-
Notifications
You must be signed in to change notification settings - Fork 259
Description
Describe the bug
Number of 'expand' rules displayed in standard output is always 0.
(except for live-response package)
Step to Reproduce
./hayabusa csv-timeline -d ../hayabusa-sample-evtx -w -C -q -o timeline.csv
Actual behavior
% ./hayabusa-3.1.0-mac-aarch64 csv-timeline -d ../hayabusa-sample-evtx -w -C -q -o timeline.csv
Start time: 2025/02/25 23:14
Total event log files: 598
Total file size: 139.2 MB
Loading detection rules. Please wait.
Excluded rules: 26
Noisy rules: 12 (Disabled)
Deprecated rules: 215 (4.94%) (Disabled)
Experimental rules: 234 (5.38%)
Stable rules: 243 (5.59%)
Test rules: 3,871 (89.03%)
Unsupported rules: 42 (0.97%) (Disabled)
Correlation rules: 3 (0.07%)
Correlation referenced rules: 3 (0.07%)
Expand rules: 0 (0.00%)
Enabled expand rules: 0 (0.00%)
...
Expected behavior
% ./hayabusa-3.1.0-mac-aarch64 csv-timeline -d ../hayabusa-sample-evtx -w -C -q -o timeline.csv
...
Expand rules: 10 (0.28%)
Enabled expand rules: 0 (0.00%)
...
Environment:
- OS: macOS Sequoia 15.3.1
- hayabusa version: 3.0.0 ~ (Since the released version of the expand rule feature)
Additional context
N/A
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working