-
Notifications
You must be signed in to change notification settings - Fork 231
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Rules folders not loading correctly #21
Comments
Hi @jimbowaba I'm not able to replicate this on my side. There is "default" rules folder, the rules folder must always be specified via the "--rules" flag.
As you can see with the above, 979 rules were loaded when pointing at the "../../sigma_rules" folder, but when I specify a different directory:
Only 54 detection rules are loaded, which to me would mean that chainsaw is using the specified path. Could you please provide steps to reproduce your issue? Thanks. |
Hi @fscc-jamesd thanks for your speedy reply (and awesome tool). A few of us spent a while looking into this and realised that it was a misunderstanding on our part. We didn't realise that the rule output would show the built in logic in every result, we assumed that specifying a ruleset would only show results specific to that ruleset. As we were choosing small ruleset that weren't hitting it was only returning the built in logic, thus confusing us. It would be useful if there was an option to turn this off to only output the specified rules. Thanks for your help |
Hey @jimbowaba Ah, I understand. There's the option |
No matter what folder you specify it seems to load the default rules folder
The text was updated successfully, but these errors were encountered: