Skip to content

Rule loader warnings #2606

Open
Open
@brokensound77

Description

@brokensound77

Rather than printing them from the rule loaded within unit tests (since the global constant is set), all output should be aggregated and raised as an actual warning to control the output.

example:

Unusual Print Spooler Child Process
There is a new integration endpoint version 8.6.1 available! Update the rule min_stack version from 8.3.0 to 8.6.0 if using new features in this latest version.
Unusual Service Host Child Process - Childless Service
There is a new integration endpoint version 8.6.1 available! Update the rule min_stack version from 8.3.0 to 8.6.0 if using new features in this latest version.
Privileges Elevation via Parent Process PID Spoofing
There is a new integration endpoint version 8.6.1 available! Update the rule min_stack version from 8.3.0 to 8.6.0 if using new features in this latest version.
Process Created with an Elevated Token
There is a new integration endpoint version 8.6.1 available! Update the rule min_stack version from 8.4.0 to 8.6.0 if using new features in this latest version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions