-
Notifications
You must be signed in to change notification settings - Fork 200
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
add support for |all
#1060
add support for |all
#1060
Conversation
Codecov ReportPatch coverage:
Additional details and impacted files@@ Coverage Diff @@
## main #1060 +/- ##
==========================================
+ Coverage 74.00% 74.22% +0.21%
==========================================
Files 24 24
Lines 18186 18360 +174
==========================================
+ Hits 13459 13628 +169
- Misses 4727 4732 +5
☔ View full report in Codecov by Sentry. |
レビューお願いします。 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
以下3点を確認しました!LGTMです!!🚀
-
修正前後で
csv-timeline -d sample-hayabusa-evtx --debug
の結果ファイル差分なし。メモリ使用量同等 -
以下ルールの検知数と
search --keywords mimikatz
の件数が一致
detection:
selection:
'|all':
- mimikatz
condition: selection
- 以下ルールの検知数と
search --keywords mimikatz
+cat result.csv | grep -i invoke | wc -l
の件数が一致
detection:
selection:
'|all':
- invoke
- mimikatz
condition: selection
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
不明点についてコメントしました。ご確認ください
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
endswithとallOnlyの区別ができなくなる個所が見つかったため解決するまでマージブロックします
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The implementation LGTM! Thanks so much!
@kazuminn 対応ありがとうございます!念のために確認ですが、 |
@YamatoSecurity はい。対応してます。 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
What Changed
fix #1038
Evidence
I done a new test.
すでに、all識別子があったので、かぶらないように、allOnly識別子を追加しています。。
計算量は、既存のor andと同じです。すべてのキーワードのデータが一つになっているメンバがあったので、それを渡すようにしています。