Skip to content

v0.5.1 - YARA rule export

Choose a tag to compare

@HalfTimeOfLife HalfTimeOfLife released this 29 Jul 09:53
· 21 commits to main since this release

Fifth release of mispSK.

Added

  • export_yara.py: generate a YARA rule from a MISP event's static IOCs (hashes, filenames, patterns, registry keys, mutexes) plus network indicators as plain string matches
  • mispsk/yara.py: classify_confidence_tier, filter_yara_candidates, escape_yara_string, build_hash_condition, extract_analyst_rule, build_yara_rule
  • mispsk/export_common.py: filter_attributes_by_type, sanitize_identifier - shared helpers for the upcoming export_splunk.py (v0.5.2)
  • Three-tier confidence model: strong (md5/sha1/sha256, any match suffices), medium (filename/pattern-in-file/regkey/mutex/..., any match suffices), weak (network indicators as string matches only, 2+ required)
  • Analyst-authored yara-type attributes are extracted and appended as separate rules rather than folded into the generated one
  • Optional syntax validation via yara-python before any output is produced
  • tests/test_yara.py, tests/test_export_common.py

Changed

  • Split mispsk/utils.py into ioc.py, dates.py, summary.py, with enrichment.py/feeds.py absorbing their remaining helpers, as groundwork for the export scripts introduced in this release

Known limitation

  • YARA is a static-only detection format: network-oriented MISP attributes (ip-src, ip-dst, domain, url, etc.) can only be included as plain string matches, never as real network-level detection
  • Hash types not computable by YARA's built-in hash module (ssdeep, tlsh, imphash, sha512, etc.) are skipped rather than included in the generated condition

See CHANGELOG.md for full details and ROADMAP.md.