Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
pySigma-backend-opensearch — الخلفية الخلفية لـ pySigma OpenSearch | Kitploit
أدوات/GitHubGitHub/sigmahq/pysigma-backend-opensearch
أدوات دفاعيةالأدوات والمكوناتكشف التسللتحليل السجلات
GitHubsigmahq/pysigma-backend-opensearch

pySigma-backend-opensearch

الخلفية الخلفية لـ pySigma OpenSearch

عرض المستودع
1466منذ 23 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

Tests Coverage
Badge Status

محرك OpenSearch الخلفي لـ pySigma

هذا هو المحرك الخلفي لـ OpenSearch الخاص بـ pySigma. يوفر الحزمة sigma.backends.opensearch مع فئتَي محرك خلفي:

  • OpensearchLuceneBackend - يحوّل قواعد Sigma إلى صيغة استعلام Lucene
  • OpenSearchPPLBackend - يحوّل قواعد Sigma إلى استعلامات PPL (لغة المعالجة الأنبوبية)

محرك Lucene الخلفي

يدعم محرك Lucene الخلفي تنسيقات الإخراج التالية:

  • default: استعلامات OpenSearch عادية بصيغة Lucene
    • تلميح: في لوحة المعلومات يجب التبديل من DQL إلى Lucene
  • monitor_rule: بنية JSON لاستيراد قواعد تنبيه OpenSearch

تتم صيانة هذا المحرك الخلفي حاليًا بواسطة:

  • Hendrik Bäcker

خلفية

محرك Lucene الخلفي

بما أن الاستعلامات المعتمدة على Lucene مطابقة إلى حد كبير لاستعلامات Elasticsearch من نوع Lucene، فإن معظم كود هذا المحرك الخلفي مأخوذ من pySigma-backend-elasticsearch.

التغييرات الخاصة بـ OpenSearch وتنسيقات الإخراج تتم في هذا المحرك الخلفي (مثل قواعد المراقبة).

محرك PPL الخلفي

محرك PPL (لغة المعالجة الأنبوبية) الخلفي مُنفَّذ من الصفر لدعم لغة الاستعلام الأصلية في OpenSearch. يوفر PPL:

  • دعم الارتباطات - دعم مدمج لقواعد ارتباط Sigma

دعم قواعد الارتباط

يدعم محرك PPL الخلفي بالكامل قواعد ارتباط Sigma، مما يتيح اكتشاف السيناريوهات المعقدة متعددة الأحداث:

  • event_count - عدّ مرات حدوث الأحداث (مثل اكتشاف هجمات القوة الغاشمة)
  • value_count - عدّ القيم المميزة لحقل (مثل رش كلمات المرور)
  • temporal - أحداث متعددة مختلفة خلال نافذة زمنية (مثل هجمات متعددة المراحل)

كيفية الاستخدام

إنشاء المخرجات - sigma-cli

محرك Lucene الخلفي

root@kitploit:~
sigma convert \
  -t opensearch \
  -p ecs_windows \
  -f monitor_rule \
  /data/sigma/rules/windows/process_creation/proc_creation_win_whoami_priv.yml

محرك PPL الخلفي

root@kitploit:~
sigma convert \
  -t opensearch-ppl \
  -p ecs_windows \
  /data/sigma/rules/windows/process_creation/proc_creation_win_whoami_priv.yml

إنشاء قواعد تنبيه - Python

محرك Lucene الخلفي

root@kitploit:~
from sigma.backends.opensearch import OpensearchLuceneBackend

from sigma.pipelines.sysmon import sysmon_pipeline
from sigma.pipelines.elasticsearch.windows import ecs_windows

from sigma.collection import SigmaCollection
from sigma.processing.resolver import ProcessingPipelineResolver

# Create our pipeline resolver
piperesolver = ProcessingPipelineResolver()

# Add wanted pipelines
piperesolver.add_pipeline_class(ecs_windows())
piperesolver.add_pipeline_class(sysmon_pipeline())

# Create a single sorted and prioritzed pipeline
resolved_pipeline = piperesolver.resolve(piperesolver.pipelines)

# Instantiate backend, using our resolved pipeline
# and some backend parameter
backend = OpensearchLuceneBackend(resolved_pipeline, index_names=['logs-*-*', 'beats-*'], monitor_interval=10, monitor_interval_unit="MINUTES")

rules = SigmaCollection.from_yaml("""
title: Run Whoami Showing Privileges
id: 97a80ec7-0e2f-4d05-9ef4-65760e634f6b
status: experimental
description: Detects a whoami.exe executed with the /priv command line flag instructing the tool to show all current user privieleges. This is often used after a privilege escalation attempt. 
references:
    - https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/whoami
author: Florian Roth
date: 2021/05/05
modified: 2022/05/13
tags:
    - attack.privilege_escalation
    - attack.discovery
    - attack.t1033
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith: '\whoami.exe'
        - OriginalFileName: 'whoami.exe'
    selection_cli:
        CommandLine|contains: '/priv'
    condition: all of selection*
falsepositives:
    - Administrative activity (rare lookups on current privileges)
level: high
""")

# Print converted rule in Lucene syntax
print("Lucene Result: \n" + "\n".join(backend.convert(rules)))

# Print converted rule ready for dsl syntax
print("DSL Result: \n" + json.dumps(backend.convert(rules, output_format="dsl_lucene")[0], indent=2))

# Generate a JSON structure to be imported as monitor rule
print("Monitor Rule Result: \n" + backend.convert(rules, output_format="monitor_rule"))

نتيجة Lucene:

root@kitploit:~
winlog.channel:Microsoft\-Windows\-Sysmon\/Operational AND (event.code:1 AND ((process.executable:*\\whoami.exe OR process.pe.original_file_name:whoami.exe) AND process.command_line:*\/priv*))

نتيجة DSL:

root@kitploit:~
{
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "query": "winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND (winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND ((process.executable:*\\\\whoami.exe OR process.pe.original_file_name:whoami.exe) AND process.command_line:*\\/priv*))))",
            "analyze_wildcard": true
          }
        }
      ]
    }
  }
}

نتيجة قاعدة المراقبة:

root@kitploit:~
{
  "type": "monitor",
  "name": "SIGMA - Run Whoami Showing Privileges",
  "description": "Detects a whoami.exe executed with the /priv command line flag instructing the tool to show all current user privieleges. This is often used after a privilege escalation attempt.",
  "enabled": true,
  "schedule": {
    "period": {
      "interval": 10,
      "unit": "MINUTES"
    }
  },
  "inputs": [
    {
      "search": {
        "indices": [
          "logs-*-*",
          "beats-*"
        ],
        "query": {
          "size": 1,
          "query": {
            "bool": {
              "must": [
                {
                  "query_string": {
                    "query": "winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND (winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND (winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND ((process.executable:*\\\\whoami.exe OR process.pe.original_file_name:whoami.exe) AND process.command_line:*\\/priv*))))))",
                    "analyze_wildcard": true
                  }
                }
              ]
            }
          }
        }
      }
    }
  ],
  "tags": [
    "attack-privilege_escalation",
    "attack-discovery",
    "attack-t1033"
  ],
  "triggers": [
    {
      "name": "generated-trigger",
      "severity": 2,
      "condition": {
        "script": {
          "source": "ctx.results[0].hits.total.value > 0",
          "lang": "painless"
        }
      },
      "actions": []
    }
  ],
  "sigma_meta_data": {
    "rule_id": "97a80ec7-0e2f-4d05-9ef4-65760e634f6b",
    "threat": []
  },
  "references": [
    "https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/whoami"
  ]
}

محرك PPL الخلفي

root@kitploit:~
from sigma.backends.opensearch.opensearch_ppl import OpenSearchPPLBackend
from sigma.collection import SigmaCollection

# Instantiate PPL backend
backend = OpenSearchPPLBackend()

# Use the same rule as above
rules = SigmaCollection.from_yaml("""
title: Run Whoami Showing Privileges
id: 97a80ec7-0e2f-4d05-9ef4-65760e634f6b
status: experimental
description: Detects a whoami.exe executed with the /priv command line flag instructing the tool to show all current user privieleges. This is often used after a privilege escalation attempt. 
references:
    - https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/whoami
author: Florian Roth
date: 2021/05/05
modified: 2022/05/13
tags:
    - attack.privilege_escalation
    - attack.discovery
    - attack.t1033
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith: '\whoami.exe'
        - OriginalFileName: 'whoami.exe'
    selection_cli:
        CommandLine|contains: '/priv'
    condition: all of selection*
falsepositives:
    - Administrative activity (rare lookups on current privileges)
level: high
""")

# Print converted rule in PPL syntax
print("PPL Result: \n" + "\n".join(backend.convert(rules)))

نتيجة PPL:

root@kitploit:~
source=windows-process_creation-* | where (LIKE(Image, "%\whoami.exe") OR OriginalFileName="whoami.exe") AND LIKE(CommandLine, "%/priv%")

مثال على قواعد ارتباط PPL

root@kitploit:~
from sigma.backends.opensearch.opensearch_ppl import OpenSearchPPLBackend
from sigma.collection import SigmaCollection

backend = OpenSearchPPLBackend()

# Brute force detection using event_count correlation
rules = SigmaCollection.from_yaml("""
title: Windows Failed Logon Event
name: failed_logon
logsource:
  product: windows
  service: security
detection:
  selection:
    EventID: 4625
  filter:
    SubjectUserName|endswith: $
  condition: selection and not filter
---
title: Brute Force Attack Detection
correlation:
  type: event_count
  rules:
    - failed_logon
  group-by:
    - TargetUserName
    - TargetDomainName
  timespan: 5m
  condition:
    gte: 10
""")

print("Correlation PPL Result: \n" + "\n".join(backend.convert(rules)))

نتيجة PPL للارتباط:

root@kitploit:~
| search source=windows-security-* | where EventID=4625 AND NOT LIKE(SubjectUserName, "%$") | stats count() as event_count by TargetUserName, TargetDomainName | where event_count >= 10

الإعدادات

يمكنك ضبط سلوك محرك PPL الخلفي باستخدام سمات مخصصة في قواعد Sigma أو خيارات تهيئة المحرك الخلفي.

السمات المخصصة لمحرك PPL الخلفي

يدعم محرك PPL الخلفي السمات المخصصة التالية التي يمكن تحديدها في قسم custom لقاعدة Sigma:

root@kitploit:~
custom:
  opensearch_ppl_index: "custom-logs-*"        # Override default index pattern
  opensearch_ppl_min_time: "-30d"              # Set query time window start
  opensearch_ppl_max_time: "now"               # Set query time window end

مثال مع سمات مخصصة

يوضح هذا المثال كيفية عمل السمات المخصصة مع قواعد الارتباط، حيث يمكن لقواعد الاكتشاف الفردية أن يكون لها نوافذ زمنية خاصة بها أو ترث من قاعدة الارتباط:

root@kitploit:~
title: Detection Rule 1 - With Own Time Filter
id: 10000400-0000-0000-0000-000000000004
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    CommandLine|contains: 'malware'
  condition: selection
custom:
  opensearch_ppl_min_time: "-7d"    # This rule uses 7 days
  opensearch_ppl_max_time: "now"
---
title: Detection Rule 2 - No Time Filter
id: 10000401-0000-0000-0000-000000000004
logsource:
  product: windows
  category: network_connection
detection:
  selection:
    DestinationPort: 443
  condition: selection
# No custom attributes - will inherit from correlation
---
title: Correlation - Mixed Time Filters
id: 10000402-0000-0000-0000-000000000004
correlation:
  type: temporal
  rules:
    - 10000400-0000-0000-0000-000000000004
    - 10000401-0000-0000-0000-000000000004
  group-by:
    - Computer
  timespan: 5m
custom:
  opensearch_ppl_min_time: "-30d"   # Rule 2 inherits this (30 days)
  opensearch_ppl_max_time: "now"

النتيجة:

  • ستبحث قاعدة الاكتشاف 1 في آخر 7 أيام (سمتها المخصصة الخاصة)
  • ستبحث قاعدة الاكتشاف 2 في آخر 30 يومًا (موروثة من قاعدة الارتباط)

خيارات المحرك الخلفي

يمكنك أيضًا تعيين قيم افتراضية عند إنشاء المحرك الخلفي:

root@kitploit:~
backend = OpenSearchPPLBackend(
    custom_logsource="default-logs-*",  # Default index pattern for all rules
    min_time="-24h",                    # Default time window start
    max_time="now"                      # Default time window end
)

السمات المخصصة في القواعد الفردية ستتجاوز هذه القيم الافتراضية على مستوى المحرك الخلفي.

تنزيل الأداة