Skip to content

[bug] Encoded rules missing rule name #1572

@crayy8

Description

@crayy8

Describe the bug
There are 4 rules in the live response encoded rule that do not have rule names. I believe the issue is that some rule files have multiple rules in them which is not being accounted for when generating the encoded rules for live response.

Image showing that there are 4 more rule titles than rule file names and that there are no duplicate rule names
Image

The two I saw from the test data are:

Step to Reproduce
Steps to reproduce the behavior:

  1. Use latest live response binary and latest encoded ruleset. Run against the hayabusa test data set and observe that some hits (as mentioned above) to not have data in the "rulefile" fields for json-timeline

Image

Expected behavior
All rules have a rule file name so rules can be identified in json-timeline output

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions