-
-
Notifications
You must be signed in to change notification settings - Fork 90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add native Sigma support #1379
Merged
Merged
Add native Sigma support #1379
Commits on Feb 18, 2021
-
Configuration menu - View commit details
-
Copy full SHA for f303883 - Browse repository at this point
Copy the full SHA f303883View commit details -
Configuration menu - View commit details
-
Copy full SHA for f250bb5 - Browse repository at this point
Copy the full SHA f250bb5View commit details -
Hook Sigma rule parsing into command system
We now try to parse a query expression as Sigma rule first. If it fails, then we go to the regular VAST expression parser. We currently fail silently on the Sigma parsing; only a debug log entry is emitted.
Configuration menu - View commit details
-
Copy full SHA for 19f3f81 - Browse repository at this point
Copy the full SHA 19f3f81View commit details -
Complete full detection parsing logic
The "1/all of X" syntax now works. We also apply the "re" modifier and translate an exact string into a pattern.
Configuration menu - View commit details
-
Copy full SHA for 4530d46 - Browse repository at this point
Copy the full SHA 4530d46View commit details -
Configuration menu - View commit details
-
Copy full SHA for 37ed10f - Browse repository at this point
Copy the full SHA 37ed10fView commit details -
Bring back symbol table parser
This data structure was removed in c6c4840 because it was not used anymore. Now we need it again.
Configuration menu - View commit details
-
Copy full SHA for ea33961 - Browse repository at this point
Copy the full SHA ea33961View commit details -
Configuration menu - View commit details
-
Copy full SHA for 9681fcd - Browse repository at this point
Copy the full SHA 9681fcdView commit details -
Configuration menu - View commit details
-
Copy full SHA for 58bdc51 - Browse repository at this point
Copy the full SHA 58bdc51View commit details -
Configuration menu - View commit details
-
Copy full SHA for 5a5f320 - Browse repository at this point
Copy the full SHA 5a5f320View commit details -
Configuration menu - View commit details
-
Copy full SHA for add41ef - Browse repository at this point
Copy the full SHA add41efView commit details -
This is not complete and by far not tested enough. It just serves as a starting point. Since VAST currently cannot handle patterns, there's no point in going exhaustive for now.
Configuration menu - View commit details
-
Copy full SHA for 9f4e7a3 - Browse repository at this point
Copy the full SHA 9f4e7a3View commit details -
Configuration menu - View commit details
-
Copy full SHA for 2f98022 - Browse repository at this point
Copy the full SHA 2f98022View commit details -
Configuration menu - View commit details
-
Copy full SHA for 44041fe - Browse repository at this point
Copy the full SHA 44041feView commit details
Commits on Feb 19, 2021
-
Configuration menu - View commit details
-
Copy full SHA for 28a973e - Browse repository at this point
Copy the full SHA 28a973eView commit details
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.