Skip to content

Rustinel v1.5.0

Choose a tag to compare

@github-actions github-actions released this 05 Sep 20:23
· 160 commits to main since this release
12222d3

Rustinel 1.5.0: correlated detection, stronger fidelity

Rustinel 1.5 makes Sigma detection more capable and the live sensor pipeline more resilient. RSigma is now the single Sigma engine, with correlation and filter rule evaluation built into the same path used by live monitoring and replay. Windows burst handling, rule reload behavior, and hot-path allocation costs have also been tightened.

Changes

Sigma detection

  • Sigma correlation and filter documents are now evaluated, including event-count and temporal correlations.
  • Detection rules are compiled into one shared engine, improving evaluation performance on large rulesets.
  • A pinned SigmaHQ compatibility gate now continuously checks the supported corpus.

Reliability and performance

  • Windows event buffering and flush behavior preserve detection fidelity under burst load and report accepted and dropped events by category.
  • Rule hot reload ignores access-only filesystem notifications, preventing self-sustaining CPU loops on large rule trees.
  • PE metadata enrichment runs outside the ETW callback, the PE cache is bounded, and IOC and Sigma matching avoid several redundant allocations.
  • Runtime, reload, test, and allowlist internals have been simplified without changing their external behavior.

Upgrading from 1.4.x

Existing configuration files continue to load. The former scanner.sigma_engine setting is ignored, while scripts using the removed --sigma-engine command-line flag must remove it. The rsigma-engine Cargo feature has also been removed.

Downloads

Platform Architecture Package
Linux x86_64 rustinel-1.5.0-x86_64-unknown-linux-musl.tar.gz
Linux arm64 rustinel-1.5.0-aarch64-unknown-linux-musl.tar.gz
Windows x86_64 rustinel-1.5.0-x86_64-pc-windows-msvc.zip
macOS arm64 rustinel-1.5.0-aarch64-apple-darwin.tar.gz
macOS x86_64 rustinel-1.5.0-x86_64-apple-darwin.tar.gz

Installer

Linux

curl -fsSL https://rustinel.io/install.sh | sh -s -- --version 1.5.0 --run

macOS

curl -fsSL https://rustinel.io/install.sh | sh -s -- --version 1.5.0
cd rustinel

macOS support is experimental. Endpoint Security requires root and a one-time Full Disk Access approval before the first successful start. See the install guide for the interactive terminal and LaunchDaemon approval paths, then run:

sudo ./rustinel run

Windows (PowerShell)

$env:RUSTINEL_VERSION='1.5.0'; irm https://rustinel.io/install.ps1 | iex; Remove-Item Env:\RUSTINEL_VERSION -ErrorAction SilentlyContinue

Full install, configuration, and SIEM ingestion guides: https://docs.rustinel.io/getting-started/

Scripts install published release binaries only. Verify downloads with rustinel-1.5.0-checksums-sha256.txt.

Provenance

All release artifacts have SLSA build provenance attestations signed by GitHub:

gh attestation verify <artifact> \
  --repo Karib0u/rustinel \
  --signer-workflow Karib0u/rustinel/.github/workflows/release.yml

What's Changed

Features

  • feat(engine): make RSigma the only Sigma engine and evaluate correlations by @Karib0u in #345
  • feat(sigma): add pinned SigmaHQ compatibility gate by @Karib0u in #370
  • perf(core): remove redundant IOC and Sigma allocations by @Karib0u in #372

Bug Fixes

  • fix(reload): ignore access-only watcher events by @Karib0u in #362
  • fix(utils): bound PE metadata cache by @Karib0u in #363
  • fix(windows): preserve detection fidelity under burst load by @Karib0u in #364
  • fix(tests): avoid response PID collision by @Karib0u in #366

Refactoring

  • perf(windows-etw): move PE enrichment out of callback by @Karib0u in #365
  • refactor(reload): separate detector state and reload responsibilities by @Karib0u in #373
  • refactor(runtime): share Linux and macOS command dispatch by @Karib0u in #374
  • refactor(runtime): share live detection pipeline construction by @Karib0u in #386
  • refactor(runtime): centralize worker drain and final flush ordering by @Karib0u in #387
  • refactor(etw): separate session routing state and record decoding by @Karib0u in #388
  • refactor(allowlist): centralize path matching with explicit compatibility policies by @Karib0u in #389
  • refactor(tests): move configuration and rule-pack tests into sibling modules by @Karib0u in #391
  • refactor(runtime): share configuration and logging startup by @Karib0u in #390

Documentation

  • docs(limitations): record four unlisted silent-risk gaps by @Karib0u in #358
  • docs(readme): clarify cross-platform detection positioning and onboarding by @Karib0u in #392

CI and release

  • fix(ci): update workflow action version pins by @Karib0u in #356
  • ci: skip duplicate atomic tests on releases by @Karib0u in #359
  • chore(deps): bump taiki-e/install-action from 2.86.7 to 2.87.0 by @dependabot[bot] in #367
  • chore(deps): bump astral-sh/setup-uv from 7.6.0 to 10.0.1 by @dependabot[bot] in #368

Dependencies

  • chore(deps): bump yara-x from 1.19.0 to 1.20.0 by @dependabot[bot] in #369

Maintenance

Other Changes

  • fix(ci): consume validated Windows Run key atomic by @Karib0u in #396

Full Changelog: v1.4.1...v1.5.0