Skip to content

Fix crash of 'analyze attack' with rulesets without ATT&CK tags - #96

Open
SkxOverKill wants to merge 1 commit into
SigmaHQ:mainfrom
SkxOverKill:main
Open

Fix crash of 'analyze attack' with rulesets without ATT&CK tags#96
SkxOverKill wants to merge 1 commit into
SigmaHQ:mainfrom
SkxOverKill:main

Conversation

@SkxOverKill

Copy link
Copy Markdown

If no rule carries an attack tag, calculate_attack_scores() returns an empty dict. The ATT&CK Navigator layer generation then evaluated max(scores.values()) on the empty dict, which raised 'ValueError: max() iterable argument is empty' and aborted the command with a raw traceback and exit code 1, without writing the output file.

Additionally, an explicitly set --max-score 0 was ignored because the previous expression checked truthiness ('max_score or ...') instead of None.

Resolve the maximum to the explicit --max-score if given, otherwise to the highest score present, falling back to 0 for empty rulesets.

If no rule carries an attack tag, calculate_attack_scores() returns an
empty dict. The ATT&CK Navigator layer generation then evaluated
max(scores.values()) on the empty dict, which raised
'ValueError: max() iterable argument is empty' and aborted the command
with a raw traceback and exit code 1, without writing the output file.

Additionally, an explicitly set --max-score 0 was ignored because the
previous expression checked truthiness ('max_score or ...') instead of
None.

Resolve the maximum to the explicit --max-score if given, otherwise to
the highest score present, falling back to 0 for empty rulesets.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant