Enable passive ransomware detection by default for beta

This commit is contained in:
OfficeCom Codex
2026-08-01 01:35:58 +02:00
parent d1bbd8838f
commit 7a6db7fbc9
6 changed files with 47 additions and 10 deletions

View File

@@ -10,7 +10,7 @@
"criticalSprayAccountCount": 10, "criticalSprayAccountCount": 10,
"correlationWarningCveThreshold": 1, "correlationWarningCveThreshold": 1,
"correlationCriticalCveThreshold": 1, "correlationCriticalCveThreshold": 1,
"ransomwareBetaEnabled": false, "ransomwareBetaEnabled": true,
"ransomwareBetaAlertingEnabled": false, "ransomwareBetaAlertingEnabled": false,
"ransomwareLookbackMinutes": 15, "ransomwareLookbackMinutes": 15,
"ransomwareWarningSignalCount": 2, "ransomwareWarningSignalCount": 2,

View File

@@ -19,12 +19,13 @@ Die Stable-Aufgabe verwendet keinen Kanalwert oder den Wert `stable`.
## Passive Ransomware-Beta ## Passive Ransomware-Beta
Die Beta ist nach der Installation weiterhin deaktiviert. Auf einem Die Ransomware-Beta ist im Beta-Kanal standardmaessig aktiviert. Die Auswertung
Pilotgeraet wird in `C:\Program Files\OCSentinel\config\ocsentinel-settings.json` bleibt passiv, solange `ransomwareBetaAlertingEnabled` auf `false` steht:
der Wert `ransomwareBetaEnabled` auf `true` gesetzt. Die Auswertung bleibt Hinweise, Warnungen und kritische Beta-Signale erscheinen im JSON-Report und
passiv, solange `ransomwareBetaAlertingEnabled` auf `false` steht: Hinweise, Dashboard, veraendern aber keine NinjaOne-Alarmfelder. Fuer eine lokale
Warnungen und kritische Beta-Signale erscheinen im JSON-Report und Dashboard, Ausnahme kann `ransomwareBetaEnabled` in
veraendern aber keine NinjaOne-Alarmfelder. `C:\Program Files\OCSentinel\config\ocsentinel-settings.json` auf `false`
gesetzt werden.
Der optionale Datei-Churn-Sensor wird nur mit Der optionale Datei-Churn-Sensor wird nur mit
`ransomwareFileChurnEnabled: true` aktiviert. Er wertet ausschliesslich bereits `ransomwareFileChurnEnabled: true` aktiviert. Er wertet ausschliesslich bereits

View File

@@ -112,6 +112,30 @@ function Get-OCSentinelArtifact {
} }
} }
function Enable-OCSentinelBetaDefaults {
param([Parameter(Mandatory)][string]$SettingsPath)
if (-not (Test-Path -LiteralPath $SettingsPath)) {
return
}
$settings = Get-Content -LiteralPath $SettingsPath -Raw | ConvertFrom-Json
if ($null -ne $settings.PSObject.Properties["ransomwareBetaDefaultApplied"]) {
return
}
if ($null -eq $settings.PSObject.Properties["ransomwareBetaEnabled"]) {
$settings | Add-Member -NotePropertyName "ransomwareBetaEnabled" -NotePropertyValue $true
}
else {
$settings.ransomwareBetaEnabled = $true
}
$settings | Add-Member -NotePropertyName "ransomwareBetaDefaultApplied" -NotePropertyValue "1.5.0-beta.4"
$settings | ConvertTo-Json -Depth 10 | Set-Content -LiteralPath $SettingsPath -Encoding UTF8
Write-Host "Enabled passive ransomware beta defaults."
}
Initialize-OCSentinelTls Initialize-OCSentinelTls
if ($ReleaseChannel -eq "stable" -and -not [string]::IsNullOrWhiteSpace($env:ReleaseChannel)) { if ($ReleaseChannel -eq "stable" -and -not [string]::IsNullOrWhiteSpace($env:ReleaseChannel)) {
@@ -133,6 +157,7 @@ $updaterPath = Join-Path $installRoot "scripts\update-ocsentinel.ps1"
$monitorPath = Join-Path $installRoot "scripts\run-ocsentinel-monitor.ps1" $monitorPath = Join-Path $installRoot "scripts\run-ocsentinel-monitor.ps1"
$appPath = Join-Path $installRoot "app\OCSentinelCli.exe" $appPath = Join-Path $installRoot "app\OCSentinelCli.exe"
$clientConfigPath = Join-Path $installRoot "config\ocsentinel-client.json" $clientConfigPath = Join-Path $installRoot "config\ocsentinel-client.json"
$settingsPath = Join-Path $installRoot "config\ocsentinel-settings.json"
$secretScriptPath = Join-Path $installRoot "scripts\protect-ocsentinel-secret.ps1" $secretScriptPath = Join-Path $installRoot "scripts\protect-ocsentinel-secret.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat" $secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
@@ -214,6 +239,10 @@ if (-not (Test-Path -LiteralPath $appPath)) {
throw "OCSentinel installation completed, but the client executable was not found." throw "OCSentinel installation completed, but the client executable was not found."
} }
if ($ReleaseChannel -eq "beta") {
Enable-OCSentinelBetaDefaults -SettingsPath $settingsPath
}
if (-not [string]::IsNullOrWhiteSpace($WebhookUrl)) { if (-not [string]::IsNullOrWhiteSpace($WebhookUrl)) {
if (-not (Test-Path -LiteralPath $clientConfigPath)) { if (-not (Test-Path -LiteralPath $clientConfigPath)) {
throw "OCSentinel client configuration was not found: $clientConfigPath" throw "OCSentinel client configuration was not found: $clientConfigPath"

View File

@@ -26,7 +26,7 @@ internal sealed record ScannerConfiguration
public int CorrelationCriticalCveThreshold { get; init; } = 1; public int CorrelationCriticalCveThreshold { get; init; } = 1;
public bool RansomwareBetaEnabled { get; init; } public bool RansomwareBetaEnabled { get; init; } = true;
public bool RansomwareBetaAlertingEnabled { get; init; } public bool RansomwareBetaAlertingEnabled { get; init; }

View File

@@ -9,10 +9,10 @@
<RootNamespace>OCSentinelCli</RootNamespace> <RootNamespace>OCSentinelCli</RootNamespace>
<Product>OfficeCom Sentinel</Product> <Product>OfficeCom Sentinel</Product>
<Company>OfficeCom</Company> <Company>OfficeCom</Company>
<Version>1.5.0-beta.3</Version> <Version>1.5.0-beta.4</Version>
<AssemblyVersion>1.5.0.0</AssemblyVersion> <AssemblyVersion>1.5.0.0</AssemblyVersion>
<FileVersion>1.5.0.0</FileVersion> <FileVersion>1.5.0.0</FileVersion>
<InformationalVersion>1.5.0-beta.3</InformationalVersion> <InformationalVersion>1.5.0-beta.4</InformationalVersion>
</PropertyGroup> </PropertyGroup>
<ItemGroup> <ItemGroup>

View File

@@ -6,6 +6,13 @@ namespace OCSentinelCli.Tests;
[SupportedOSPlatform("windows")] [SupportedOSPlatform("windows")]
public sealed class RansomwareBetaTests public sealed class RansomwareBetaTests
{ {
[Fact]
public void RansomwareBetaIsEnabledByDefault()
{
Assert.True(new ScannerConfiguration().RansomwareBetaEnabled);
Assert.False(new ScannerConfiguration().RansomwareBetaAlertingEnabled);
}
[Fact] [Fact]
public void FileChurnBelowBothThresholdsDoesNotCreateSignal() public void FileChurnBelowBothThresholdsDoesNotCreateSignal()
{ {