Skip to main content

Crate rsigma_parser

Crate rsigma_parser 

Source
Expand description

§rsigma-parser

A comprehensive parser for Sigma detection rules, correlations, and filters.

This crate parses Sigma YAML files into a strongly-typed AST, handling:

  • Detection rules: field matching, wildcards, boolean conditions, field modifiers
  • Condition expressions: and, or, not, 1 of, all of, parenthesized groups
  • Correlation rules: event_count, value_count, temporal, aggregations
  • Filter rules: additional conditions applied to referenced rules
  • Rule collections: multi-document YAML, action: global/reset/repeat
  • Value types: strings with wildcards, numbers, booleans, null, regex, CIDR
  • All 30+ field modifiers: contains, endswith, startswith, re, cidr, base64, base64offset, wide, windash, all, cased, exists, fieldref, comparison operators, regex flags, timestamp parts, and more

§Architecture

  • PEG grammar (pest) for condition expression parsing with correct operator precedence (NOT > AND > OR) and Pratt parsing
  • yaml_serde for YAML structure deserialization
  • Custom parsing for field modifiers, wildcard strings, and timespan values
  • Semantic validation (validate) rejects invalid rules before lowering: a missing or unusable logsource, conflicting modifiers, values of the wrong type for their modifiers, invalid regular expressions and CIDR networks, empty detections, and conditions that reference undefined detections

§Quick Start

use rsigma_parser::parse_sigma_yaml;

let yaml = r#"
title: Detect Whoami
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        CommandLine|contains: 'whoami'
    condition: selection
level: medium
"#;

let collection = parse_sigma_yaml(yaml).unwrap();
assert_eq!(collection.rules.len(), 1);
assert_eq!(collection.rules[0].title, "Detect Whoami");

§Parsing condition expressions

use rsigma_parser::parse_condition;

let expr = parse_condition("selection_main and 1 of selection_dword_* and not 1 of filter_*").unwrap();
println!("{expr}");

Re-exports§

pub use ads::AdsCarrier;
pub use ads::AdsContent;
pub use ads::AdsDocument;
pub use ads::AdsScaffoldEntry;
pub use ads::AdsSection;
pub use ads::AdsSectionInfo;
pub use ads::AdsSectionStatus;
pub use ads::ads_catalogue;
pub use ast::ArrayQuantifier;
pub use ast::ConditionExpr;
pub use ast::ConditionOperator;
pub use ast::CorrelationCondition;
pub use ast::CorrelationRule;
pub use ast::CorrelationType;
pub use ast::Detection;
pub use ast::DetectionItem;
pub use ast::Detections;
pub use ast::FieldAlias;
pub use ast::FieldSpec;
pub use ast::FilterRule;
pub use ast::FilterRuleTarget;
pub use ast::Level;
pub use ast::LogSource;
pub use ast::Modifier;
pub use ast::Quantifier;
pub use ast::Related;
pub use ast::RelationType;
pub use ast::SelectorPattern;
pub use ast::SigmaCollection;
pub use ast::SigmaDocument;
pub use ast::SigmaRule;
pub use ast::Status;
pub use ast::WindowMode;
pub use condition::parse_condition;
pub use emit::emit_collection_yaml;
pub use emit::emit_rule_yaml;
pub use error::Result;
pub use error::SigmaParserError;
pub use error::SourceLocation;
pub use exemplar::EXEMPLARS_KEY;
pub use exemplar::Exemplar;
pub use exemplar::ExemplarErrorKind;
pub use exemplar::ExemplarPayload;
pub use exemplar::ExemplarRuleKind;
pub use exemplar::ExemplarShapeError;
pub use exemplar::Expect;
pub use exemplar::TimedEvent;
pub use exemplar::correlation_exemplars;
pub use exemplar::exemplars;
pub use exemplar::exemplars_from_attrs;
pub use exemplar::filter_exemplars;
pub use exemplar::match_exemplar_count;
pub use exemplar::match_exemplar_count_json;
pub use exemplar::parse_exemplars;
pub use exemplar::raw_exemplar_values;
pub use exemplar::raw_match_exemplar_count;
pub use exemplar::raw_winning_exemplars;
pub use lint::catalogue::LintRuleInfo;
pub use lint::catalogue::catalogue;
pub use lint::fix::SourceFixOutcome;
pub use lint::fix::apply_fixes_to_source;
pub use lint::AdsConfig;
pub use lint::FileLintResult;
pub use lint::Fix;
pub use lint::FixDisposition;
pub use lint::FixPatch;
pub use lint::InlineSuppressions;
pub use lint::LintConfig;
pub use lint::LintRule;
pub use lint::LintWarning;
pub use lint::Severity;
pub use lint::Span;
pub use lint::apply_suppressions;
pub use lint::lint_yaml_directory;
pub use lint::lint_yaml_directory_with_config;
pub use lint::lint_yaml_file;
pub use lint::lint_yaml_file_with_config;
pub use lint::lint_yaml_str;
pub use lint::lint_yaml_str_with_config;
pub use lint::lint_yaml_value;
pub use lint::parse_inline_suppressions;
pub use parser::parse_field_spec;
pub use parser::parse_sigma_directory;
pub use parser::parse_sigma_file;
pub use parser::parse_sigma_yaml;
pub use selector::detection_name_matches;
pub use value::SigmaString;
pub use value::SigmaValue;
pub use value::SpecialChar;
pub use value::StringPart;
pub use value::Timespan;
pub use version::SPEC_VERSION_ARRAY_MATCHING;
pub use version::SPEC_VERSION_FLOOR;
pub use version::SPEC_VERSION_SUPPORTED;
pub use version::array_matching_enabled;
pub use version::is_unsupported;
pub use version::resolve_major;

Modules§

ads
ADS (Alerting and Detection Strategy) section vocabulary and reading helpers.
ast
AST types for all Sigma constructs: rules, detections, conditions, correlations, and filters.
condition
Condition expression parser using pest PEG grammar + Pratt parser.
emit
Emit a parsed Sigma rule back to canonical Sigma YAML.
error
exemplar
Embedded rule exemplars under rsigma.exemplars.
fieldpath
Field-path helpers shared by the parser, evaluator, and converters.
lint
Built-in linter for Sigma rules, correlations, and filters.
parser
Main YAML → AST parser for Sigma rules, correlations, filters, and collections.
reference
Shared reference data for Sigma detection rules.
selector
Detection-name glob matching for ... of selection_* selector expressions.
validate
Semantic checks on parsed detections.
value
version
Sigma specification version targeting (the sigma-version attribute).