Skip to content

[bug] Rules run without required fields #1604

Open
@crayy8

Description

@crayy8

Describe the bug
I'm not sure how much of these are bugs so feel free to close if you do not agree. Based off the hayabusa rule documentation there are certain fields that are required and some that are optional. From testing many of the required fields are not really required and will still run without issue.

Required fields (based off documentation) that will still flag items:

  • author
  • date
  • title
  • id
  • status
  • logsource
  • falsepositives
  • ruletype

The only fields that are marked as required that will actually generate an error are:

  • level
  • detection

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions