Repository navigation
Conversation
A Sigma value with an escaped asterisk, e.g. '/tn \*' or '\\*\IPC$', was emitted as `\*` in the search string. The Splunk search command treats every asterisk as a wildcard and documents that a backslash cannot escape it, so `f="lit\*star"` also matches `litstar` and `litXYZstar`. Rules that look for a literal asterisk turned into much broader searches, e.g. `schtasks /delete /tn *` (delete all tasks) matched the deletion of any task and `\\*\IPC$` matched every host's IPC$ share. Convert such values to an anchored, case-insensitive regular expression and pass them through the existing regex handling (`regex` command, or `rex`/`eval` inside OR). Keywords are matched against _raw. Values without a literal asterisk are converted as before, and IN lists are only skipped when one of their values has a literal asterisk. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
BLUF
'/tn \*'or'\\\\\*\\IPC$', is emitted as\*in the search string. Splunk'ssearchcommand treats every*as a wildcard, and the Splunk docs (Search Manual, "Backslashes") say a backslash cannot escape an asterisk. Sof="lit\*star"matcheslit*star,litstarandlitXYZstaralike.*, and they turn into much broader searches (false positives):proc_creation_win_schtasks_delete_all("delete all scheduled tasks",/tn *) matches the deletion of any task.ShareName: \\*\IPC$rules (win_security_susp_psexec,..._atsvc_task,..._lm_namedpipe, ...) match every\\HOST\IPC$.-Filter *in the Get-ADUser/Get-ADComputer discovery rules matches any filter.| regex, orrex/evalinside an OR, the same path as|re. Keywords are matched against_raw. IN lists are only skipped when one of their values has a literal asterisk. Values without a literal asterisk are converted exactly as before.Priority: medium
Details
Before and after for the real rule
proc_creation_win_schtasks_delete_all.yml, converted bymainand by this branch and run on Splunk 10.4.3 against 3 events:Splunk also warns about the current output: "The term 'f="lit*star"' contains a wildcard in the middle of a word or string." For keywords the current output is worse:
"lit\*star"did not match an event containinglit*starat all, but did matchlitXstarandlitstar.Notes on the change (
sigma/backends/splunk/splunk.py):_has_literal_asterisk()looks for a*inside the plain-string parts of aSigmaString. Wildcards areSpecialCharsand are not affected.convert_condition_field_eq_val_str()converts such a value withSigmaString.to_regex(), anchors it with^...$and adds theiflag, because Sigma string matching and Splunksearchare case-insensitive. It then hands the value toconvert_condition_field_eq_val_re(). That method already does theregex/regex !=(NOT) and therex+eval+fieldCondition="true"(OR) handling.convert_condition_val_str()does the same for keywords, unanchored, on_raw.decide_convert_condition_as_in_expression()returns False when one of the values has a literal asterisk. Otherwise the value would stay insideIN (...)as a wildcard.rex/evalpair per value, as|relists do today. For example,posh_ps_get_process_security_software_discoverygives 9 pairs.data_model(tstats) output uses the same deferred| regexpath as|re.Testing
New tests in
tests/test_backend_splunk.py:contains, and backslashes combined with a literal asterisk (\\*\IPC$)INdata_modeloutputLive validation on Splunk Enterprise 10.4.3 (container). The events were ingested with the field
fset tolit*star,litXstar,lit\star,litstar,lit\*star,lit\Xstar,litXYZstar,LIT*STAR,\\*\IPC$and\\HOST\IPC$, and the queries were converted by this branch:mainmatchesf: 'lit\*star'lit...star)lit*star,LIT*STARf: '\\\\\*\\IPC$'\\*\IPC$,\\HOST\IPC$\\*\IPC$f|contains: 'it\*st'lit*star,LIT*STARnot f: 'lit\*star'lit*star,LIT*STARf: ['lit\*star', 'litXYZstar'](OR)litXYZstar'lit\*star'litXstar,lit\star,litstar, ... but notlit*starlit*star['lit\*star', 'IPC$'](rex field=_raw)lit*starand IPC$ eventsrex/evalpairsAll 27 SigmaHQ rules with a literal asterisk convert without errors in the
default,savedsearchesanddata_modelformats. The SPL2 backend is a separate class and is not affected.The steps from
.github/workflows/test.ymlwere run locally withpoetry install(the locked pySigma 1.2.0):pytest --cov=sigma: 159 passed on Python 3.10, 3.11, 3.12 and 3.13.🤖 Generated with Claude Code