Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Standard delete function in our rules mapping script #415

Closed
AdriiiPRodri opened this issue Jun 3, 2019 · 1 comment
Closed

Standard delete function in our rules mapping script #415

AdriiiPRodri opened this issue Jun 3, 2019 · 1 comment
Assignees
Labels
enhancement rules Rules related issues
Milestone

Comments

@AdriiiPRodri
Copy link
Contributor

Hi team,

This issue is to add the option to remove a certain standard in the rules, this functionality will be added to the script introduced in #392 map_standard.py

A new parameter (-d/--delete) will be added and the standard to be deleted will be specified.

Best regards,
Adri

@AdriiiPRodri AdriiiPRodri added enhancement rules Rules related issues labels Jun 3, 2019
@AdriiiPRodri AdriiiPRodri self-assigned this Jun 3, 2019
@AdriiiPRodri
Copy link
Contributor Author

AdriiiPRodri commented Jun 3, 2019

Status update

We have implemented the new functionality of eliminating standards in the rule files, this will be done with the new parameter (-d/--delete):

adriiiprodri@Wazuh:~/Desktop/git/wazuh-ruleset/tools/map-security-standard$ python map_standard.py -h
usage: map_standard.py [-h] [-p PATH] [-m MAPPING] [-d DELETE]

optional arguments:
  -h, --help            show this help message and exit
  -p PATH, --path PATH  Rules path
  -m MAPPING, --mapping MAPPING
                        Mapping path
  -d DELETE, --delete DELETE
                        Standard to be delete

This is the example output, in this case the standard gdpr has been removed:

