Rule Customization

Rule-authoring structure

Custom rule structureDescription
rules (Rules)Rules used to identify findings
rule-tests (Tests)Test files for verifying rules
utilsReusable rules for authoring new rules

Rules — rule file structure

FieldDescription
idUnique rule identifier
messageShort rule title
descriptionDescription of the finding
languageTarget language
metadataAdditional data such as cwe, category, references, and technology
(metadata) severitySeverity: critical | high | medium | low | info
(metadata) scoreInteger priority score from 0 to 100 for SAST rules. Use 70 or higher only for high-impact rules likely to identify real vulnerabilities; keep best-practice or hardening rules below 50. Not required for SCA, secrets, or internal-threat rules.
(metadata) fix_descriptionRemediation or response guidance
ruleThe matching rule

Rule example

This example identifies Log4j info calls. A call alone does not demonstrate a Log4j vulnerability.

yaml
id: log4j-logger-info
message: Log4j Logger info usage
description: Identify calls to Log4j Logger info.
language: Java
metadata:
  category: security
  severity: info
  score: 35
  fix_description: |-
    Check whether the deployed Log4j version is affected by the security advisory.
  references: https://www.cisa.gov/news-events/news/apache-log4j-vulnerability-guidance
rule:
  pattern: org.apache.logging.log4j.Logger.info($$$)

Rule-tests — test file structure

FieldDescription
idRule identifier; not required in the web interface
validCode that should not match
invalidCode that should match

Rule test example

yaml
id: log4j-logger-info
valid: 
  - |
    import some.other.safe.Logger;
    
    public class VulnerableExample {
        private static final Logger logger = LogManager.getLogger(VulnerableExample.class);
        public void processUserInput(String userInput) {
            logger.info("User input: {}", userInput);
        }
    }
invalid:
  - |
    import org.apache.logging.log4j.LogManager;
    import org.apache.logging.log4j.Logger;
    
    public class VulnerableExample {
        private static final Logger logger = LogManager.getLogger(VulnerableExample.class);
        public void processUserInput(String userInput) {
            logger.info("User input: {}", userInput);
        }
    }

Utils structure

Field Description
id Unique utility rule identifier
language Target language
rule The matching rule

Utility example

yaml
id: detect-bad-class
language: Java
rule:
    pattern: new BadClass($_N, "BadKey")

Using the utility in a rule:

yaml
id: bad-class-usage
message: BadClass construction
description: Identify object construction matched by the detect-bad-class utility.
language: Java
metadata:
    severity: info
rule:
    matches: detect-bad-class

Related pages2