Add time-bounded burst scans
This commit is contained in:
@@ -1,7 +1,9 @@
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[ValidateSet("daily", "burst")]
|
||||
[string]$Kind = "daily"
|
||||
[string]$Kind = "daily",
|
||||
[ValidateRange(15, 480)]
|
||||
[int]$BurstDurationMinutes = 120
|
||||
)
|
||||
|
||||
$ErrorActionPreference = "Stop"
|
||||
@@ -25,9 +27,69 @@ function Get-NinjaBurstEnabled {
|
||||
return $false
|
||||
}
|
||||
|
||||
if ($Kind -eq "burst" -and -not (Get-NinjaBurstEnabled)) {
|
||||
Write-Host "OfficeCom Sentinel burst check: disabled."
|
||||
exit 0
|
||||
function Get-NinjaValue {
|
||||
param([Parameter(Mandatory)][string]$Name, [Parameter(Mandatory)][string]$Type)
|
||||
|
||||
try {
|
||||
if (Get-Command -Name "Get-NinjaProperty" -ErrorAction SilentlyContinue) {
|
||||
return Get-NinjaProperty -Name $Name -Type $Type
|
||||
}
|
||||
if (Get-Command -Name "Ninja-Property-Get" -ErrorAction SilentlyContinue) {
|
||||
return Ninja-Property-Get -Name $Name
|
||||
}
|
||||
}
|
||||
catch {
|
||||
Write-Warning "Could not read Ninja field '$Name': $($_.Exception.Message)"
|
||||
}
|
||||
return $null
|
||||
}
|
||||
|
||||
function Set-NinjaValue {
|
||||
param([Parameter(Mandatory)][string]$Name, [AllowEmptyString()][string]$Value, [Parameter(Mandatory)][string]$Type)
|
||||
|
||||
try {
|
||||
if (Get-Command -Name "Set-NinjaProperty" -ErrorAction SilentlyContinue) {
|
||||
Set-NinjaProperty -Name $Name -Value $Value -Type $Type -Force | Out-Null
|
||||
return $true
|
||||
}
|
||||
if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) {
|
||||
Ninja-Property-Set -Name $Name -Value $Value | Out-Null
|
||||
return $true
|
||||
}
|
||||
}
|
||||
catch {
|
||||
Write-Warning "Could not update Ninja field '$Name': $($_.Exception.Message)"
|
||||
}
|
||||
return $false
|
||||
}
|
||||
|
||||
if ($Kind -eq "burst") {
|
||||
if (-not (Get-NinjaBurstEnabled)) {
|
||||
Set-NinjaValue -Name "ocsentinelburststatus" -Value "idle" -Type "Text" | Out-Null
|
||||
Write-Host "OfficeCom Sentinel burst check: disabled."
|
||||
exit 0
|
||||
}
|
||||
|
||||
$now = [DateTimeOffset]::UtcNow
|
||||
$untilValue = Get-NinjaValue -Name "ocsentinelburstuntilutc" -Type "DateTime"
|
||||
$until = $null
|
||||
if (-not [string]::IsNullOrWhiteSpace([string]$untilValue)) {
|
||||
try { $until = [DateTimeOffset]$untilValue } catch { Write-Warning "Burst end time is invalid and will be restarted." }
|
||||
}
|
||||
|
||||
if ($null -eq $until) {
|
||||
$until = $now.AddMinutes($BurstDurationMinutes)
|
||||
Set-NinjaValue -Name "ocsentinelburstuntilutc" -Value $until.ToString("o") -Type "DateTime" | Out-Null
|
||||
Write-Host "OfficeCom Sentinel burst window started until $($until.ToString('u'))."
|
||||
}
|
||||
elseif ($until -le $now) {
|
||||
Set-NinjaValue -Name "ocsentinelburst" -Value "false" -Type "Checkbox" | Out-Null
|
||||
Set-NinjaValue -Name "ocsentinelburststatus" -Value "completed" -Type "Text" | Out-Null
|
||||
Write-Host "OfficeCom Sentinel burst window completed and was disabled."
|
||||
exit 0
|
||||
}
|
||||
|
||||
Set-NinjaValue -Name "ocsentinelburststatus" -Value "active until $($until.ToUniversalTime().ToString('o'))" -Type "Text" | Out-Null
|
||||
}
|
||||
|
||||
$createdNew = $false
|
||||
@@ -39,7 +101,11 @@ try {
|
||||
}
|
||||
|
||||
Write-Host "OfficeCom Sentinel scheduled $Kind scan started."
|
||||
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $monitorScript -Mode status -UploadMode required -SecretPath $secretPath -SuppressTriggerExit
|
||||
$monitorArgs = @("-NoProfile", "-ExecutionPolicy", "Bypass", "-File", $monitorScript, "-Mode", "status", "-UploadMode", "required", "-SecretPath", $secretPath, "-SuppressTriggerExit")
|
||||
if ($Kind -eq "burst") {
|
||||
$monitorArgs += @("-LookbackDays", "1", "-TopCount", "25")
|
||||
}
|
||||
& powershell.exe @monitorArgs
|
||||
exit $LASTEXITCODE
|
||||
}
|
||||
finally {
|
||||
|
||||
Reference in New Issue
Block a user