fix(rules): match web-attack rules on the CRS attack_type the daemon emits - #230
Merged
Merged
Conversation
ralyodio
force-pushed
the
fix/rules-match-daemon-events
branch
from
September 25, 2026 16:36
2e64bd2 to
8990f6e
Compare
ThreatCrush Security Scan12 finding(s) HIGH/CRITICAL: 1 | MEDIUM: 6 | LOW: 5
Snippets are redacted; ThreatCrush never prints matched credential material. |
…emits The web-sqli-attack, web-path-traversal, web-xss-attack and exploit-probe-pattern rules matched the message text 'Attack detected [X]', which only 'threatcrush monitor' prints; the daemon's log-watcher writes 'Attack [X]', so none of them ever fired on a daemon event. Match the structured details.attack_type instead, gated on high/critical severity so a sub-threshold request (which also carries attack_type) never trips them. exploit-probe-pattern listed CMD_INJECTION and XXE, which CRS never reports; it now covers rce, ssrf, rfi, php_injection and ssti. web-sqli-attack and web-path-traversal drop from critical to high so a rule never lifts a one-CRS-rule hit past min_severity = critical. 'threatcrush rules show' now prints and/or sub-conditions.
ralyodio
force-pushed
the
fix/rules-match-daemon-events
branch
from
September 25, 2026 16:39
8990f6e to
d091495
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The shipped web-attack rules (
web-sqli-attack,web-path-traversal,web-xss-attack,exploit-probe-pattern) matched the message textAttack detected [X]. Onlythreatcrush monitorprints that; the daemon's log-watcher writesAttack [X]. None of these rules has ever fired on a daemon event.Change
details.attack_typefrom the CRS verdict (feat(cli): score web requests with the OWASP Core Rule Set (PL1) #222), which the engine already resolves as a bare field name, so the engine needed no change. Message wording no longer matters to any web rule, so monitor and log-watcher keep their current text.attack_type(as alowSuspicious …orClient error …event). Each rule therefore also needsseverityto behighorcritical, which log-watcher assigns only at or above the anomaly threshold.exploit-probe-patternlistedCMD_INJECTIONandXXE, which CRS never reports (it files command injection underrce, and an access log has no request body for XXE). It now matchesrce|ssrf|rfi|php_injection|ssti.web-sqli-attackandweb-path-traversalgo fromcriticaltohigh. Acriticalrule would take a single-CRS-rulehighevent pastmin_severity = "critical", which the docs say requires two matching rules.threatcrush rules show <id>now printsand/orsub-conditions. Without that it would showattack_type equals "sqli"and leave out the severity gate.I checked every other default rule for the same bug
[ident] messageand severity. OK.Port scan detected: …(case-insensitivecontains). OK.Client error NNN:. OK.scannerandinjection, or a null type. Module severity still bans them.remediation.ttl_secondson rules is shown byrules showbut ignored byRemediationManager, which always uses the Fibonacci ladder.user-journal/system, and the ssh rules neither select nor match them.Measurement (on top of #228, real traffic, 15 rotated nginx access logs, ~238k lines → ~89k events)
A throwaway script replayed each line through
LogWatcher.processand thenRuleEngine, with the clock set to each line's timestamp. It is not committed.blockrule bans (min_severity=high)high)Event mix is the same on both sides: 49,271 high, 964 critical, 38,719 low. None of the low events carried an
attack_typeat the default threshold. For the sub-threshold case, see the test below.The set of banned IPs does not change. Rules now fire and are recorded as detections. Because the rule engine runs before remediation on the bus, a ban is now attributed to the rule (
rule_id,[DETECTION] …reason) rather than the raw event.Hand-check of newly firing request shapes, grouped with digits normalised. Every group is an attack probe:
.gitprobes,cgi-bin/.%2e/…/bin/sh, literal../allow_url_include/auto_prepend_file, Mozi/routerwget …;shRCE, cloud-metadata SSRF/RFI, vault.yml fetches.xhtmlpage flagged by 941130. With 941130 off by default there are none.Tests
apps/cli/src/daemon/__tests__/web-attack-rules.test.tssends real access-log lines through the daemon'sLogWatcherand then the default rules:default-rules.ts).anomaly_threshold = 10, a 5-point/.envrequest becomes alowevent withattack_type = path_traversal, at status 200 and at 404. The test asserts that no web-attack rule fires. These two fail if the severity gate is removed (checked).vitest run src/daemon src/core src/__tests__/doc-claims.test.ts: 150 passed.