ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s
21 lines
970 B
Bash
Executable File
21 lines
970 B
Bash
Executable File
#!/bin/sh
|
|
#
|
|
# In-container half of the ARTEX Sigma live event-matching test. run.sh launches
|
|
# this inside a Python container with the Sigma rule tree (atomic rules and the
|
|
# correlation/ subtree) mounted read-only at /sigma and this directory at /src. It
|
|
# installs a pinned pySigma, then hands off to check.py, which asserts that every
|
|
# atomic rule matches its malicious sample events and stays quiet on its benign
|
|
# ones, and that every correlation rule fires on its positive timeline and stays
|
|
# quiet on its negative ones (see check.py's header for the trust model and
|
|
# scope). pySigma does the parsing; check.py walks the compiled condition tree and
|
|
# aggregation spec and tests each sample event or timeline against it.
|
|
#
|
|
# POSIX sh (the slim image ships dash). Exits non-zero if any assertion fails.
|
|
set -eu
|
|
|
|
VERSION="${PYSIGMA_VERSION:-2.0.0}"
|
|
|
|
pip install --quiet --disable-pip-version-check "pysigma==${VERSION}" >/dev/null 2>&1
|
|
|
|
exec python3 /src/check.py
|