pub enum RuleId {
Show 80 variants
NonAsciiHostname,
PunycodeDomain,
MixedScriptInLabel,
UserinfoTrick,
ConfusableDomain,
RawIpUrl,
NonStandardPort,
InvalidHostChars,
TrailingDotWhitespace,
LookalikeTld,
NonAsciiPath,
HomoglyphInPath,
DoubleEncoding,
PlainHttpToSink,
SchemelessToSink,
InsecureTlsFlags,
ShortenedUrl,
AnsiEscapes,
ControlChars,
BidiControls,
ZeroWidthChars,
HiddenMultiline,
UnicodeTags,
InvisibleMathOperator,
VariationSelector,
InvisibleWhitespace,
PipeToInterpreter,
CurlPipeShell,
WgetPipeShell,
HttpiePipeShell,
XhPipeShell,
DotfileOverwrite,
ArchiveExtract,
ProcMemAccess,
DockerRemotePrivEsc,
CredentialFileSweep,
Base64DecodeExecute,
DataExfiltration,
DynamicCodeExecution,
ObfuscatedPayload,
SuspiciousCodeExfiltration,
ProxyEnvSet,
SensitiveEnvExport,
CodeInjectionEnv,
InterpreterHijackEnv,
ShellInjectionEnv,
MetadataEndpoint,
PrivateNetworkAccess,
CommandNetworkDeny,
ConfigInjection,
ConfigSuspiciousIndicator,
ConfigMalformed,
ConfigNonAscii,
ConfigInvisibleUnicode,
McpInsecureServer,
McpUntrustedServer,
McpDuplicateServerName,
McpOverlyPermissive,
McpSuspiciousArgs,
GitTyposquat,
DockerUntrustedRegistry,
PipUrlInstall,
NpmUrlInstall,
Web3RpcEndpoint,
Web3AddressInUrl,
VetNotConfigured,
HiddenCssContent,
HiddenColorContent,
HiddenHtmlAttribute,
MarkdownComment,
HtmlComment,
ServerCloaking,
ClipboardHidden,
PdfHiddenText,
CredentialInText,
HighEntropySecret,
PrivateKeyExposed,
PolicyBlocklisted,
CustomRuleMatch,
LicenseRequired,
}Expand description
Unique identifier for each detection rule.
Variants§
NonAsciiHostname
PunycodeDomain
MixedScriptInLabel
UserinfoTrick
ConfusableDomain
RawIpUrl
NonStandardPort
InvalidHostChars
TrailingDotWhitespace
LookalikeTld
NonAsciiPath
HomoglyphInPath
DoubleEncoding
PlainHttpToSink
SchemelessToSink
InsecureTlsFlags
ShortenedUrl
AnsiEscapes
ControlChars
BidiControls
ZeroWidthChars
HiddenMultiline
UnicodeTags
InvisibleMathOperator
VariationSelector
InvisibleWhitespace
PipeToInterpreter
CurlPipeShell
WgetPipeShell
HttpiePipeShell
XhPipeShell
DotfileOverwrite
ArchiveExtract
ProcMemAccess
DockerRemotePrivEsc
CredentialFileSweep
Base64DecodeExecute
DataExfiltration
DynamicCodeExecution
ObfuscatedPayload
SuspiciousCodeExfiltration
ProxyEnvSet
SensitiveEnvExport
CodeInjectionEnv
InterpreterHijackEnv
ShellInjectionEnv
MetadataEndpoint
PrivateNetworkAccess
CommandNetworkDeny
ConfigInjection
ConfigSuspiciousIndicator
ConfigMalformed
ConfigNonAscii
ConfigInvisibleUnicode
McpInsecureServer
McpUntrustedServer
McpDuplicateServerName
McpOverlyPermissive
McpSuspiciousArgs
GitTyposquat
DockerUntrustedRegistry
PipUrlInstall
NpmUrlInstall
Web3RpcEndpoint
Web3AddressInUrl
VetNotConfigured
HiddenCssContent
HiddenColorContent
HiddenHtmlAttribute
MarkdownComment
HtmlComment
ServerCloaking
ClipboardHidden
PdfHiddenText
CredentialInText
HighEntropySecret
PrivateKeyExposed
PolicyBlocklisted
CustomRuleMatch
LicenseRequired
Trait Implementations§
Source§impl<'de> Deserialize<'de> for RuleId
impl<'de> Deserialize<'de> for RuleId
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
impl Copy for RuleId
impl Eq for RuleId
impl StructuralPartialEq for RuleId
Auto Trait Implementations§
impl Freeze for RuleId
impl RefUnwindSafe for RuleId
impl Send for RuleId
impl Sync for RuleId
impl Unpin for RuleId
impl UnsafeUnpin for RuleId
impl UnwindSafe for RuleId
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
Source§impl<T> ToStringFallible for Twhere
T: Display,
impl<T> ToStringFallible for Twhere
T: Display,
Source§fn try_to_string(&self) -> Result<String, TryReserveError>
fn try_to_string(&self) -> Result<String, TryReserveError>
ToString::to_string, but without panic on OOM.