Skip to main content

Crate stix_ffi

Crate stix_ffi 

Source
Expand description

FFI-friendly facade over the stix toolkit.

Pure Rust (no FFI macros). The language bindings each wrap this surface: an Engine parses patterns and bundles into opaque Pattern/Bundle handles and runs matches, returning a MatchOutcome; deep structure (the AST, object properties) crosses as JSON.

use stix_ffi::Engine;

let engine = Engine::new();
let pattern = engine.parse_pattern("[ipv4-addr:value = '198.51.100.5']").unwrap();
let bundle = engine.parse_bundle(r#"{"type":"bundle","objects":[
    {"type":"ipv4-addr","id":"ipv4-addr--1","value":"198.51.100.5"},
    {"type":"observed-data","id":"observed-data--1",
     "first_observed":"2020-01-01T00:00:00Z","last_observed":"2020-01-01T00:00:00Z",
     "number_observed":1,"object_refs":["ipv4-addr--1"]}
]}"#).unwrap();
assert!(engine.match_bundle(&pattern, &bundle).unwrap().matched);

Re-exports§

pub use engine::Engine;
pub use error::ErrorCode;
pub use error::FfiError;
pub use handles::Bundle;
pub use handles::MatchOutcome;
pub use handles::Pattern;

Modules§

engine
The Engine handle: owns a registry, parses patterns/bundles, runs matches.
error
The facade’s flat error type, mappable onto host-language exceptions.
handles
Opaque handles (Pattern, Bundle) and the plain MatchOutcome value.