Expand description
§rsigma-parser
A comprehensive parser for Sigma detection rules, correlations, and filters.
This crate parses Sigma YAML files into a strongly-typed AST, handling:
- Detection rules: field matching, wildcards, boolean conditions, field modifiers
- Condition expressions:
and,or,not,1 of,all of, parenthesized groups - Correlation rules:
event_count,value_count,temporal, aggregations - Filter rules: additional conditions applied to referenced rules
- Rule collections: multi-document YAML,
action: global/reset/repeat - Value types: strings with wildcards, numbers, booleans, null, regex, CIDR
- All 30+ field modifiers:
contains,endswith,startswith,re,cidr,base64,base64offset,wide,windash,all,cased,exists,fieldref, comparison operators, regex flags, timestamp parts, and more
§Architecture
- PEG grammar (
pest) for condition expression parsing with correct operator precedence (NOT>AND>OR) and Pratt parsing - yaml_serde for YAML structure deserialization
- Custom parsing for field modifiers, wildcard strings, and timespan values
- Semantic validation (
validate) rejects invalid rules before lowering: a missing or unusable logsource, conflicting modifiers, values of the wrong type for their modifiers, invalid regular expressions and CIDR networks, empty detections, and conditions that reference undefined detections
§Quick Start
use rsigma_parser::parse_sigma_yaml;
let yaml = r#"
title: Detect Whoami
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains: 'whoami'
condition: selection
level: medium
"#;
let collection = parse_sigma_yaml(yaml).unwrap();
assert_eq!(collection.rules.len(), 1);
assert_eq!(collection.rules[0].title, "Detect Whoami");§Parsing condition expressions
use rsigma_parser::parse_condition;
let expr = parse_condition("selection_main and 1 of selection_dword_* and not 1 of filter_*").unwrap();
println!("{expr}");Re-exports§
pub use ads::AdsCarrier;pub use ads::AdsContent;pub use ads::AdsDocument;pub use ads::AdsScaffoldEntry;pub use ads::AdsSection;pub use ads::AdsSectionInfo;pub use ads::AdsSectionStatus;pub use ads::ads_catalogue;pub use ast::ArrayQuantifier;pub use ast::ConditionExpr;pub use ast::ConditionOperator;pub use ast::CorrelationCondition;pub use ast::CorrelationRule;pub use ast::CorrelationType;pub use ast::Detection;pub use ast::DetectionItem;pub use ast::Detections;pub use ast::FieldAlias;pub use ast::FieldSpec;pub use ast::FilterRule;pub use ast::FilterRuleTarget;pub use ast::Level;pub use ast::LogSource;pub use ast::Modifier;pub use ast::Quantifier;pub use ast::Related;pub use ast::RelationType;pub use ast::SelectorPattern;pub use ast::SigmaCollection;pub use ast::SigmaDocument;pub use ast::SigmaRule;pub use ast::Status;pub use ast::WindowMode;pub use condition::parse_condition;pub use emit::emit_collection_yaml;pub use emit::emit_rule_yaml;pub use error::Result;pub use error::SigmaParserError;pub use error::SourceLocation;pub use exemplar::EXEMPLARS_KEY;pub use exemplar::Exemplar;pub use exemplar::ExemplarErrorKind;pub use exemplar::ExemplarPayload;pub use exemplar::ExemplarRuleKind;pub use exemplar::ExemplarShapeError;pub use exemplar::Expect;pub use exemplar::TimedEvent;pub use exemplar::correlation_exemplars;pub use exemplar::exemplars;pub use exemplar::exemplars_from_attrs;pub use exemplar::filter_exemplars;pub use exemplar::match_exemplar_count;pub use exemplar::match_exemplar_count_json;pub use exemplar::parse_exemplars;pub use exemplar::raw_exemplar_values;pub use exemplar::raw_match_exemplar_count;pub use exemplar::raw_winning_exemplars;pub use lint::catalogue::LintRuleInfo;pub use lint::catalogue::catalogue;pub use lint::fix::SourceFixOutcome;pub use lint::fix::apply_fixes_to_source;pub use lint::AdsConfig;pub use lint::FileLintResult;pub use lint::Fix;pub use lint::FixDisposition;pub use lint::FixPatch;pub use lint::InlineSuppressions;pub use lint::LintConfig;pub use lint::LintRule;pub use lint::LintWarning;pub use lint::Severity;pub use lint::Span;pub use lint::apply_suppressions;pub use lint::lint_yaml_directory;pub use lint::lint_yaml_directory_with_config;pub use lint::lint_yaml_file;pub use lint::lint_yaml_file_with_config;pub use lint::lint_yaml_str;pub use lint::lint_yaml_str_with_config;pub use lint::lint_yaml_value;pub use lint::parse_inline_suppressions;pub use parser::parse_field_spec;pub use parser::parse_sigma_directory;pub use parser::parse_sigma_file;pub use parser::parse_sigma_yaml;pub use selector::detection_name_matches;pub use value::SigmaString;pub use value::SigmaValue;pub use value::SpecialChar;pub use value::StringPart;pub use value::Timespan;pub use version::SPEC_VERSION_ARRAY_MATCHING;pub use version::SPEC_VERSION_FLOOR;pub use version::SPEC_VERSION_SUPPORTED;pub use version::array_matching_enabled;pub use version::is_unsupported;pub use version::resolve_major;
Modules§
- ads
- ADS (Alerting and Detection Strategy) section vocabulary and reading helpers.
- ast
- AST types for all Sigma constructs: rules, detections, conditions, correlations, and filters.
- condition
- Condition expression parser using pest PEG grammar + Pratt parser.
- emit
- Emit a parsed Sigma rule back to canonical Sigma YAML.
- error
- exemplar
- Embedded rule exemplars under
rsigma.exemplars. - fieldpath
- Field-path helpers shared by the parser, evaluator, and converters.
- lint
- Built-in linter for Sigma rules, correlations, and filters.
- parser
- Main YAML → AST parser for Sigma rules, correlations, filters, and collections.
- reference
- Shared reference data for Sigma detection rules.
- selector
- Detection-name glob matching for
... of selection_*selector expressions. - validate
- Semantic checks on parsed detections.
- value
- version
- Sigma specification version targeting (the
sigma-versionattribute).