Skip to content

Commit 739762d

Browse files
committed
Merge branch 'main' into cleanup-survey-code
2 parents cf2b8d4 + 53673c0 commit 739762d

File tree

3 files changed

+571
-850
lines changed

3 files changed

+571
-850
lines changed

detection_rules/devtools.py

+5-6
Original file line numberDiff line numberDiff line change
@@ -901,7 +901,7 @@ def rule_survey(ctx: click.Context, query, date_range, dump_file, hide_zero_coun
901901
from eql.table import Table
902902
from kibana.resources import Signal
903903
from .main import search_rules
904-
from .eswrap import parse_unique_field_results
904+
# from .eswrap import parse_unique_field_results
905905

906906
survey_results = []
907907
start_time, end_time = date_range
@@ -927,11 +927,10 @@ def rule_survey(ctx: click.Context, query, date_range, dump_file, hide_zero_coun
927927
alerts = {a['_source']['signal']['rule']['rule_id']: a['_source']
928928
for a in Signal.search(range_dsl, size=10000)['hits']['hits']}
929929

930-
for alert in alerts:
931-
rule_id = alert['signal']['rule']['rule_id']
932-
rule = rules.id_map[rule_id]
933-
unique_results = parse_unique_field_results(rule.contents.data.type, rule.contents.data.unique_fields, alert)
934-
930+
# for alert in alerts:
931+
# rule_id = alert['signal']['rule']['rule_id']
932+
# rule = rules.id_map[rule_id]
933+
# unique_results = parse_unique_field_results(rule.contents.data.type, rule.contents.data.unique_fields, alert)
935934

936935
for rule_id, count in counts.items():
937936
alert_count = len(alerts.get(rule_id, []))

etc/deprecated_rules.json

-10
Original file line numberDiff line numberDiff line change
@@ -34,21 +34,11 @@
3434
"rule_name": "Execution via Regsvcs/Regasm",
3535
"stack_version": "7.14.0"
3636
},
37-
"5e87f165-45c2-4b80-bfa5-52822552c997": {
38-
"deprecation_date": "2022/03/16",
39-
"rule_name": "Potential PrintNightmare File Modification",
40-
"stack_version": "7.13"
41-
},
4237
"61c31c14-507f-4627-8c31-072556b89a9c": {
4338
"deprecation_date": "2021/04/15",
4439
"rule_name": "Mknod Process Activity",
4540
"stack_version": "7.14.0"
4641
},
47-
"6506c9fd-229e-4722-8f0f-69be759afd2a": {
48-
"deprecation_date": "2022/03/16",
49-
"rule_name": "Potential PrintNightmare Exploit Registry Modification",
50-
"stack_version": "7.13"
51-
},
5242
"67a9beba-830d-4035-bfe8-40b7e28f8ac4": {
5343
"deprecation_date": "2021/04/15",
5444
"rule_name": "SMTP to the Internet",

0 commit comments

Comments
 (0)