Skip to content

add: [Rulezet] new rule format - #529

Merged
adulau merged 3 commits into
mainfrom
rulezet_new_format
Sep 11, 2026
Merged

adulau merged 3 commits into
mainfrom
rulezet_new_format

Conversation

@ecrou-exact

Copy link
Copy Markdown
Contributor

Summary

  • Add splunk-rule: Splunk detection/correlation search (SPL), with scheduling, risk score, severity, and MITRE ATT&CK mapping.
  • Add elastic-detection-rule: Elastic Security detection rule (KQL/Lucene/EQL/ES|QL), with scheduling, risk score, severity, and MITRE ATT&CK mapping.
  • Add kql-analytics-rule: Microsoft Sentinel/Defender XDR KQL analytics rule, with scheduling, alert thresholds, entity mappings, and MITRE ATT&CK mapping.

First version with Claude Code.

For rulezet ( to see the rule into pivotick ;) )

Add a dedicated object for a Splunk detection/correlation search (SPL query), covering scheduling, risk score, severity, and MITRE ATT&CK mapping.
Add a dedicated object for an Elastic Security detection rule (KQL, Lucene, EQL, or ES|QL query), covering scheduling, risk score, severity, and MITRE ATT&CK mapping.
Add a dedicated object for a Microsoft Sentinel or Defender XDR KQL analytics rule, covering scheduling, alert thresholds, entity mappings, and MITRE ATT&CK mapping.
@ecrou-exact ecrou-exact changed the title Rulezet new format add: [Rulezet] new rule format Sep 11, 2026
@adulau
adulau merged commit a021b8d into main Sep 11, 2026
7 checks passed
@adulau

adulau commented Sep 11, 2026

Copy link
Copy Markdown
Member

Thank you!

ecrou-exact added a commit to rulezet/rulezet-core that referenced this pull request Sep 11, 2026
…mplates

MISP/misp-objects#529 (merged) added splunk-rule, elastic-detection-rule
and kql-analytics-rule templates — the 3 rule formats Rulezet already
supports (Rule.format == 'splunk'/'elastic'/'kql') had no MISP object
mapping yet, unlike yara/sigma/suricata/wazuh/nse/crs/nova.

pymisp's bundled misp-objects data doesn't include these new templates
yet (checked: definition.json absent from the installed package), so
each is vendored locally under object_templates/ and passed via
misp_objects_template_custom — the same approach already used for
Rulezet's own custom rulezet-metadata/rulezet-bundle objects.

Mapping follows the existing minimal convention (full rule content in
the primary query attribute + title as rule-name), same level of
support as every other format. Verified end-to-end against real
splunk/elastic/kql rules in the local DB — both the single-object and
full-event export paths produce the right object alongside
rulezet-metadata.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
ecrou-exact added a commit to rulezet/rulezet-core that referenced this pull request Sep 11, 2026
…mplates

MISP/misp-objects#529 (merged) added splunk-rule, elastic-detection-rule
and kql-analytics-rule templates — the 3 rule formats Rulezet already
supports (Rule.format == 'splunk'/'elastic'/'kql') had no MISP object
mapping yet, unlike yara/sigma/suricata/wazuh/nse/crs/nova.

pymisp's bundled misp-objects data doesn't include these new templates
yet (checked: definition.json absent from the installed package), so
each is vendored locally under object_templates/ and passed via
misp_objects_template_custom — the same approach already used for
Rulezet's own custom rulezet-metadata/rulezet-bundle objects.

Mapping follows the existing minimal convention (full rule content in
the primary query attribute + title as rule-name), same level of
support as every other format. Verified end-to-end against real
splunk/elastic/kql rules in the local DB — both the single-object and
full-event export paths produce the right object alongside
rulezet-metadata.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants