Skip to content

fix(rules): remove redundant androdr-084 (duplicates androdr-047)#213

Merged
yasirhamza merged 1 commit into
mainfrom
fix/remove-redundant-androdr-084
Jun 8, 2026
Merged

fix(rules): remove redundant androdr-084 (duplicates androdr-047)#213
yasirhamza merged 1 commit into
mainfrom
fix/remove-redundant-androdr-084

Conversation

@yasirhamza

Copy link
Copy Markdown
Owner

Reverts the bundled rule androdr-084 and bumps the android-sigma-rules submodule to 95cc55f (rules#31).

Why: androdr-084 keyed on CVE-2025-48595, which androdr-047 already covers — 047's source is the CISA Known Exploited Vulnerabilities catalog (= actively-exploited CVEs) and its evidence already lists CVE-2025-48595 with per-CVE severity (CRITICAL). Forced to level: medium by the device_posture severity cap, 084 had no distinction over 047 and rendered a duplicate finding card (confirmed on a real device).

Removes res/raw/sigma_androdr_084_*.yml + its SigmaRuleEngine registration. The 52 IOC entries from the original batch are retained in the submodule.

Sigma test suite green after removal.

🤖 Generated with Claude Code

Unbundles androdr-084 and bumps the android-sigma-rules submodule to 95cc55f
(rule removed there too). androdr-047 already covers CVE-2025-48595 — its
source is the CISA Known Exploited Vulnerabilities catalog and its evidence
lists the CVE with per-CVE severity. Capped at medium by the device_posture
policy, 084 added no distinction over 047 and produced a duplicate card.

The 52 IOC entries from the same batch remain in the submodule.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@yasirhamza yasirhamza merged commit a30fdad into main Jun 8, 2026
3 checks passed
@yasirhamza yasirhamza deleted the fix/remove-redundant-androdr-084 branch June 8, 2026 15:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant