Skip to content

[bug] Number of expand rules displayed in stdout is invalid #1598

@fukusuket

Description

@fukusuket

Describe the bug
Number of 'expand' rules displayed in standard output is always 0.
(except for live-response package)

Step to Reproduce
./hayabusa csv-timeline -d ../hayabusa-sample-evtx -w -C -q -o timeline.csv

Actual behavior

% ./hayabusa-3.1.0-mac-aarch64 csv-timeline -d ../hayabusa-sample-evtx -w -C -q -o timeline.csv
Start time: 2025/02/25 23:14
Total event log files: 598
Total file size: 139.2 MB

Loading detection rules. Please wait.

Excluded rules: 26
Noisy rules: 12 (Disabled)

Deprecated rules: 215 (4.94%) (Disabled)
Experimental rules: 234 (5.38%)
Stable rules: 243 (5.59%)
Test rules: 3,871 (89.03%)
Unsupported rules: 42 (0.97%) (Disabled)

Correlation rules: 3 (0.07%)
Correlation referenced rules: 3 (0.07%)

Expand rules: 0 (0.00%)
Enabled expand rules: 0 (0.00%)
...

Expected behavior

% ./hayabusa-3.1.0-mac-aarch64 csv-timeline -d ../hayabusa-sample-evtx -w -C -q -o timeline.csv
...
Expand rules: 10 (0.28%)
Enabled expand rules: 0 (0.00%)
...

Environment:

  • OS: macOS Sequoia 15.3.1
  • hayabusa version: 3.0.0 ~ (Since the released version of the expand rule feature)

Additional context
N/A

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions