From 1fba3a3958a154ab11666c32de267b74b9211815 Mon Sep 17 00:00:00 2001 From: Karib0u Date: Sat, 3 Oct 2026 10:07:45 +0200 Subject: [PATCH 1/3] chore(release): prepare 1.9.0 --- .github/release-notes/1.9.0.md | 40 +++++++++++++++++++++++++++++----- .github/workflows/release.yml | 2 +- Cargo.lock | 2 +- Cargo.toml | 2 +- 4 files changed, 37 insertions(+), 9 deletions(-) diff --git a/.github/release-notes/1.9.0.md b/.github/release-notes/1.9.0.md index faeee4e..3d1778b 100644 --- a/.github/release-notes/1.9.0.md +++ b/.github/release-notes/1.9.0.md @@ -1,16 +1,44 @@ ## Highlights -- **More room for written-file bursts.** - Written-file YARA and hash IOC inspection use an 8,192-job queue and an 8,192-target settling table, replacing the 256-entry limits in the release candidates. -- **Vanished files free pending scan slots.** - When the settling table is full, bounded checks reclaim deleted or renamed-away paths so persistent files written after temporary-file churn can be scanned. - Process and loaded-image resolution keep their separate queue and I/O capacity. -- **Clearer detection-gap diagnostics.** +- **Broader file and memory detection.** + YARA scans qualifying written files on Linux, macOS, and Windows, plus Linux heap and stack mappings and memfd executables. + macOS memory scans classify each VM region by its own mapping and exclude the dyld shared cache from private-memory scan budgets. + Written-file inspection uses an 8,192-job queue and an 8,192-target settling table, with bounded reclamation of vanished paths and separate capacity for process and loaded-image resolution. + Linux resolves process artifacts within their mount namespace, including container paths. +- **More Windows telemetry.** + Classic PowerShell starts, Application and Defender Operational channels, and WMI permanent subscription events expand Sigma coverage. +- **More control over Sigma detection.** + Set `scanner.sigma_match_mode = "all"` to emit every matching detection rule, and use per-rule compatibility diagnostics to identify unsupported fields. + Correlation buffers flush on timers and shutdown, while field lookup and CIDR IOC matching use faster indexed paths. +- **Safer updates and privileged inputs.** + Binary updates verify signed release checksums, rule-pack installs verify signed catalogs, and configuration and rule inputs are checked for unsafe write permissions. + Managed installation and logging paths receive tighter permissions, and active response validates and terminates through one process handle. +- **More reliable service operation.** + Critical worker failures terminate the agent for service-manager recovery, Windows service recovery can be configured during installation, and Unix stop signals drain pending work. + Superseded process identities are retired on exec, startup diagnostics distinguish detector readiness, and alert writer drops are counted and reported. `rustinel doctor` warns explicitly when dropped written-file jobs leave a YARA and hash IOC detection gap. ## Upgrade notes +- **Updating:** run `rustinel update` or install `1.9.0` explicitly with the installer version option. + Restart the service after replacing the binary, then run `rustinel doctor` and verify a known detection before broad deployment. +- **Configuration validation:** unknown sections or options, including `EDR__` environment variables, and invalid active-response settings stop startup. + Remove obsolete keys and correct reported configuration errors before upgrading managed hosts. +- **Input and output permissions:** configuration and rule inputs must not be writable by untrusted accounts. + Check custom deployment paths with `rustinel doctor`; unsafe configuration stops startup, and unsafe rule inputs leave the affected detector unloaded at startup or preserve its previous rules during reload. + Log and capture output permissions are restricted to their owner. +- **YARA severity and active response:** file and process-memory alerts use the first valid rule metadata value from `severity`, `level`, then `score`. + Rules without recognized metadata default to `high` instead of `critical`, and active response uses the resulting alert severity. + Deployments with `response.min_severity = "critical"` must add `severity = "critical"` to rules intended to trigger response, or lower the response threshold after reviewing their rules. +- **Signed downloads:** custom rule catalogs must include a valid signature from the trusted release key. + Binary updates also require signed checksum assets; missing or invalid signatures stop replacement. +- **Windows written-file scanning:** the file ID is read from the path when the scan is queued, because Kernel-File ETW events carry none. + Files on network volumes are not scanned and are counted under `artifact_resolver.identity_unavailable`. - **Written-file scanning remains bounded.