feat: Support 1 of selection*
and all of selection*
#957
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What Changed
1 of selection*
andall of selection*
#956conditions:
block conversion process internally with the following specifications before rule compilation/tokenize1 of selection*
->(select1 or select2 or select3)
all of selection*
->(select1 and select2 and select3)
Evidence
Environment
Test1
Detection count
of rule which has
1 of selection_*
is the same before/after../hayabusa-2.2.2 -d ... -r
hayabusa-rules/win_security_pass_the_hash_2.yml./hayabusa-new -d ... -r
Sigma/win_security_pass_the_hash_2.ymlThe result of the above two commands is as follows
Test2
Detection count
of rule which has
1 of filter_*
andall of suspicious2*
is the same before/after../hayabusa-2.2.2 -d ... -r
hayabusa-rules/win_system_susp_service_installation.yml./hayabusa-new -d ... -r
Sigma/win_system_susp_service_installation.ymlThe result of the above two commands is as follows
Benchmark1
Data: evtx-baseline v0.7
Command:
./hayabusa csv-timeline -d ./all-evtx -o out.csv --debug
Benchmark2
Data: hayabusa-sample-evtx
Command:
./hayabusa csv-timeline -d ./all-evtx -o out.csv --debug
I would appreciate it if you could review🙏