v0.5.1 - YARA rule export
Fifth release of mispSK.
Added
export_yara.py: generate a YARA rule from a MISP event's static IOCs (hashes, filenames, patterns, registry keys, mutexes) plus network indicators as plain string matchesmispsk/yara.py:classify_confidence_tier,filter_yara_candidates,escape_yara_string,build_hash_condition,extract_analyst_rule,build_yara_rulemispsk/export_common.py:filter_attributes_by_type,sanitize_identifier- shared helpers for the upcomingexport_splunk.py(v0.5.2)- Three-tier confidence model: strong (md5/sha1/sha256, any match suffices), medium (filename/pattern-in-file/regkey/mutex/..., any match suffices), weak (network indicators as string matches only, 2+ required)
- Analyst-authored
yara-type attributes are extracted and appended as separate rules rather than folded into the generated one - Optional syntax validation via
yara-pythonbefore any output is produced tests/test_yara.py,tests/test_export_common.py
Changed
- Split
mispsk/utils.pyintoioc.py,dates.py,summary.py, withenrichment.py/feeds.pyabsorbing their remaining helpers, as groundwork for the export scripts introduced in this release
Known limitation
- YARA is a static-only detection format: network-oriented MISP attributes (
ip-src,ip-dst,domain,url, etc.) can only be included as plain string matches, never as real network-level detection - Hash types not computable by YARA's built-in
hashmodule (ssdeep,tlsh,imphash,sha512, etc.) are skipped rather than included in the generated condition
See CHANGELOG.md for full details and ROADMAP.md.