-
Notifications
You must be signed in to change notification settings - Fork 9
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Fixed sentinelasim pipeline bugs, added basic test for sentinelasim p…
…ipeline
- Loading branch information
1 parent
6d6b133
commit 68e9d47
Showing
3 changed files
with
35 additions
and
4 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
import pytest | ||
from sigma.exceptions import SigmaTransformationError | ||
from sigma.pipelines.microsoft365defender.microsoft365defender import InvalidHashAlgorithmError | ||
|
||
from sigma.backends.kusto import KustoBackend | ||
from sigma.collection import SigmaCollection | ||
from sigma.pipelines.sentinelasim import sentinel_asim_pipeline | ||
|
||
|
||
def test_sentinel_asim_basic_conversion(): | ||
"""Tests splitting username up into different fields if it includes a domain""" | ||
assert KustoBackend(processing_pipeline=sentinel_asim_pipeline()).convert( | ||
SigmaCollection.from_yaml(""" | ||
title: Test | ||
status: test | ||
logsource: | ||
category: process_creation | ||
product: windows | ||
detection: | ||
sel1: | ||
CommandLine: command1 | ||
condition: any of sel* | ||
""") | ||
) == ['imProcessCreate\n| ' | ||
'where TargetProcessCommandLine =~ "command1"'] | ||
|