Skip to main content

Module validate

Module validate 

Source
Expand description

Semantic checks on parsed detections.

The parser runs these checks on every detection it builds, so rule parse, lint, the LSP, evaluation, and conversion reject the same invalid rules, as pySigma does when it loads a rule. IR lowering repeats the item checks for detections that are built or rewritten after parsing.

Functionsยง

check_cidr
Check that a |cidr value is address/prefix with no host bits set, as pySigma requires.
check_detection_item
Check one detection item: its modifier chain, and every value against the type its modifiers require.
check_modifiers
Check that a modifier chain sets at most one operator and combines only modifiers that compose.
check_regex
Check that a |re value is a valid regular expression.
exists_flag
The boolean an |exists value stands for.