Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 34 additions & 6 deletions .github/release-notes/1.9.0.md
Original file line number Diff line number Diff line change
@@ -1,16 +1,44 @@
## Highlights

- **More room for written-file bursts.**
Written-file YARA and hash IOC inspection use an 8,192-job queue and an 8,192-target settling table, replacing the 256-entry limits in the release candidates.
- **Vanished files free pending scan slots.**
When the settling table is full, bounded checks reclaim deleted or renamed-away paths so persistent files written after temporary-file churn can be scanned.
Process and loaded-image resolution keep their separate queue and I/O capacity.
- **Clearer detection-gap diagnostics.**
- **Broader file and memory detection.**
YARA scans qualifying written files on Linux, macOS, and Windows, plus Linux heap and stack mappings and memfd executables.
macOS memory scans classify each VM region by its own mapping and exclude the dyld shared cache from private-memory scan budgets.
Written-file inspection uses an 8,192-job queue and an 8,192-target settling table, with bounded reclamation of vanished paths and separate capacity for process and loaded-image resolution.
Linux resolves process artifacts within their mount namespace, including container paths.
- **More Windows telemetry.**
Classic PowerShell starts, Application and Defender Operational channels, and WMI permanent subscription events expand Sigma coverage.
- **More control over Sigma detection.**
Set `scanner.sigma_match_mode = "all"` to emit every matching detection rule, and use per-rule compatibility diagnostics to identify unsupported fields.
Correlation buffers flush on timers and shutdown, while field lookup and CIDR IOC matching use faster indexed paths.
- **Safer updates and privileged inputs.**
Binary updates verify signed release checksums, rule-pack installs verify signed catalogs, and configuration and rule inputs are checked for unsafe write permissions.
Managed installation and logging paths receive tighter permissions, and active response validates and terminates through one process handle.
- **More reliable service operation.**
Critical worker failures terminate the agent for service-manager recovery, Windows service recovery can be configured during installation, and Unix stop signals drain pending work.
Superseded process identities are retired on exec, startup diagnostics distinguish detector readiness, and alert writer drops are counted and reported.
`rustinel doctor` warns explicitly when dropped written-file jobs leave a YARA and hash IOC detection gap.

## Upgrade notes

- **Updating:** run `rustinel update` or install `1.9.0` explicitly with the installer version option.
Restart the service after replacing the binary, then run `rustinel doctor` and verify a known detection before broad deployment.
- **Configuration validation:** unknown sections or options, including `EDR__` environment variables, and invalid active-response settings stop startup.
Remove obsolete keys and correct reported configuration errors before upgrading managed hosts.
- **Input and output permissions:** configuration and rule inputs must not be writable by untrusted accounts.
Check custom deployment paths with `rustinel doctor`; unsafe configuration stops startup, and unsafe rule inputs leave the affected detector unloaded at startup or preserve its previous rules during reload.
Log and capture output permissions are restricted to their owner.
- **YARA severity and active response:** file and process-memory alerts use the first valid rule metadata value from `severity`, `level`, then `score`.
Rules without recognized metadata default to `high` instead of `critical`, and active response uses the resulting alert severity.
Deployments with `response.min_severity = "critical"` must add `severity = "critical"` to rules intended to trigger response, or lower the response threshold after reviewing their rules.
- **Signed downloads:** custom rule catalogs must include a valid signature from the trusted release key.
Binary updates also require signed checksum assets; missing or invalid signatures stop replacement.
- **Windows written-file scanning:** the file ID is read from the path when the scan is queued, because Kernel-File ETW events carry none.
Files on network volumes are not scanned and are counted under `artifact_resolver.identity_unavailable`.
- **Written-file scanning remains bounded.**
Files settle for 250 ms, with at most 8,192 pending targets and 8,192 queued jobs.
Each new target arriving at table capacity checks up to 64 pending paths for disappearance, continuing from the previous check.
If the queue is full or no slot is reclaimed, its scan is shed and counted under `artifact_resolver.written_file_dropped`; base file telemetry and Sigma evaluation still run.
- **Linux process artifacts:** container artifacts require a confirmed mount namespace and matching process lifetime.
Script content is a worker-time snapshot, and files replaced before inspection are rejected.
- **Compatibility tooling:** the field-availability contract uses schema version 3 with an explicit field view.
Update consumers that validate this schema, and review alert volume before enabling all-matches Sigma mode or additional Windows event sources.
2 changes: 1 addition & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ env:
CARGO_TERM_COLOR: always
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
# Update this commit deliberately when the rules repository's atomic suite changes.
RUSTINEL_RULES_REF: 7f768c0ef6ef5e2b411399be38c972f7e1791cbe
RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f

permissions:
contents: read
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ env:
CARGO_TERM_COLOR: always
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
# Update this commit deliberately when the rules repository's atomic suite changes.
RUSTINEL_RULES_REF: 8732a0f02e88a1a67d011543cd25ed8c464d7d33
RUSTINEL_RULES_REF: fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f

permissions:
contents: read
Expand Down
2 changes: 1 addition & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "rustinel"
version = "1.9.0-rc.2"
version = "1.9.0"
edition = "2021"
authors = []
description = "Open-source EDR for Windows, Linux, and macOS with Sigma, YARA, and IOC detection"
Expand Down
1 change: 1 addition & 0 deletions deny.toml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
[advisories]
ignore = [
{ id = "RUSTSEC-2026-0327", reason = "This advisory requires Wasmtime component-model async callbacks. yara-x 1.21 uses core WebAssembly modules with Wasmtime default features disabled; component-model and component-model-async are absent from the dependency feature tree on all targets. Disabling component-model-async is the upstream workaround. No patched 45.x release is available. See https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-32h6-97mm-8q3c." },
{ id = "RUSTSEC-2026-0316", reason = "This advisory affects wasmtime::component::Val record lifting. yara-x 1.21 uses core WebAssembly modules with Wasmtime default features disabled; component-model is absent from the dependency tree. No patched 45.x release is available. See https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-jqpg-j7w6-42pr." },
{ id = "RUSTSEC-2023-0071", reason = "rsa is pulled transitively by yara-x. No fixed rsa release is available, and rustinel does not use yara-x for attacker observable private key RSA operations." },
{ id = "RUSTSEC-2025-0141", reason = "bincode is pulled transitively by yara-x. This is tracked as an upstream maintenance advisory until yara-x removes or replaces it." },
Expand Down
Loading