Files
sigma-rules/detection_rules/action.py
T

72 lines
1.8 KiB
Python
Raw Normal View History

2024-08-06 18:07:12 -04:00
# Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one
# or more contributor license agreements. Licensed under the Elastic License
# 2.0; you may not use this file except in compliance with the Elastic License
# 2.0.
"""Dataclasses for Action."""
2024-08-06 18:07:12 -04:00
from dataclasses import dataclass
from pathlib import Path
from typing import Any
2024-08-06 18:07:12 -04:00
from .mixins import MarshmallowDataclassMixin
from .schemas import definitions
@dataclass(frozen=True)
class ActionMeta(MarshmallowDataclassMixin):
"""Data stored in an exception's [metadata] section of TOML."""
2024-08-06 18:07:12 -04:00
creation_date: definitions.Date
rule_id: list[definitions.UUIDString]
2024-08-06 18:07:12 -04:00
rule_name: str
updated_date: definitions.Date
# Optional fields
deprecation_date: definitions.Date | None = None
comments: str | None = None
maturity: definitions.Maturity | None = None
2024-08-06 18:07:12 -04:00
@dataclass(frozen=True)
2024-08-06 18:07:12 -04:00
class Action(MarshmallowDataclassMixin):
"""Data object for rule Action."""
2024-08-06 18:07:12 -04:00
@dataclass
class ActionParams:
"""Data object for rule Action params."""
2024-08-06 18:07:12 -04:00
body: str
action_type_id: definitions.ActionTypeId
group: str
params: ActionParams
id: str | None = None
frequency: dict[str, Any] | None = None
alerts_filter: dict[str, Any] | None = None
2024-08-06 18:07:12 -04:00
@dataclass(frozen=True)
class TOMLActionContents(MarshmallowDataclassMixin):
"""Object for action from TOML file."""
2024-08-06 18:07:12 -04:00
metadata: ActionMeta
actions: list[Action]
2024-08-06 18:07:12 -04:00
@dataclass(frozen=True)
class TOMLAction:
"""Object for action from TOML file."""
2024-08-06 18:07:12 -04:00
contents: TOMLActionContents
path: Path
@property
def name(self) -> str:
2024-08-06 18:07:12 -04:00
return self.contents.metadata.rule_name
@property
def id(self) -> list[definitions.UUIDString]:
2024-08-06 18:07:12 -04:00
return self.contents.metadata.rule_id