022-03-30 21:02:14 +09:00
Yamato Security
66ac9dd00b Merge pull request #474 from Yamato-Security/update/rules_submodule_main
updated rules submodule(To main branch)
2022-03-30 20:54:23 +09:00
Yamato Security
c8e86c1c20 Merge pull request #475 from Yamato-Security/update/rules_submodule_develop
updated rules submodule(To develop branch)
2022-03-30 20:53:52 +09:00
DustInDark
2b8ee9e41c updated rules submodule: 2022-03-30 20:42:13 +09:00
DustInDark
230a481eaf updated rules submodule 2022-03-30 20:39:46 +09:00
DustInDark
425a629de7 Enhancement: add config config #456 (#471)
* added config option #456

* added process of option to speicifed config folder #456

following files adjust config option.

* noisy_rules.txt

* exclude_rules.txt

* fixed usage in readme
2022-03-30 15:26:58 +09:00
James / hach1yon
bca578b89e add equalsfield pipe (#467) 2022-03-30 11:49:20 +09:00
garigariganzy
7861174a93 Remove unnecessary code from timeline_event_info and rename files for… (#470)
* Remove unnecessary code from timeline_event_info and rename files for issue462

* Remove unnecessary code #462
2022-03-30 09:46:18 +09:00
DustInDark
fa86a9a027 Fearture/ added output update result#410 (#452)
* add git2 crate #391

* added Update option #391

* updated readme #391

* fixed cargo.lock

* fixed option if-statement #391

* changed utc short option and rule-update short option #391

* updated readme

* updated readme

* fixed -u long option & version number update #391

* added fast-forwarding rules repository #391

* updated command line option #391

* moved output logo prev update rule

* fixed readme #391

* removed recursive option in readme

* changed rules update from clone and pull to submodule update #391

* fixed document

* changed unnecessary clone recursively to clone only

* English message update.

* cargo fmt

* English message update. ( 4657c35e5c cherry-pick)

* added create rules folder when rules folder is not exist

* fixed gitmodules github-rules url from ssh to https

* added output of updated file #420

* fixed error #410

* changed update rule list seq

* added test

* fixed output #410

* fixed output and fixed output date field  when  modified field is lacked #410

* fixed compile error

* fixed output

- added enter after Latest rule update output
- added output when no exist new rule
- fixed Latest rule update date format
- changed output from 'Latest rule update' to 'Latest rules update'

* fixed compile error

* changed modified date source from rules folder to each yml rule file

* formatting use chrono in main.rs

* merge develop clippy ci

* fixed output when no update rule #410

- removed Latest rule update

- no output "Rules update successfully" when No rule changed

* Change English

Co-authored-by: Tanaka Zakku <71482215+YamatoSecurity@users.noreply.github.com>
2022-03-29 13:09:54 +09:00
James / hach1yon
67cf88cddd fix degrade for pull req #464 (#468)
* fix degrade for pull req #464

* add trim
2022-03-27 22:26:42 +09:00
Yamato Security
b3476f6ad5 Merge pull request #466 from Yamato-Security/rule_submodule_update_main
Updated rule submodule in main branch
2022-03-26 19:14:05 +09:00
Yamato Security
e372605de6 Merge pull request #465 from Yamato-Security/rule_submodule_update
Updated rule submodule in develop branch
2022-03-26 19:13:43 +09:00
DustInDark
9b058bcbdc updated submodule 2022-03-26 18:13:38 +09:00
DustInDark
6e555f0832 updated submodule 2022-03-26 18:05:15 +09:00
James / hach1yon
b0e4247857 Feature/#440 refactoring #395 (#464) 2022-03-26 16:11:11 +09:00
Yamato Security
5e14263272 statistics event id update (#457) 2022-03-22 19:01:32 +09:00
DustInDark
e563224b52 added clippy workflow #428 (#429)
* added clippy workflow #428

* fixed action yaml to run clippy #428

* fixed indent

* fixed workflow

* fixed workflow error

* fixed indent

* changed no annotation #428

* adujusted annotation version

* fixed clippy::needless_match

* remove if let exception

* removed unnecessary permission check #428
2022-03-21 12:45:30 +09:00