Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Flatten command field types for the jsonpacker #130

Open
wants to merge 7 commits into
base: main
Choose a base branch
from

Conversation

JSCU-CNI
Copy link
Contributor

@JSCU-CNI JSCU-CNI commented Aug 5, 2024

This PR flattens the field type command in the JSON packer and fixes #132.

Currently the dissect.target project is inconsistent in using the same field name command and the new field type command. This patch makes it possible to upload and aggregate on different records in Elasticsearch with the field name command and differing field types.

For example, see RunKeysPlugin.runkeys and PowerShellHistoryPlugin.powershell_history.

You could argue (and we agree) that this should be fixed in dissect.target as all RecordDescriptors currently using ("string", "command") should perhaps use the new command record type. That makes sense to do in the long run. Perhaps a field called full could be added to the standard output of the command fieldtype dict to still be able to index the full, original, command.

Historically the command field type introduced a backwards incompatible change into dissect. This PR fixes that inconsistency.

Copy link

codecov bot commented Aug 5, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 82.52%. Comparing base (c482853) to head (18977b3).

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #130      +/-   ##
==========================================
- Coverage   83.87%   82.52%   -1.35%     
==========================================
  Files          34       34              
  Lines        3478     3480       +2     
==========================================
- Hits         2917     2872      -45     
- Misses        561      608      +47     
Flag Coverage Δ
unittests 82.52% <100.00%> (-1.35%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@Miauwkeru
Copy link
Contributor

Thanks for your contribution, we will look at the changes later. But for now, could you maybe create an issue and attach it to this PR? It would make keeping track of issues a lot easier for us.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Flatten command field types for the jsonpacker
2 participants