Skip to content

Conversation

17cell
Copy link

@17cell 17cell commented Sep 18, 2025

Pull Request

After discussing with @eric-forte-elastic , we decided to configure ES|QL schema validation to reference tests/data/{place-holder}.toml for flexibility, rather than hardcoding a rule in the rules/ directory that might be decommissioned

Summary - What I changed

I cloned the ES|QL rule rules/windows/defense_evasion_posh_obfuscation_index_reversal.toml into tests/data and pointed the rule_path in test_schemas.py to the tests/data directory.

How To Test

python3.12 -m detection_rules test

Copy link

cla-checker-service bot commented Sep 18, 2025

💚 CLA has been signed

@Mikaayenson
Copy link
Contributor

Thanks @17cell for opening the PR. Can you sign the CLA and add a version bump to pyproject.toml ?

@17cell
Copy link
Author

17cell commented Sep 18, 2025

Thanks for the review @Mikaayenson I have bumped the version and signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants