2017-02-13 23:14:40 +01:00
|
|
|
# Output backends for sigmac
|
2018-07-24 00:01:16 +02:00
|
|
|
# Copyright 2018 SOC Prime
|
2017-12-07 21:55:43 +01:00
|
|
|
|
|
|
|
|
# This program is free software: you can redistribute it and/or modify
|
|
|
|
|
# it under the terms of the GNU Lesser General Public License as published by
|
|
|
|
|
# the Free Software Foundation, either version 3 of the License, or
|
|
|
|
|
# (at your option) any later version.
|
|
|
|
|
|
|
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
|
# GNU Lesser General Public License for more details.
|
|
|
|
|
|
|
|
|
|
# You should have received a copy of the GNU Lesser General Public License
|
|
|
|
|
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
2017-02-13 23:14:40 +01:00
|
|
|
|
2017-02-22 22:47:12 +01:00
|
|
|
import sigma
|
2018-07-20 23:30:32 +02:00
|
|
|
from .base import SingleTextQueryBackend
|
|
|
|
|
from .exceptions import PartialMatchError, FullMatchError
|
2018-06-07 16:18:23 +03:00
|
|
|
|
|
|
|
|
class QualysBackend(SingleTextQueryBackend):
|
2018-06-07 23:31:09 +02:00
|
|
|
"""Converts Sigma rule into Qualys saved search. Contributed by SOC Prime. https://socprime.com"""
|
2018-06-07 16:18:23 +03:00
|
|
|
identifier = "qualys"
|
|
|
|
|
active = True
|
2019-11-03 23:32:50 +01:00
|
|
|
config_required = False
|
|
|
|
|
default_config = ["sysmon", "qualys"]
|
2018-06-07 16:18:23 +03:00
|
|
|
andToken = " and "
|
|
|
|
|
orToken = " or "
|
|
|
|
|
notToken = "not "
|
|
|
|
|
subExpression = "(%s)"
|
|
|
|
|
listExpression = "%s"
|
|
|
|
|
listSeparator = " "
|
|
|
|
|
valueExpression = "%s"
|
|
|
|
|
nullExpression = "%s is null"
|
|
|
|
|
notNullExpression = "not (%s is null)"
|
|
|
|
|
mapExpression = "%s:`%s`"
|
|
|
|
|
mapListsSpecialHandling = True
|
|
|
|
|
PartialMatchFlag = False
|
|
|
|
|
|
|
|
|
|
def __init__(self, *args, **kwargs):
|
|
|
|
|
super().__init__(*args, **kwargs)
|
|
|
|
|
fl = []
|
|
|
|
|
for item in self.sigmaconfig.fieldmappings.values():
|
|
|
|
|
if item.target_type == list:
|
|
|
|
|
fl.extend(item.target)
|
|
|
|
|
else:
|
|
|
|
|
fl.append(item.target)
|
|
|
|
|
self.allowedFieldsList = list(set(fl))
|
|
|
|
|
|
|
|
|
|
def generateORNode(self, node):
|
|
|
|
|
new_list = []
|
|
|
|
|
for val in node:
|
|
|
|
|
if type(val) == tuple and not(val[0] in self.allowedFieldsList):
|
|
|
|
|
pass
|
|
|
|
|
# self.PartialMatchFlag = True
|
|
|
|
|
else:
|
|
|
|
|
new_list.append(val)
|
|
|
|
|
|
2018-06-22 00:41:21 +02:00
|
|
|
generated = [self.generateNode(val) for val in new_list]
|
|
|
|
|
filtered = [g for g in generated if g is not None]
|
|
|
|
|
return self.orToken.join(filtered)
|
2018-06-07 16:18:23 +03:00
|
|
|
|
|
|
|
|
def generateANDNode(self, node):
|
|
|
|
|
new_list = []
|
|
|
|
|
for val in node:
|
|
|
|
|
if type(val) == tuple and not(val[0] in self.allowedFieldsList):
|
|
|
|
|
self.PartialMatchFlag = True
|
|
|
|
|
else:
|
|
|
|
|
new_list.append(val)
|
2018-06-22 00:41:21 +02:00
|
|
|
generated = [self.generateNode(val) for val in new_list]
|
|
|
|
|
filtered = [g for g in generated if g is not None]
|
|
|
|
|
return self.andToken.join(filtered)
|
2018-06-07 16:18:23 +03:00
|
|
|
|
|
|
|
|
def generateMapItemNode(self, node):
|
|
|
|
|
key, value = node
|
|
|
|
|
if self.mapListsSpecialHandling == False and type(value) in (str, int, list) or self.mapListsSpecialHandling == True and type(value) in (str, int):
|
|
|
|
|
if key in self.allowedFieldsList:
|
|
|
|
|
return self.mapExpression % (key, self.generateNode(value))
|
|
|
|
|
else:
|
|
|
|
|
return self.generateNode(value)
|
|
|
|
|
elif type(value) == list:
|
|
|
|
|
return self.generateMapItemListNode(key, value)
|
|
|
|
|
else:
|
|
|
|
|
raise TypeError("Backend does not support map values of type " + str(type(value)))
|
|
|
|
|
|
|
|
|
|
def generateMapItemListNode(self, key, value):
|
|
|
|
|
itemslist = []
|
|
|
|
|
for item in value:
|
|
|
|
|
if key in self.allowedFieldsList:
|
|
|
|
|
itemslist.append('%s:`%s`' % (key, self.generateValueNode(item)))
|
|
|
|
|
else:
|
|
|
|
|
itemslist.append('%s' % (self.generateValueNode(item)))
|
|
|
|
|
return "(" + (" or ".join(itemslist)) + ")"
|
|
|
|
|
|
|
|
|
|
def generate(self, sigmaparser):
|
|
|
|
|
"""Method is called for each sigma rule and receives the parsed rule (SigmaParser)"""
|
|
|
|
|
all_keys = set()
|
|
|
|
|
|
|
|
|
|
for parsed in sigmaparser.condparsed:
|
2018-06-07 23:31:09 +02:00
|
|
|
query = self.generateQuery(parsed)
|
|
|
|
|
if query == "()":
|
2018-06-07 16:18:23 +03:00
|
|
|
self.PartialMatchFlag = None
|
2018-06-07 23:31:09 +02:00
|
|
|
|
2018-06-07 16:18:23 +03:00
|
|
|
if self.PartialMatchFlag == True:
|
2018-06-07 23:31:09 +02:00
|
|
|
raise PartialMatchError(query)
|
2018-06-07 16:18:23 +03:00
|
|
|
elif self.PartialMatchFlag == None:
|
2018-06-07 23:31:09 +02:00
|
|
|
raise FullMatchError(query)
|
2018-06-07 16:18:23 +03:00
|
|
|
else:
|
2018-08-02 22:41:32 +02:00
|
|
|
return query
|