Initial OfficeCom Sentinel client and deployment assets
This commit is contained in:
107
docs/ninjaone-org-report-playbook.md
Normal file
107
docs/ninjaone-org-report-playbook.md
Normal file
@@ -0,0 +1,107 @@
|
||||
# NinjaOne Organization Report Playbook
|
||||
|
||||
> Legacy: This playbook documents the older shared-folder organization reporting model. For the recommended replacement, use the V2 n8n-based design in `attacktracer-ninja-v2-architecture.md`.
|
||||
|
||||
## Goal
|
||||
|
||||
Build a central AttackTracer overview as a local HTML report generated from mirrored device reports.
|
||||
|
||||
## Recommended design
|
||||
|
||||
### Device layer
|
||||
|
||||
Each endpoint continues to write these device custom fields:
|
||||
|
||||
- `attacktracerstatus`
|
||||
- `attacktracerreason`
|
||||
- `attacktracerbasestatus`
|
||||
- `attacktracerevents`
|
||||
- `attacktraceruniqueips`
|
||||
- `attacktracercvecritical`
|
||||
- `attacktracercvetotal`
|
||||
- `attacktracermode`
|
||||
- `attacktracertriggered`
|
||||
- `attacktracerlastscanutc`
|
||||
|
||||
Each endpoint can also mirror its JSON report to a shared folder:
|
||||
|
||||
```powershell
|
||||
& "C:\Program Files\AttackTracerNinja\scripts\run-attacktracer-ninja-monitor.ps1" -Mode status -MirrorRoot "\\fileserver\AttackTracer\OrgA"
|
||||
```
|
||||
|
||||
That will create one JSON file per machine, such as:
|
||||
|
||||
- `\\fileserver\AttackTracer\OrgA\WSUS.json`
|
||||
- `\\fileserver\AttackTracer\OrgA\MILSRV222.json`
|
||||
|
||||
## Central report host
|
||||
|
||||
Use one always-on Windows server as the central report host:
|
||||
|
||||
- stable network path access to the mirrored report share
|
||||
- enough permissions to read every mirrored JSON file
|
||||
- optional browser/file access for opening the rendered HTML report
|
||||
|
||||
This host only builds the local HTML report. It does not write organization-level custom fields back into NinjaOne.
|
||||
|
||||
If your NinjaOne environment exposes `Set-NinjaOrganizationProperty` or `Ninja-Organization-Property-Set`, the same script can also update these text-based organization fields:
|
||||
|
||||
- `attacktracerorgstatus`
|
||||
- `attacktracerorgsummary`
|
||||
- `attacktracerorglastupdate`
|
||||
|
||||
## Org report generator
|
||||
|
||||
Use the organization generator script on the delegate machine:
|
||||
|
||||
- [scripts/build-attacktracer-org-report.ps1](C:\Users\Besitzer\Documents\AttackTracerNinjaVersion\scripts\build-attacktracer-org-report.ps1)
|
||||
|
||||
Installed path after setup:
|
||||
|
||||
- `C:\Program Files\AttackTracerNinja\scripts\build-attacktracer-org-report.ps1`
|
||||
|
||||
### Generate HTML only
|
||||
|
||||
```powershell
|
||||
& "C:\Program Files\AttackTracerNinja\scripts\build-attacktracer-org-report.ps1" `
|
||||
-ReportsRoot "\\fileserver\AttackTracer\OrgA" `
|
||||
-OutputPath "..\reports\attacktracer-org-report.html"
|
||||
```
|
||||
|
||||
### Recommended production command
|
||||
|
||||
```powershell
|
||||
& "C:\Program Files\AttackTracerNinja\scripts\build-attacktracer-org-report.ps1" `
|
||||
-ReportsRoot "\\fileserver\AttackTracer\OrgA" `
|
||||
-OutputPath "\\fileserver\AttackTracer\OrgA\attacktracer-org-report.html"
|
||||
```
|
||||
|
||||
### Optional: also update organization summary fields
|
||||
|
||||
```powershell
|
||||
& "C:\Program Files\AttackTracerNinja\scripts\build-attacktracer-org-report.ps1" `
|
||||
-ReportsRoot "\\fileserver\AttackTracer\OrgA" `
|
||||
-OutputPath "\\fileserver\AttackTracer\OrgA\attacktracer-org-report.html" `
|
||||
-WriteNinjaOrgSummary
|
||||
```
|
||||
|
||||
## What the HTML contains
|
||||
|
||||
The generated HTML report includes:
|
||||
|
||||
- scanned device count
|
||||
- alerting device count
|
||||
- critical device count
|
||||
- total event count
|
||||
- unique source IP count
|
||||
- an alert table with the most relevant rows
|
||||
- a compact `Log sauber` device list
|
||||
|
||||
## Operational recommendation
|
||||
|
||||
Schedule it in two stages:
|
||||
|
||||
1. run the endpoint monitor script on all managed servers and mirror JSON output to the organization share
|
||||
2. run the organization report generator on the central report host a few minutes later
|
||||
|
||||
This keeps the device logic simple and gives you one stable HTML organization summary to open locally or from the share.
|
||||
Reference in New Issue
Block a user