Skip to content

Document fieldref combinations and remove the duplicate neq entry - #222

Merged
nasbench merged 2 commits into
SigmaHQ:v2.2.0from
mostafa:fix/fieldref-modifiers
Sep 25, 2026
Merged

nasbench merged 2 commits into
SigmaHQ:v2.2.0from
mostafa:fix/fieldref-modifiers

Conversation

@mostafa

@mostafa mostafa commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Summary

This records behavior pySigma already implements.

  • fieldref rejects a referenced name that contains wildcards (SigmaFieldReferenceModifier raises "Field references must not contain wildcards").
  • fieldref may be followed by contains, startswith, or endswith. Those modifiers set the field reference's starts_with and ends_with flags (contains sets both). A string modifier written first inserts wildcards, which the field reference then rejects, so the string modifier has to come after fieldref.
  • fieldref may be combined with neq. In pySigma, neq is SigmaNegateModifier, which negates the detection item. It is not the numeric SigmaNotEqualModifier.
  • The Numeric Modifiers section listed neq a second time. That entry is removed. The generic neq entry stays.

Test plan

  • mdformat --check specification/sigma-appendix-modifiers.md

@nasbench
nasbench changed the base branch from main to v2.2.0 September 25, 2026 20:13
@nasbench

Copy link
Copy Markdown
Member

The changes should target the v2.2 branch. I already changed it for you, please resolve the conflcits.

fieldref rejects wildcards and may be followed by contains, startswith,
or endswith. neq stays the generic negation modifier, so the numeric
section no longer repeats it.
@mostafa
mostafa force-pushed the fix/fieldref-modifiers branch from 7997919 to 8a74bac Compare September 25, 2026 20:41
@nasbench
nasbench merged commit 0cc37db into SigmaHQ:v2.2.0 Sep 25, 2026
4 checks passed
@mostafa
mostafa deleted the fix/fieldref-modifiers branch September 25, 2026 20:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants