From 8a74bac35cb2c9e17c700fe1ebc79ee7cf44846e Mon Sep 17 00:00:00 2001 From: Mostafa Moradian Date: Fri, 25 Sep 2026 15:36:46 +0200 Subject: [PATCH] Document fieldref combinations and remove the duplicate neq entry fieldref rejects wildcards and may be followed by contains, startswith, or endswith. neq stays the generic negation modifier, so the numeric section no longer repeats it. --- changelog/version-2.1-2.2.md | 2 ++ specification/sigma-appendix-modifiers.md | 11 ++++++++--- 2 files changed, 10 insertions(+), 3 deletions(-) diff --git a/changelog/version-2.1-2.2.md b/changelog/version-2.1-2.2.md index 103e6c9..0282131 100644 --- a/changelog/version-2.1-2.2.md +++ b/changelog/version-2.1-2.2.md @@ -19,6 +19,8 @@ The following is a non-exhaustive list of changes between the v2.1.0 and v2.2.0 ## Modifiers - `re` : Provides a more detailed definition and descripions +- `fieldref` : Rejects wildcards in the referenced field name, may be followed by `contains`, `startswith`, or `endswith`, and combines with `neq` +- `neq` : Removed the duplicate entry from the numeric modifiers, since `neq` is the generic negation modifier ## Tags diff --git a/specification/sigma-appendix-modifiers.md b/specification/sigma-appendix-modifiers.md index 43c9d53..3807cc8 100644 --- a/specification/sigma-appendix-modifiers.md +++ b/specification/sigma-appendix-modifiers.md @@ -100,7 +100,6 @@ The modifiers listed in this section can only be applied to numeric values. - `lte`: Field is less or equal than the value - `gt`: Field is greater than the value - `gte`: Field is greater or equal than the value -- `neq`: Field is not equal than the value ### Time Modifiers @@ -130,14 +129,20 @@ The modifiers listed in this section can only be applied to IP values. - Replace with query expression in target query language (`QueryExpressionPlaceholderTransformation`/`query_expression_placeholders`) - Replace placeholder with wildcard `*`, which should only be used as last resort. (`WildcardPlaceholderTransformation`/`wildcard_placeholders`) -- `fieldref`: Modifies a plain string into a field reference. A field reference can be used to compare fields of matched - events directly at query/matching time. Can be conbine with the `neq` modifier. +- `fieldref`: Modifies a plain string into a field reference. A field reference compares the field with another + field of the matched event at query or matching time. The referenced name must not contain wildcards. + + `fieldref` may be followed by one of `contains`, `startswith`, or `endswith`. That string modifier must come + after `fieldref`, because a string modifier written first inserts wildcards and a field reference rejects them. + `fieldref` may also be combined with `neq`. ## History - 2025-XX-XX Specification v2.2.0 - provides more details on the regex - make use of `(?flag)` or `(?-flag)` deprecated + - document that `fieldref` rejects wildcards, may be followed by `contains`, `startswith`, or `endswith`, and combines with `neq` + - remove the duplicate `neq` entry from Numeric Modifiers, since `neq` is the generic negation modifier - 2025-08-02 Specification v2.1.0 - Add `neq` - Add time modifiers