From afe64bdb3ef4d80d5f5afbc98c32485f8a90bd57 Mon Sep 17 00:00:00 2001 From: Ignacio Bermudez Corrales Date: Fri, 6 Nov 2020 10:37:11 -0800 Subject: [PATCH] detection/experimental folder for untested detections --- bin/testing_coverage.py | 31 ++++++++++--------- detections/experimental/application/.untested | 0 .../detect_phishing_content___ssa.yml | 0 detections/experimental/cloud/.untested | 0 detections/experimental/endpoint/.untested | 0 detections/experimental/network/.untested | 0 detections/experimental/web/.untested | 0 7 files changed, 16 insertions(+), 15 deletions(-) create mode 100644 detections/experimental/application/.untested rename detections/{ => experimental}/application/detect_phishing_content___ssa.yml (100%) create mode 100644 detections/experimental/cloud/.untested create mode 100644 detections/experimental/endpoint/.untested create mode 100644 detections/experimental/network/.untested create mode 100644 detections/experimental/web/.untested diff --git a/bin/testing_coverage.py b/bin/testing_coverage.py index eb08bc7ee7..37c1153599 100644 --- a/bin/testing_coverage.py +++ b/bin/testing_coverage.py @@ -29,34 +29,35 @@ for root, _, files in os.walk(get_path("../tests")): tested[detection_type].add(t['file']) for root, _, files in os.walk(get_path("../detections")): - for detection in files: - if detection.endswith('yml') or detection.endswith('yaml'): - detection_desc = parse_detection(os.path.join(root, detection)) - detection_type = detection_desc['type'] - detection = "%s/%s" % (root.split("/")[-1], detection) - if detection not in tested[detection_type]: - if detection_type not in untested: - untested[detection_type] = list() - untested[detection_type].append(detection) + if not os.path.isfile(os.path.join(root, ".untested")): + for detection in files: + if detection.endswith('yml') or detection.endswith('yaml'): + detection_desc = parse_detection(os.path.join(root, detection)) + detection_type = detection_desc['type'] + detection = "%s/%s" % (root.split("/")[-1], detection) + if detection not in tested[detection_type]: + if detection_type not in untested: + untested[detection_type] = list() + untested[detection_type].append(detection) -for k in untested.keys(): +for k in set(untested.keys()).union(tested.keys()): print(''' Tested %s detections ==================== %s -''' % (k, "\n".join(tested[k]))) +''' % (k, "\n".join(tested[k]) if k in tested else "")) print(''' Untested %s detections ====================== %s -''' % (k, "\n".join(untested[k]))) +''' % (k, "\n".join(untested[k]) if k in untested else "")) total_tested = 0 total_untested = 0 -for k in untested.keys(): - n_tested = len(tested[k]) - n_untested = len(untested[k]) +for k in set(untested.keys()).union(tested.keys()): + n_tested = len(tested[k]) if k in tested else 0 + n_untested = len(untested[k]) if k in untested else 0 total_tested = total_tested + n_tested total_untested = total_untested + n_untested print("""%s testing coverage: (%d/%d) %.2f""" diff --git a/detections/experimental/application/.untested b/detections/experimental/application/.untested new file mode 100644 index 0000000000..e69de29bb2 diff --git a/detections/application/detect_phishing_content___ssa.yml b/detections/experimental/application/detect_phishing_content___ssa.yml similarity index 100% rename from detections/application/detect_phishing_content___ssa.yml rename to detections/experimental/application/detect_phishing_content___ssa.yml diff --git a/detections/experimental/cloud/.untested b/detections/experimental/cloud/.untested new file mode 100644 index 0000000000..e69de29bb2 diff --git a/detections/experimental/endpoint/.untested b/detections/experimental/endpoint/.untested new file mode 100644 index 0000000000..e69de29bb2 diff --git a/detections/experimental/network/.untested b/detections/experimental/network/.untested new file mode 100644 index 0000000000..e69de29bb2 diff --git a/detections/experimental/web/.untested b/detections/experimental/web/.untested new file mode 100644 index 0000000000..e69de29bb2