** Files settle for 250 ms, with at most 8,192 pending targets and 8,192 queued jobs. Each new target arriving at table capacity checks up to 64 pending paths for disappearance, continuing from the previous check. If the queue is full or no slot is reclaimed, its scan is shed and counted under `artifact_resolver.written_file_dropped`; base file telemetry and Sigma evaluation still run. +- **Linux process artifacts:** container artifacts require a confirmed mount namespace and matching process lifetime. + Script content is a worker-time snapshot, and files replaced before inspection are rejected. +- **Compatibility tooling:** the field-availability contract uses schema version 3 with an explicit field view. + Update consumers that validate this schema, and review alert volume before enabling all-matches Sigma mode or additional Windows event sources. diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 533eaca..3834e86 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -8,7 +8,7 @@ env: CARGO_TERM_COLOR: always FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true # Update this commit deliberately when the rules repository's atomic suite changes. - RUSTINEL_RULES_REF: 8732a0f02e88a1a67d011543cd25ed8c464d7d33 + RUSTINEL_RULES_REF: 7f768c0ef6ef5e2b411399be38c972f7e1791cbe permissions: contents: read diff --git a/Cargo.lock b/Cargo.lock index c8c191f..d384d9a 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -3201,7 +3201,7 @@ dependencies = [ [[package]] name = "rustinel" -version = "1.9.0-rc.2" +version = "1.9.0" dependencies = [ "anyhow", "arc-swap", diff --git a/Cargo.toml b/Cargo.toml index e04d297..c397f1e 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "rustinel" -version = "1.9.0-rc.2" +version = "1.9.0" edition = "2021" authors = [] description = "Open-source EDR for Windows, Linux, and macOS with Sigma, YARA, and IOC detection" From b6b0623d59a5910314fe37baf421c54d44f25c61 Mon Sep 17 00:00:00 2001 From: Karib0u Date: Sat, 3 Oct 2026 10:08:51 +0200 Subject: [PATCH 2/3] chore(release): pin reviewed atomic rules revision --- .github/workflows/ci.yml | 2 +- .github/workflows/release.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c9e05db..0278dc1 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -17,7 +17,7 @@ env: CARGO_TERM_COLOR: always FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true # Update this commit deliberately when the rules repository's atomic suite changes. - RUSTINEL_RULES_REF: 7f768c0ef6ef5e2b411399be38c972f7e1791cbe + RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f permissions: contents: read diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 3834e86..2117a26 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -8,7 +8,7 @@ env: CARGO_TERM_COLOR: always FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true # Update this commit deliberately when the rules repository's atomic suite changes. - RUSTINEL_RULES_REF: 7f768c0ef6ef5e2b411399be38c972f7e1791cbe + RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f permissions: contents: read From c6e9dd8b018e770f150ca40a4ccd37e0d2fc8682 Mon Sep 17 00:00:00 2001 From: Karib0u Date: Sat, 3 Oct 2026 10:12:03 +0200 Subject: [PATCH 3/3] fix(deps): document unreachable Wasmtime async advisory --- deny.toml | 1 + 1 file changed, 1 insertion(+) diff --git a/deny.toml b/deny.toml index 577d871..1a291c1 100644 --- a/deny.toml +++ b/deny.toml @@ -1,5 +1,6 @@ [advisories] ignore = [ + { id = "RUSTSEC-2026-0327", reason = "This advisory requires Wasmtime component-model async callbacks. yara-x 1.21 uses core WebAssembly modules with Wasmtime default features disabled; component-model and component-model-async are absent from the dependency feature tree on all targets. Disabling component-model-async is the upstream workaround. No patched 45.x release is available. See https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-32h6-97mm-8q3c." }, { id = "RUSTSEC-2026-0316", reason = "This advisory affects wasmtime::component::Val record lifting. yara-x 1.21 uses core WebAssembly modules with Wasmtime default features disabled; component-model is absent from the dependency tree. No patched 45.x release is available. See https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-jqpg-j7w6-42pr." }, { id = "RUSTSEC-2023-0071", reason = "rsa is pulled transitively by yara-x. No fixed rsa release is available, and rustinel does not use yara-x for attacker observable private key RSA operations." }, { id = "RUSTSEC-2025-0141", reason = "bincode is pulled transitively by yara-x. This is tracked as an upstream maintenance advisory until yara-x removes or replaces it." },