Skip to content

Commit

Permalink
Merge pull request #155 from frack113/references_duplicate
Browse files Browse the repository at this point in the history
Add DuplicateReferencesValidator
  • Loading branch information
thomaspatzke authored Nov 4, 2023
2 parents ae7c544 + 991ff3f commit b1475a4
Show file tree
Hide file tree
Showing 2 changed files with 64 additions and 0 deletions.
20 changes: 20 additions & 0 deletions sigma/validators/core/metadata.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
from collections import Counter
from collections import defaultdict
from dataclasses import dataclass
from typing import ClassVar, Dict, List
Expand Down Expand Up @@ -94,3 +95,22 @@ def finalize(self) -> List[SigmaValidationIssue]:
for title, rules in self.titles.items()
if len(rules) > 1
]


@dataclass
class DuplicateReferencesIssue(SigmaValidationIssue):
description = "The same references appears multiple times"
severity = SigmaValidationIssueSeverity.MEDIUM
reference: str


class DuplicateReferencesValidator(SigmaRuleValidator):
"""Validate rule References uniqueness."""

def validate(self, rule: SigmaRule) -> List[SigmaValidationIssue]:
references = Counter(rule.references)
return [
DuplicateReferencesIssue([rule], reference)
for reference, count in references.items()
if count > 1
]
44 changes: 44 additions & 0 deletions tests/test_validators.py
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@
TitleLengthValidator,
DuplicateTitleIssue,
DuplicateTitleValidator,
DuplicateReferencesIssue,
DuplicateReferencesValidator,
)
from sigma.validators.core.condition import (
AllOfThemConditionIssue,
Expand Down Expand Up @@ -898,3 +900,45 @@ def test_validator_duplicate_title_valid():
"""
)
assert validator.validate(rule) == []


def test_validator_duplicate_references():
validator = DuplicateReferencesValidator()
rule = SigmaRule.from_yaml(
"""
title: Test
references:
- ref_a
- ref_b
- ref_a
status: test
logsource:
category: test
detection:
sel:
field: value
condition: sel
"""
)
assert validator.validate(rule) == [DuplicateReferencesIssue([rule], "ref_a")]


def test_validator_duplicate_references_valid():
validator = DuplicateReferencesValidator()
rule = SigmaRule.from_yaml(
"""
title: Test
references:
- ref_a
- ref_b
- ref_c
status: test
logsource:
category: test
detection:
sel:
field: value
condition: sel
"""
)
assert validator.validate(rule) == []

0 comments on commit b1475a4

Please sign in to comment.