-
Notifications
You must be signed in to change notification settings - Fork 206
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Regex Changes fpr msauth #129
Conversation
Hi Jesus,
thx for the email.
That is true ... But as in the issue 125 on github reported in Englisch
Version it Version it is called Security ID so the regex you suggested is
ok. But for example
in German it is called Sicherheits-ID so mine regex with the \s* catches
both languages. Or am I missing something here.
And their is another "bug". At the rule 18217 the fix is missing.
Many Greetings
ERik
´
2018-05-14 14:58 GMT+02:00 Jesús Linares <[email protected]>:
… Hi @ervet <https:/ervet> ,
We already added the PR #125
<#125>.
So, your change would be:
from:
ID:\s+%{S-1-1-0}| ID:\s+S-1-1-0
to:
ID:\s+%{S-1-1-0}|*\s**ID:\s+S-1-1-0
The \s* is not really needed because both regexes are going to match if
there is at least one space before "ID".
Thanks,
Jesus.
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
<#129 (comment)>,
or mute the thread
<https:/notifications/unsubscribe-auth/AlD000AgyndcjZkbN-aJHFNvwhEOgYWTks5tyX96gaJpZM4Tu-KB>
.
|
Hi @ervet, OK, I see your point, the goal is to capture Security ID: and Sicherheits-ID:. I will check it. Thanks!. |
Hello @ervet, We have been testing the rules and they are right, great job. We greatly appreciate the efforts and contributions the community makes to help us improve. We have to consider the option of also changing the decoders because even if the rules work well and are activated correctly, the information we get in the decoder is wrong and we should check it. For example:
As we can see, in both cases we get the same rule activated in front of each event, but in phase two "complete decoding" we do not get the information correctly when we have a dash. This is because of the decoders. For example:
Most probably we will merge this PR with a parallel branch that we will create specifically. Then we will change the decoders and merge the branch with the Master. We can not say for sure because in the future we will get the windows events in JSON format and the obtaining of each field will be trivial, facilitating and improving the functioning of the ruleset #905. Thank you very much for your collaboration. Kind regards, Alfonso Ruiz-Bravo |
Changed the regex as suggested here ...
#125 ... Works perfectly for German Version. Try to check more language version clients soon.