ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
45 lines
2.4 KiB
YAML
45 lines
2.4 KiB
YAML
# SigmaHQ validator baseline for the ARTEX detection rules.
|
|
#
|
|
# `sigma check` on its own runs only pySigma's core validators. This config turns
|
|
# on the full SigmaHQ convention set (the pySigma-validators-sigmahq plugin) and
|
|
# then disables four checks that encode SigmaHQ *monorepo* conventions which do
|
|
# not apply to this small, self-contained rule set. Every other SigmaHQ check is
|
|
# enforced, and detections/tests/sigma_lint/ fails the build if any enabled check
|
|
# reports an issue. Each exclusion below is a deliberate, documented decision, not
|
|
# a silenced defect.
|
|
#
|
|
# Run:
|
|
# pip install pySigma-validators-sigmahq
|
|
# sigma check --validation-config detections/tests/sigma_lint/validators.yml detections/sigma/
|
|
#
|
|
validators:
|
|
- all
|
|
|
|
# sigmahq_github_link wants every `references:` URL to be a commit permalink
|
|
# rather than a branch link. That check exists so rules citing external,
|
|
# third-party write-ups keep pointing at the exact revision they were written
|
|
# against. Our references point at *our own* living defense docs
|
|
# (docs/defense-ko.md, docs/defense-en.md) on `main`: we want them to track the
|
|
# current guide, not freeze to a snapshot that goes stale as the guide improves.
|
|
- -sigmahq_github_link
|
|
|
|
# sigmahq_filename_prefix and sigmahq_correlation_filename_prefix require
|
|
# logsource-prefixed filenames (web_*, proxy_*) and a correlation_* prefix, the
|
|
# filing scheme of SigmaHQ's single flat rules/ tree. This repository ships a
|
|
# small set under detections/sigma/ with descriptive artex_* names and a
|
|
# correlation/ subdirectory, referenced by the correlation rules' header
|
|
# comments, the reproduction tests, and the README index. Renaming to the
|
|
# monorepo prefixes would desynchronize those references for no gain on a
|
|
# standalone set.
|
|
- -sigmahq_filename_prefix
|
|
- -sigmahq_correlation_filename_prefix
|
|
|
|
# sigmahq_logsource_unknown flags `category: application` (the guard-marker
|
|
# forensic log search) and a product-less `category: process_creation` (the
|
|
# cross-platform destructive-command hunting lead) as outside the SigmaHQ
|
|
# taxonomy. Both logsources are intentionally generic: these indicators appear
|
|
# across heterogeneous application/audit and process-creation logs, and the
|
|
# README tells defenders to map them to their own pipeline. Pinning a single
|
|
# product would narrow the rules incorrectly.
|
|
- -sigmahq_logsource_unknown
|