adriiiprodri@Wazuh:~/Desktop/git/wazuh-ruleset/tools/map-security-standard$ python map_standard.py -d gdpr
[DELETE] Deleted gdpr in file 0500-owncloud_rules.xml
[DELETE] Deleted gdpr in file 0350-amazon_rules.xml
[DELETE] Deleted gdpr in file 0230-ms-se_rules.xml
[DELETE] Deleted gdpr in file 0025-sendmail_rules.xml
[DELETE] Deleted gdpr in file 0245-web_rules.xml
[DELETE] Deleted gdpr in file 0310-openbsd_rules.xml
[DELETE] Deleted gdpr in file 0016-wazuh_rules.xml
[DELETE] Deleted gdpr in file 0480-qualysguard_rules.xml
[DELETE] Deleted gdpr in file 0055-courier_rules.xml
[DELETE] Deleted gdpr in file 0430-ms_wdefender_rules.xml
[DELETE] Deleted gdpr in file 0585-win-application_rules.xml
[DELETE] Deleted gdpr in file 0510-ciscat_rules.xml
[DELETE] Deleted gdpr in file 0140-roundcube_rules.xml
[DELETE] Deleted gdpr in file 0525-openvas_rules.xml
[DELETE] Deleted gdpr in file 0085-pam_rules.xml
[DELETE] Deleted gdpr in file 0605-win-mcafee_rules.xml
[DELETE] Deleted gdpr in file 0530-mysql_audit_rules.xml
[DELETE] Deleted gdpr in file 0365-auditd_rules.xml
[DELETE] Deleted gdpr in file 0175-proftpd_rules.xml
[DELETE] Deleted gdpr in file 0095-sshd_rules.xml
[DELETE] Deleted gdpr in file 0345-netscaler_rules.xml
[DELETE] Deleted gdpr in file 0470-vshell_rules.xml
[DELETE] Deleted gdpr in file 0075-cisco-ios_rules.xml
[DELETE] Deleted gdpr in file 0385-oscap_rules.xml
[DELETE] Deleted gdpr in file 0040-imapd_rules.xml
[DELETE] Deleted gdpr in file 0325-opensmtpd_rules.xml
[DELETE] Deleted gdpr in file 0360-serv-u_rules.xml
[DELETE] Deleted gdpr in file 0315-apparmor_rules.xml
[DELETE] Deleted gdpr in file 0320-clam_av_rules.xml
[DELETE] Deleted gdpr in file 0300-postgresql_rules.xml
[DELETE] Deleted gdpr in file 0450-mongodb_rules.xml
[DELETE] Deleted gdpr in file 0340-puppet_rules.xml
[DELETE] Deleted gdpr in file 0020-syslog_rules.xml
[DELETE] Deleted gdpr in file 0210-vpn_concentrator_rules.xml
[DELETE] Deleted gdpr in file 0120-symantec-av_rules.xml
[DELETE] Deleted gdpr in file 0435-ms_logs_rules.xml
[DELETE] Deleted gdpr in file 0080-sonicwall_rules.xml
[DELETE] Deleted gdpr in file 0110-ms_dhcp_rules.xml
[DELETE] Deleted gdpr in file 0580-win-security_rules.xml
[DELETE] Deleted gdpr in file 0295-mysql_rules.xml
[DELETE] Deleted gdpr in file 0185-vsftpd_rules.xml
[DELETE] Deleted gdpr in file 0155-dovecot_rules.xml
[DELETE] Deleted gdpr in file 0425-cisco-estreamer_rules.xml
[DELETE] Deleted gdpr in file 0220-msauth_rules.xml
[DELETE] Deleted gdpr in file 0560-docker_integration_rules.xml
[DELETE] Deleted gdpr in file 0485-cylance_rules.xml
[DELETE] Deleted gdpr in file 0030-postfix_rules.xml
[DELETE] Deleted gdpr in file 0600-win-wdefender_rules.xml
[DELETE] Deleted gdpr in file 0135-hordeimp_rules.xml
[DELETE] Deleted gdpr in file 0160-vmpop3d_rules.xml
[DELETE] Deleted gdpr in file 0195-named_rules.xml
[DELETE] Deleted gdpr in file 0065-pix_rules.xml
[DELETE] Deleted gdpr in file 0620-win-generic_rules.xml
[DELETE] Deleted gdpr in file 0105-asterisk_rules.xml
[DELETE] Deleted gdpr in file 0305-dropbear_rules.xml
[DELETE] Deleted gdpr in file 0115-arpwatch_rules.xml
[DELETE] Deleted gdpr in file 0165-vpopmail_rules.xml
[DELETE] Deleted gdpr in file 0235-vmware_rules.xml
[DELETE] Deleted gdpr in file 0270-web_appsec_rules.xml
[DELETE] Deleted gdpr in file 0045-mailscanner_rules.xml
[DELETE] Deleted gdpr in file 0455-docker_rules.xml
[DELETE] Deleted gdpr in file 0255-zeus_rules.xml
[DELETE] Deleted gdpr in file 0515-exim_rules.xml
[DELETE] Deleted gdpr in file 0285-systemd_rules.xml
[DELETE] Deleted gdpr in file 0125-symantec-ws_rules.xml
[DELETE] Deleted gdpr in file 0390-fortigate_rules.xml
[DELETE] Deleted gdpr in file 0420-freeipa_rules.xml
[DELETE] Deleted gdpr in file 0215-policy_rules.xml
[DELETE] Deleted gdpr in file 0170-ftpd_rules.xml
[DELETE] Deleted gdpr in file 0490-virustotal_rules.xml
[DELETE] Deleted gdpr in file 0405-rsa-auth-manager_rules.xml
[DELETE] Deleted gdpr in file 0200-smbd_rules.xml
[DELETE] Deleted gdpr in file 0615-win-ms-se_rules.xml
[DELETE] Deleted gdpr in file 0050-ms-exchange_rules.xml
[DELETE] Deleted gdpr in file 0575-win-base_rules.xml
[DELETE] Deleted gdpr in file 0610-win-ms_logs_rules.xml
[DELETE] Deleted gdpr in file 0130-trend-osce_rules.xml
[DELETE] Deleted gdpr in file 0535-mariadb_rules.xml
[DELETE] Deleted gdpr in file 0505-vuls_rules.xml
[DELETE] Deleted gdpr in file 0260-nginx_rules.xml
[DELETE] Deleted gdpr in file 0240-ids_rules.xml
[DELETE] Deleted gdpr in file 0440-ms_sqlserver_rules.xml
[DELETE] Deleted gdpr in file 0590-win-system_rules.xml
[DELETE] Deleted gdpr in file 0395-hp_rules.xml
[DELETE] Deleted gdpr in file 0190-ms_ftpd_rules.xml
[DELETE] Deleted gdpr in file 0445-identity_guard_rules.xml
[DELETE] Deleted gdpr in file 0520-vulnerability-detector_rules.xml
[DELETE] Deleted gdpr in file 0330-sysmon_rules.xml
[DELETE] Deleted gdpr in file 0090-telnetd_rules.xml
[DELETE] Deleted gdpr in file 0100-solaris_bsm_rules.xml
[DELETE] Deleted gdpr in file 0015-ossec_rules.xml
[DELETE] Deleted gdpr in file 0225-mcafee_av_rules.xml
[DELETE] Deleted gdpr in file 0400-openvpn_rules.xml
[DELETE] Deleted gdpr in file 0265-php_rules.xml
[DELETE] Deleted gdpr in file 0250-apache_rules.xml
[DELETE] Deleted gdpr in file 0495-proxmox-ve_rules.xml
[DELETE] Deleted gdpr in file 0070-netscreenfw_rules.xml
[DELETE] Deleted gdpr in file 0275-squid_rules.xml
[DELETE] Deleted gdpr in file 0180-pure-ftpd_rules.xml
[DELETE] Deleted gdpr in file 0205-racoon_rules.xml
[DELETE] Deleted gdpr in file 0145-wordpress_rules.xml
[DELETE] Deleted gdpr in file 0060-firewall_rules.xml
[DELETE] Deleted gdpr in file 0595-win-sysmon_rules.xml
[DELETE] Deleted gdpr in file 0150-cimserver_rules.xml
[DELETE] Deleted gdpr in file 0280-attack_rules.xml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement rules Rules related issues
Projects
None yet
Development

No branches or pull requests

2 participants