From 777b007bb46cc2a08aaa51a23910b3cdd5a54315 Mon Sep 17 00:00:00 2001 From: fukusuket <41001169+fukusuket@users.noreply.github.com> Date: Sat, 15 Jun 2024 08:14:01 +0900 Subject: [PATCH 1/2] feat: add support for correlation name lookup --- src/detections/rule/correlation_parser.rs | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/detections/rule/correlation_parser.rs b/src/detections/rule/correlation_parser.rs index e7c5df878..e45678774 100644 --- a/src/detections/rule/correlation_parser.rs +++ b/src/detections/rule/correlation_parser.rs @@ -23,6 +23,11 @@ fn is_related_rule(rule_node: &RuleNode, id_or_title: &str) -> bool { return true; } } + if let Some(title) = hash.get(&Yaml::String("name".to_string())) { + if title.as_str() == Some(id_or_title) { + return true; + } + } } false } From 13f4db87713ecf917186d70ed87a60fcc89b11fe Mon Sep 17 00:00:00 2001 From: Yamato Security <71482215+YamatoSecurity@users.noreply.github.com> Date: Sun, 16 Jun 2024 08:29:31 +0900 Subject: [PATCH 2/2] update changelog --- CHANGELOG-Japanese.md | 7 +++++++ CHANGELOG.md | 7 +++++++ 2 files changed, 14 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index b42d5611c..8e55f34e7 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -1,5 +1,12 @@ # 変更点 +## x.x.x [xxxx/xx/xx] + +**改善:** + +- `cidr-utils`クレートを新バージョン0.6.xに対応した。 (#1366) (@hitenkoku) +- Sigma correlationルールの`name`ルックアップに対応した。 (#1363) (@fukusuket) + ## 2.16.0 [2024/06/11] **新機能:** diff --git a/CHANGELOG.md b/CHANGELOG.md index d27ba1a15..00eb85b52 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,12 @@ # Changes +## x.x.x [xxxx/xx/xx] + +**Enchancements:** + +- Support for the newer version 0.6.x `cidr-utils` crate. (#1366) (@hitenkoku) +- Added support for Sigma correlation rule's `name` lookup. (#1363) (@fukusuket) + ## 2.16.0 [2024/06/11] **New Features:**