Skip to content

Commit f13d9a3

Browse files
committed
Fix rule formats for cypress tests
Signed-off-by: vikhy-aws <191836418+vikhy-aws@users.noreply.github.com>
1 parent 471b80f commit f13d9a3

4 files changed

Lines changed: 104 additions & 96 deletions

File tree

Lines changed: 26 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,28 @@
11
{
2-
"id": "25b9c01c-350d-4b95-bed1-836d04a4f325",
3-
"category": "dns",
4-
"title": "Cypress DNS Rule",
5-
"description": "Detects DNS name as QWE",
6-
"status": "experimental",
7-
"author": "Cypress Tests",
8-
"references": [
9-
{
10-
"value": ""
11-
}
12-
],
13-
"tags": [
14-
{
15-
"value": "dns.high"
16-
}
17-
],
18-
"log_source": "",
19-
"detection": "selection:\n dns-question-name:\n - QuestionName\ncondition: selection",
20-
"level": "high",
21-
"false_positives": [
22-
{
23-
"value": ""
24-
}
25-
]
2+
"rule": {
3+
"id": "25b9c01c-350d-4b95-bed1-836d04a4f325",
4+
"category": "dns",
5+
"title": "Cypress DNS Rule",
6+
"description": "Detects DNS name as QWE",
7+
"status": "experimental",
8+
"author": "Cypress Tests",
9+
"references": [
10+
{
11+
"value": ""
12+
}
13+
],
14+
"tags": [
15+
{
16+
"value": "dns.high"
17+
}
18+
],
19+
"log_source": "",
20+
"detection": "selection:\n dns-question-name:\n - QuestionName\ncondition: selection",
21+
"level": "high",
22+
"false_positives": [
23+
{
24+
"value": ""
25+
}
26+
]
27+
}
2628
}
Lines changed: 26 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,28 @@
11
{
2-
"id": "25b9c01c-350d-4b95-bed1-836d04a4f325",
3-
"category": "dns",
4-
"title": "Cypress DNS Type Rule",
5-
"description": "Detects DNS type as QWE",
6-
"status": "experimental",
7-
"author": "Cypress Tests",
8-
"references": [
9-
{
10-
"value": ""
11-
}
12-
],
13-
"tags": [
14-
{
15-
"value": "dns.high"
16-
}
17-
],
18-
"log_source": "",
19-
"detection": "selection:\n dns-answers-type:\n - AnswerType\ncondition: selection",
20-
"level": "high",
21-
"false_positives": [
22-
{
23-
"value": ""
24-
}
25-
]
2+
"rule": {
3+
"id": "25b9c01c-350d-4b95-bed1-836d04a4f325",
4+
"category": "dns",
5+
"title": "Cypress DNS Type Rule",
6+
"description": "Detects DNS type as QWE",
7+
"status": "experimental",
8+
"author": "Cypress Tests",
9+
"references": [
10+
{
11+
"value": ""
12+
}
13+
],
14+
"tags": [
15+
{
16+
"value": "dns.high"
17+
}
18+
],
19+
"log_source": "",
20+
"detection": "selection:\n dns-answers-type:\n - AnswerType\ncondition: selection",
21+
"level": "high",
22+
"false_positives": [
23+
{
24+
"value": ""
25+
}
26+
]
27+
}
2628
}
Lines changed: 26 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,28 @@
11
{
2-
"id": "25b9c01c-350d-4b95-bed1-836d04a4f326",
3-
"category": "network",
4-
"title": "Cypress Network Rule",
5-
"description": "Detects network changes",
6-
"status": "experimental",
7-
"author": "Cypress Tests",
8-
"references": [
9-
{
10-
"value": ""
11-
}
12-
],
13-
"tags": [
14-
{
15-
"value": "network.high"
16-
}
17-
],
18-
"log_source": "",
19-
"detection": "selection:\n keywords:\n - erase\n - delete\n - YXC\ncondition: selection",
20-
"level": "high",
21-
"false_positives": [
22-
{
23-
"value": ""
24-
}
25-
]
2+
"rule": {
3+
"id": "25b9c01c-350d-4b95-bed1-836d04a4f326",
4+
"category": "network",
5+
"title": "Cypress Network Rule",
6+
"description": "Detects network changes",
7+
"status": "experimental",
8+
"author": "Cypress Tests",
9+
"references": [
10+
{
11+
"value": ""
12+
}
13+
],
14+
"tags": [
15+
{
16+
"value": "network.high"
17+
}
18+
],
19+
"log_source": "",
20+
"detection": "selection:\n keywords:\n - erase\n - delete\n - YXC\ncondition: selection",
21+
"level": "high",
22+
"false_positives": [
23+
{
24+
"value": ""
25+
}
26+
]
27+
}
2628
}
Lines changed: 26 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,28 @@
11
{
2-
"id": "25b9c01c-350d-4b95-bed1-836d04a4f123",
3-
"category": "windows",
4-
"title": "Cypress USB Rule",
5-
"description": "USB plugged-in rule",
6-
"status": "experimental",
7-
"author": "Cypress Tests",
8-
"references": [
9-
{
10-
"value": ""
11-
}
12-
],
13-
"tags": [
14-
{
15-
"value": "windows.usb"
16-
}
17-
],
18-
"log_source": "",
19-
"detection": "selection:\n winlog-event_id:\n - 2003\n - 2100\n - 2102\ncondition: selection",
20-
"level": "high",
21-
"false_positives": [
22-
{
23-
"value": ""
24-
}
25-
]
2+
"rule": {
3+
"id": "25b9c01c-350d-4b95-bed1-836d04a4f123",
4+
"category": "windows",
5+
"title": "Cypress USB Rule",
6+
"description": "USB plugged-in rule",
7+
"status": "experimental",
8+
"author": "Cypress Tests",
9+
"references": [
10+
{
11+
"value": ""
12+
}
13+
],
14+
"tags": [
15+
{
16+
"value": "windows.usb"
17+
}
18+
],
19+
"log_source": "",
20+
"detection": "selection:\n winlog-event_id:\n - 2003\n - 2100\n - 2102\ncondition: selection",
21+
"level": "high",
22+
"false_positives": [
23+
{
24+
"value": ""
25+
}
26+
]
27+
}
2628
}

0 commit comments

Comments
 (0)