First Commit
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s

This commit is contained in:
dela
2026-10-09 08:38:16 +08:00
commit 0335d572de
756 changed files with 201663 additions and 0 deletions
+85
View File
@@ -0,0 +1,85 @@
#!/bin/sh
#
# In-container half of the ARTEX Sigma SigmaHQ-convention lint test. run.sh
# launches this inside a Python container with the Sigma rule tree mounted
# read-only at /sigma and this directory at /src. It installs a pinned sigma-cli
# plus the pinned SigmaHQ validator plugin, then asserts two properties:
#
# 1. baseline is clean sigma check with the documented validators.yml
# baseline reports 0 errors and 0 issues.
# 2. the full set is live running ALL SigmaHQ validators (no exclusions) still
# reports issues, and every issue type is one of the
# four documented, excluded categories — nothing else.
#
# Property 2 is the anti-vacuity guard. If the validator plugin failed to load,
# the "all" run would report zero issues and property 1 would pass vacuously;
# requiring the known exclusions to appear proves the full SigmaHQ set actually
# ran. It also fails the build the moment a rule picks up a NEW convention issue
# outside the documented baseline (e.g. a mis-cased title or an invalid field),
# because that issue type would not be in the allow-list below and property 1
# would stop being clean.
#
# POSIX sh (the slim image ships dash). Exits non-zero if any assertion fails.
set -eu
VERSION="${SIGMA_CLI_VERSION:-3.1.0}"
SIGMAHQ_VALIDATORS_VERSION="${SIGMAHQ_VALIDATORS_VERSION:-0.21.0}"
pip install --quiet --disable-pip-version-check \
"sigma-cli==${VERSION}" "pySigma-validators-sigmahq==${SIGMAHQ_VALIDATORS_VERSION}" >/dev/null 2>&1
# The four issue types the documented baseline (validators.yml) intentionally
# excludes. Any issue outside this set must fail the build.
ALLOWED='SigmahqGithubLinkIssue SigmahqFilenamePrefixIssue SigmahqCorrelationFilenamePrefixIssue SigmahqLogsourceUnknownIssue'
printf 'validators:\n - all\n' > /tmp/all.yml
fail=0
note() { printf ' %s\n' "$1"; }
pass() { note "PASS $1"; }
bad() { note "FAIL $1"; fail=1; }
echo "== 1/2 documented SigmaHQ baseline is clean (validators.yml) =="
if base_out="$(sigma check --validation-config /src/validators.yml /sigma 2>&1)" \
&& printf '%s' "$base_out" | grep -q 'Found 0 errors, 0 condition errors and 0 issues'; then
pass "sigma check with the documented baseline: 0 errors, 0 issues"
else
bad "the documented baseline reported problems (a non-excluded convention issue, or an error)"
printf '%s\n' "$base_out" | sed 's/^/ /'
fi
echo "== 2/2 the full SigmaHQ validator set runs, and only the documented exclusions remain =="
all_out="$(sigma check --validation-config /tmp/all.yml /sigma 2>&1 || true)"
# Collect the distinct issue types the full set reports.
types="$(printf '%s' "$all_out" | grep -oE 'issue=Sigmahq[A-Za-z]+Issue' | sed 's/^issue=//' | sort -u)"
if [ -z "$types" ]; then
bad "the full validator set reported no SigmaHQ issues at all — the plugin did not load (vacuous)"
else
# Anti-vacuity: the two load-bearing exclusions must actually appear.
for must in SigmahqGithubLinkIssue SigmahqLogsourceUnknownIssue; do
if printf '%s\n' "$types" | grep -qx "$must"; then
pass "full set is live: $must present"
else
bad "expected $must from the full validator set but it was absent — plugin/version drift"
fi
done
# No issue type outside the documented allow-list may appear.
unexpected=0
for t in $types; do
case " $ALLOWED " in
*" $t "*) : ;;
*) bad "undocumented convention issue from the full set: $t"; unexpected=1 ;;
esac
done
[ "$unexpected" -eq 0 ] && pass "every reported issue is one of the four documented exclusions"
fi
echo
echo "reference: sigma-cli ${VERSION}, pySigma-validators-sigmahq ${SIGMAHQ_VALIDATORS_VERSION}"
if [ "$fail" -eq 0 ]; then
echo "RESULT: PASS"
else
echo "RESULT: FAIL"
fi
exit "$fail"
