Skip to content

Commit

Permalink
Update to use the official pySigma SQLite backend
Browse files Browse the repository at this point in the history
  • Loading branch information
wagga40 committed Dec 29, 2023
1 parent f511e7c commit 84d9b14
Show file tree
Hide file tree
Showing 3 changed files with 22 additions and 15 deletions.
2 changes: 1 addition & 1 deletion .gitmodules
Original file line number Diff line number Diff line change
Expand Up @@ -6,4 +6,4 @@
url = https://github.com/SigmaHQ/legacy-sigmatools.git
[submodule "pySigma-backend-sqlite"]
path = pySigma-backend-sqlite
url = https://github.com/wagga40/pySigma-backend-sqlite.git
url = https://github.com/SigmaHQ/pySigma-backend-sqlite.git
33 changes: 20 additions & 13 deletions gen_ruleset.py
Original file line number Diff line number Diff line change
Expand Up @@ -4,17 +4,25 @@
from sigma.pipelines.windows import windows_logsource_pipeline, windows_audit_pipeline
from sigma.processing.resolver import ProcessingPipelineResolver

import multiprocessing as mp
from pathlib import Path
import json
import sys
import sqlite3
import functools

# Paths
rules_path = r"./sigma/rules/windows/"
ruleset_name_sysmon = "rules_windows_sysmon_pysigma.json"
ruleset_name_windows = "rules_windows_generic_pysigma.json"

def convert_rule(backend, rule):
try:
return backend.convert_rule(rule, "zircolite")[0]
except Exception as e:
print(e)

def ruleset_generator(name, output_filename, input_rules, pipelines):

print(f'[+] Initialisation ruleset : {name}')
# Create the pipeline resolver
piperesolver = ProcessingPipelineResolver()
Expand All @@ -32,24 +40,23 @@ def ruleset_generator(name, output_filename, input_rules, pipelines):
rule_list = list(rules.rglob(pattern))
else:
sys.exit(f"Log path {rules} is not a directory")

rule_collection = SigmaCollection.load_ruleset(rule_list)

ruleset = []

print(f'[+] Conversion : {name}')
for rule in rule_collection.rules:
try:
converted_rule = sqlite_backend.convert_rule(rule, "zircolite")[0]
rule_as_json = json.loads(converted_rule)
ruleset.append(rule_as_json)
except Exception as e:
print(e)

ruleset = sorted(ruleset, key=lambda d: d['level'])

pool = mp.Pool()
ruleset = pool.map(functools.partial(convert_rule, sqlite_backend), rule_collection)
pool.close()
pool.join()

ruleset = [rule for rule in ruleset if rule is not None] # Removing empty results
ruleset = sorted(ruleset, key=lambda d: d['level']) # Sorting by level
with open(output_filename, 'w') as outfile:
json.dump(ruleset, outfile, indent=4, ensure_ascii=True)

ruleset_generator("sysmon", ruleset_name_sysmon, rules_path, [sysmon_pipeline(), windows_logsource_pipeline()])
ruleset_generator("generic", ruleset_name_windows, rules_path, [windows_audit_pipeline(), windows_logsource_pipeline()])

if __name__ == '__main__':
ruleset_generator("sysmon", ruleset_name_sysmon, rules_path, [sysmon_pipeline(), windows_logsource_pipeline()])
ruleset_generator("generic", ruleset_name_windows, rules_path, [windows_audit_pipeline(), windows_logsource_pipeline()])

0 comments on commit 84d9b14

Please sign in to comment.