You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fukusuket
changed the title
[bug] ttp-visualize command does not extract count related rule
[bug] ttp-visualize/ttp-summary command does not extract count related rule
Mar 14, 2024
Describe the bug
I noticed this while testing #135 ...
The
ttp-visualize
command does not extract rules using count such asPW Spray
.Step to Reproduce
hayabusa json-timeline -d hayabusa-sample-evtx -o timeline.jsonl -L -w
takajo-2.4.0 ttp-visualize -t timeline.jsonl -o ttp-old.json
takajo-dev ttp-visualize -t timeline.jsonl -o ttp-new.json
diff ttp-old.json ttp-new.json
Expected behavior
There is no difference.
Actual behavior
There is following diff.
Environment (please complete the following information):
Additional context
This seems to be a regression when the following feature was introduced.
I'm expecting
EventID
to be of typeint
, but for thecount
rule it'sstring
, so it seems like the json conversion fails and it doesn't get output.The text was updated successfully, but these errors were encountered: