New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.
Already on GitHub? Sign in to your account
refactor: remove unneeded escapes(in |re
block)
#3744
refactor: remove unneeded escapes(in |re
block)
#3744
Conversation
|re
block)|re
block)
I'm sorry, I noticed that the |
I've also finished removing |
|
Thanks for the quick review :) I fixed |
I'm seeing a large amount of false positives in my logs from these rules since this change. I'm not smart enough to know if it's an issue with the commits or with my log management tool Security Onion though. Thoughts? |
@OhHappyDagger |
The rules that fixed the regex in this PR are related to the issue #1009 . Will this help with your research? |
Sure. Here is an example of an event that hit on 73e67340-0d25-11eb-adc1-0242ac120002 in Security Onion. After brushing up on regex a bit, it seems like your rules should be fine. I'm pretty confused on why these are matching. I'm thinking it's either an issue with Security Onion or my install, not with these rules. Thanks for the referenced issue, I'll keep digging.
|
Hi, Thanks for commenting on this. From the looks of it. The event you posted is a I suggest we take this discussion to the issues section. So please can you open an Issue here? Since this could be a false positive with another rule and I would love to know more about it. Regards. |
Thank you for maintaining Sigma :)
I noticed some yml
|re
blocks have unneeded escapes like bellow. So I removed unneeded escapes in this PR.\/c
\/r
\"
\-
Besides in rare cases,
/
,-
and"
should not be escaped and will actually cause parsing errors on some regex libraries when there are unneeded escapes(ref: rust-lang/regex#501 (comment)).I have also confirmed that the regex which removed unneeded escapes didn't cause compilation errors in the following programming languages.
I would appreciate it if you could review馃檹