Skip to main content

rsigma_parser/
lib.rs

1//! # rsigma-parser
2//!
3//! A comprehensive parser for Sigma detection rules, correlations, and filters.
4//!
5//! This crate parses Sigma YAML files into a strongly-typed AST, handling:
6//!
7//! - **Detection rules**: field matching, wildcards, boolean conditions, field modifiers
8//! - **Condition expressions**: `and`, `or`, `not`, `1 of`, `all of`, parenthesized groups
9//! - **Correlation rules**: `event_count`, `value_count`, `temporal`, aggregations
10//! - **Filter rules**: additional conditions applied to referenced rules
11//! - **Rule collections**: multi-document YAML, `action: global/reset/repeat`
12//! - **Value types**: strings with wildcards, numbers, booleans, null, regex, CIDR
13//! - **All 30+ field modifiers**: `contains`, `endswith`, `startswith`, `re`, `cidr`,
14//!   `base64`, `base64offset`, `wide`, `windash`, `all`, `cased`, `exists`, `fieldref`,
15//!   comparison operators, regex flags, timestamp parts, and more
16//!
17//! ## Architecture
18//!
19//! - **PEG grammar** ([`pest`]) for condition expression parsing with correct operator
20//!   precedence (`NOT` > `AND` > `OR`) and Pratt parsing
21//! - **yaml_serde** for YAML structure deserialization
22//! - **Custom parsing** for field modifiers, wildcard strings, and timespan values
23//! - **Semantic validation** ([`validate`]) rejects invalid rules before lowering: a
24//!   missing or unusable logsource, conflicting modifiers, values of the wrong type
25//!   for their modifiers, invalid regular expressions and CIDR networks, empty
26//!   detections, and conditions that reference undefined detections
27//!
28//! ## Quick Start
29//!
30//! ```rust
31//! use rsigma_parser::parse_sigma_yaml;
32//!
33//! let yaml = r#"
34//! title: Detect Whoami
35//! logsource:
36//!     product: windows
37//!     category: process_creation
38//! detection:
39//!     selection:
40//!         CommandLine|contains: 'whoami'
41//!     condition: selection
42//! level: medium
43//! "#;
44//!
45//! let collection = parse_sigma_yaml(yaml).unwrap();
46//! assert_eq!(collection.rules.len(), 1);
47//! assert_eq!(collection.rules[0].title, "Detect Whoami");
48//! ```
49//!
50//! ## Parsing condition expressions
51//!
52//! ```rust
53//! use rsigma_parser::parse_condition;
54//!
55//! let expr = parse_condition("selection_main and 1 of selection_dword_* and not 1 of filter_*").unwrap();
56//! println!("{expr}");
57//! ```
58
59pub mod ads;
60pub mod ast;
61pub mod condition;
62pub mod emit;
63pub mod error;
64pub mod exemplar;
65pub mod fieldpath;
66pub mod lint;
67pub mod parser;
68pub mod reference;
69pub mod selector;
70pub mod validate;
71pub mod value;
72pub mod version;
73
74// Re-export the most commonly used types and functions at crate root
75pub use ads::{
76    AdsCarrier, AdsContent, AdsDocument, AdsScaffoldEntry, AdsSection, AdsSectionInfo,
77    AdsSectionStatus, ads_catalogue,
78};
79pub use ast::{
80    ArrayQuantifier, ConditionExpr, ConditionOperator, CorrelationCondition, CorrelationRule,
81    CorrelationType, Detection, DetectionItem, Detections, FieldAlias, FieldSpec, FilterRule,
82    FilterRuleTarget, Level, LogSource, Modifier, Quantifier, Related, RelationType,
83    SelectorPattern, SigmaCollection, SigmaDocument, SigmaRule, Status, WindowMode,
84};
85pub use condition::parse_condition;
86pub use emit::{emit_collection_yaml, emit_rule_yaml};
87pub use error::{Result, SigmaParserError, SourceLocation};
88pub use exemplar::{
89    EXEMPLARS_KEY, Exemplar, ExemplarErrorKind, ExemplarPayload, ExemplarRuleKind,
90    ExemplarShapeError, Expect, TimedEvent, correlation_exemplars, exemplars, exemplars_from_attrs,
91    filter_exemplars, match_exemplar_count, match_exemplar_count_json, parse_exemplars,
92    raw_exemplar_values, raw_match_exemplar_count, raw_winning_exemplars,
93};
94pub use lint::catalogue::{LintRuleInfo, catalogue};
95#[cfg(feature = "fix")]
96pub use lint::fix::{SourceFixOutcome, apply_fixes_to_source};
97pub use lint::{
98    AdsConfig, FileLintResult, Fix, FixDisposition, FixPatch, InlineSuppressions, LintConfig,
99    LintRule, LintWarning, Severity, Span, apply_suppressions, lint_yaml_directory,
100    lint_yaml_directory_with_config, lint_yaml_file, lint_yaml_file_with_config, lint_yaml_str,
101    lint_yaml_str_with_config, lint_yaml_value, parse_inline_suppressions,
102};
103pub use parser::{parse_field_spec, parse_sigma_directory, parse_sigma_file, parse_sigma_yaml};
104pub use selector::detection_name_matches;
105pub use value::{SigmaString, SigmaValue, SpecialChar, StringPart, Timespan};
106pub use version::{
107    SPEC_VERSION_ARRAY_MATCHING, SPEC_VERSION_FLOOR, SPEC_VERSION_SUPPORTED,
108    array_matching_enabled, is_unsupported, resolve_major,
109};