Rustinel v1.5.0
Rustinel 1.5.0: correlated detection, stronger fidelity
Rustinel 1.5 makes Sigma detection more capable and the live sensor pipeline more resilient. RSigma is now the single Sigma engine, with correlation and filter rule evaluation built into the same path used by live monitoring and replay. Windows burst handling, rule reload behavior, and hot-path allocation costs have also been tightened.
Changes
Sigma detection
- Sigma correlation and filter documents are now evaluated, including event-count and temporal correlations.
- Detection rules are compiled into one shared engine, improving evaluation performance on large rulesets.
- A pinned SigmaHQ compatibility gate now continuously checks the supported corpus.
Reliability and performance
- Windows event buffering and flush behavior preserve detection fidelity under burst load and report accepted and dropped events by category.
- Rule hot reload ignores access-only filesystem notifications, preventing self-sustaining CPU loops on large rule trees.
- PE metadata enrichment runs outside the ETW callback, the PE cache is bounded, and IOC and Sigma matching avoid several redundant allocations.
- Runtime, reload, test, and allowlist internals have been simplified without changing their external behavior.
Upgrading from 1.4.x
Existing configuration files continue to load. The former scanner.sigma_engine setting is ignored, while scripts using the removed --sigma-engine command-line flag must remove it. The rsigma-engine Cargo feature has also been removed.
Downloads
| Platform | Architecture | Package |
|---|---|---|
| Linux | x86_64 | rustinel-1.5.0-x86_64-unknown-linux-musl.tar.gz |
| Linux | arm64 | rustinel-1.5.0-aarch64-unknown-linux-musl.tar.gz |
| Windows | x86_64 | rustinel-1.5.0-x86_64-pc-windows-msvc.zip |
| macOS | arm64 | rustinel-1.5.0-aarch64-apple-darwin.tar.gz |
| macOS | x86_64 | rustinel-1.5.0-x86_64-apple-darwin.tar.gz |
Installer
Linux
curl -fsSL https://rustinel.io/install.sh | sh -s -- --version 1.5.0 --runmacOS
curl -fsSL https://rustinel.io/install.sh | sh -s -- --version 1.5.0
cd rustinelmacOS support is experimental. Endpoint Security requires root and a one-time Full Disk Access approval before the first successful start. See the install guide for the interactive terminal and LaunchDaemon approval paths, then run:
sudo ./rustinel runWindows (PowerShell)
$env:RUSTINEL_VERSION='1.5.0'; irm https://rustinel.io/install.ps1 | iex; Remove-Item Env:\RUSTINEL_VERSION -ErrorAction SilentlyContinueFull install, configuration, and SIEM ingestion guides: https://docs.rustinel.io/getting-started/
Scripts install published release binaries only. Verify downloads with rustinel-1.5.0-checksums-sha256.txt.
Provenance
All release artifacts have SLSA build provenance attestations signed by GitHub:
gh attestation verify <artifact> \
--repo Karib0u/rustinel \
--signer-workflow Karib0u/rustinel/.github/workflows/release.ymlWhat's Changed
Features
- feat(engine): make RSigma the only Sigma engine and evaluate correlations by @Karib0u in #345
- feat(sigma): add pinned SigmaHQ compatibility gate by @Karib0u in #370
- perf(core): remove redundant IOC and Sigma allocations by @Karib0u in #372
Bug Fixes
- fix(reload): ignore access-only watcher events by @Karib0u in #362
- fix(utils): bound PE metadata cache by @Karib0u in #363
- fix(windows): preserve detection fidelity under burst load by @Karib0u in #364
- fix(tests): avoid response PID collision by @Karib0u in #366
Refactoring
- perf(windows-etw): move PE enrichment out of callback by @Karib0u in #365
- refactor(reload): separate detector state and reload responsibilities by @Karib0u in #373
- refactor(runtime): share Linux and macOS command dispatch by @Karib0u in #374
- refactor(runtime): share live detection pipeline construction by @Karib0u in #386
- refactor(runtime): centralize worker drain and final flush ordering by @Karib0u in #387
- refactor(etw): separate session routing state and record decoding by @Karib0u in #388
- refactor(allowlist): centralize path matching with explicit compatibility policies by @Karib0u in #389
- refactor(tests): move configuration and rule-pack tests into sibling modules by @Karib0u in #391
- refactor(runtime): share configuration and logging startup by @Karib0u in #390
Documentation
- docs(limitations): record four unlisted silent-risk gaps by @Karib0u in #358
- docs(readme): clarify cross-platform detection positioning and onboarding by @Karib0u in #392
CI and release
- fix(ci): update workflow action version pins by @Karib0u in #356
- ci: skip duplicate atomic tests on releases by @Karib0u in #359
- chore(deps): bump taiki-e/install-action from 2.86.7 to 2.87.0 by @dependabot[bot] in #367
- chore(deps): bump astral-sh/setup-uv from 7.6.0 to 10.0.1 by @dependabot[bot] in #368
Dependencies
- chore(deps): bump yara-x from 1.19.0 to 1.20.0 by @dependabot[bot] in #369
Maintenance
- chore: prepare release 1.5.0-rc.1 by @Karib0u in #371
- chore(release): prepare 1.5.0 by @Karib0u in #395
Other Changes
Full Changelog: v1.4.1...v1.5.0