+41
View File
@@ -0,0 +1,41 @@
#!/usr/bin/env bash
#
# Reproducible SigmaHQ-convention lint for the ARTEX Sigma rules (../../sigma/).
# `sigma check` on its own runs only pySigma's core validators; this test runs
# the full SigmaHQ convention set (the pySigma-validators-sigmahq plugin) against
# the documented baseline in validators.yml, so the "passes sigma check cleanly"
# claim in the README and CONTRIBUTING covers SigmaHQ's conventions, not just the
# core checks.
#
# It proves two properties with no host dependency beyond Docker (everything runs
# in a container, nothing is installed on the host and nothing is written to the
# repo tree):
#
# 1. the documented baseline (validators.yml) reports 0 errors and 0 issues
# 2. the full validator set actually runs, and only the four documented
# exclusions remain — the anti-vacuity guard (see check.sh)
#
# The four exclusions and the rationale for each live in validators.yml.
#
# Usage: detections/tests/sigma_lint/run.sh
# Env: PYTHON_IMAGE (default python:3.12-slim)
# SIGMA_CLI_VERSION (default 3.1.0 — the pinned reference version)
# SIGMAHQ_VALIDATORS_VERSION (default 0.21.0 — the pinned validator plugin)
set -euo pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"
REPO="$(cd "$HERE/../../.." && pwd)"
SIGMA_DIR="$REPO/detections/sigma"
PYTHON_IMAGE="${PYTHON_IMAGE:-python:3.12-slim}"
SIGMA_CLI_VERSION="${SIGMA_CLI_VERSION:-3.1.0}"
SIGMAHQ_VALIDATORS_VERSION="${SIGMAHQ_VALIDATORS_VERSION:-0.21.0}"
# Everything runs inside the container: check.sh installs the pinned sigma-cli and
# SigmaHQ validator plugin, then asserts the two properties and exits non-zero on
# any failure. The rule tree and this directory are mounted read-only.
docker run --rm \
-v "$SIGMA_DIR:/sigma:ro" \
-v "$HERE:/src:ro" \
-e SIGMA_CLI_VERSION="$SIGMA_CLI_VERSION" \
-e SIGMAHQ_VALIDATORS_VERSION="$SIGMAHQ_VALIDATORS_VERSION" \
"$PYTHON_IMAGE" sh /src/check.sh
@@ -0,0 +1,44 @@
# SigmaHQ validator baseline for the ARTEX detection rules.
#
# `sigma check` on its own runs only pySigma's core validators. This config turns
# on the full SigmaHQ convention set (the pySigma-validators-sigmahq plugin) and
# then disables four checks that encode SigmaHQ *monorepo* conventions which do
# not apply to this small, self-contained rule set. Every other SigmaHQ check is
# enforced, and detections/tests/sigma_lint/ fails the build if any enabled check
# reports an issue. Each exclusion below is a deliberate, documented decision, not
# a silenced defect.
#
# Run:
# pip install pySigma-validators-sigmahq
# sigma check --validation-config detections/tests/sigma_lint/validators.yml detections/sigma/
#
validators:
- all
# sigmahq_github_link wants every `references:` URL to be a commit permalink
# rather than a branch link. That check exists so rules citing external,
# third-party write-ups keep pointing at the exact revision they were written
# against. Our references point at *our own* living defense docs
# (docs/defense-ko.md, docs/defense-en.md) on `main`: we want them to track the
# current guide, not freeze to a snapshot that goes stale as the guide improves.
- -sigmahq_github_link
# sigmahq_filename_prefix and sigmahq_correlation_filename_prefix require
# logsource-prefixed filenames (web_*, proxy_*) and a correlation_* prefix, the
# filing scheme of SigmaHQ's single flat rules/ tree. This repository ships a
# small set under detections/sigma/ with descriptive artex_* names and a
# correlation/ subdirectory, referenced by the correlation rules' header
# comments, the reproduction tests, and the README index. Renaming to the
# monorepo prefixes would desynchronize those references for no gain on a
# standalone set.
- -sigmahq_filename_prefix
- -sigmahq_correlation_filename_prefix
# sigmahq_logsource_unknown flags `category: application` (the guard-marker
# forensic log search) and a product-less `category: process_creation` (the
# cross-platform destructive-command hunting lead) as outside the SigmaHQ
# taxonomy. Both logsources are intentionally generic: these indicators appear
# across heterogeneous application/audit and process-creation logs, and the
# README tells defenders to map them to their own pipeline. Pinning a single
# product would narrow the rules incorrectly.
- -sigmahq_logsource_unknown