Skip to main content

Crate rsigma_ir

Crate rsigma_ir 

Source
Expand description

§rsigma-ir

Intermediate representation for Sigma rules — a shared canonical form between evaluation and conversion backends.

The IR lives between the parser AST (rsigma-parser) and the eval engine and convert backends:

YAML ─► parser(AST) ─► pipeline(AST transformations) ─► lower(HIR) ─► compile(CompiledRule)
                                                             │
                                                         convert(Backend queries)

The HIR captures modifier resolution, quantified selectors, and array-scope detections in a serializable form. Compiled matchers (Regex, IpNet) are elided from the IR; they are materialised in the compile step.

§Architecture

  • IrRule — the top-level shape, a superset of SigmaRule metadata with a resolution-free detection tree (IrDetection) and conditions (IrCondition) that preserve quantified selectors.

  • IrMatcher — modifier-resolved matchers. Each field modifier that changes comparison (contains, startswith, endswith, cidr, re, numeric operators, exists, fieldref, timestamp parts) produces an explicit enum variant rather than being encoded as a combination of raw values and an opaque Modifiers bitfield.

  • IrDetection — mirrors the compiler’s CompiledDetection at the semantic level: AllOf, AnyOf, Keywords, ArrayMatch, And, and Conditional. Array-scope quantifiers (any/all/all-or-empty/none) are preserved.

  • IrMatcher — a faithful, lossless match model. String matches keep a wildcard-aware, original-case hir::IrPattern; encoding modifiers stay explicit as hir::IrEncoding steps. Nothing is lowercased, regex-compiled, or encoding-expanded during lowering, so both eval (at compile time) and convert (at emit time) can render it exactly.

§Constraints

  • Sync-only. No tokio, reqwest, or other async-runtime dependencies.
  • HIR values are literal-only on the default lowering path; deferred DynamicSourceRef values are produced only when lower::LowerOptions::permissive_placeholders is enabled.

Re-exports§

pub use cache::CacheError;
pub use cache::HIR_SCHEMA_VERSION;
pub use cache::HirCacheHeader;
pub use cache::decode_rules;
pub use cache::encode_rules;
pub use error::IrError;
pub use lower::LowerOptions;
pub use lower::lower_conditions;
pub use lower::lower_rule;
pub use optimize::CseReport;
pub use optimize::RepeatedItem;
pub use optimize::common_subexpressions;
pub use optimize::eliminate_dead_detections;
pub use optimize::flatten_condition;
pub use optimize::optimize_rule;
pub use raise::RaiseOptions;
pub use raise::ir_pattern_to_sigma;
pub use raise::raise_rule;
pub use hir::*;

Modules§

cache
Versioned serialization of lowered rules, the HIR cache.
encoding
Expansion of encoding modifiers into plain string matches.
error
Error types for the lowering pipeline.
hir
Intermediate representation types for Sigma rules.
lower
Lowering: parser AST → HIR.
optimize
Pure-data optimization passes over an IrRule.
raise
Raising: HIR → parser AST.