58 Commits

Author SHA1 Message Date
OfficeCom Codex
2cf3281b4d Retry interrupted client package downloads
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Failing after 24s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-27 11:13:48 +02:00
OfficeCom Codex
b2da734c75 Publish stable client version 1.3.6
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 51s
2026-07-27 10:46:41 +02:00
OfficeCom Codex
40c6daada8 Persist Ninja context for scheduled scans
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 56s
2026-07-27 10:45:49 +02:00
OfficeCom Codex
5be4fb6c33 Show event freshness and device coverage
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 47s
2026-07-27 01:50:46 +02:00
OfficeCom Codex
0fe8a96057 Skip unsupported Gitea artifact upload
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 47s
2026-07-27 01:33:31 +02:00
OfficeCom Codex
eb621ace5a Preserve updater exit code in bootstrap
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 22s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 48s
2026-07-27 01:25:26 +02:00
OfficeCom Codex
e997e6b58c Use Roboto for Sentinel dashboard
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 22s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-27 01:24:43 +02:00
OfficeCom Codex
3f09805999 Initialize TLS for legacy client updates
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 47s
2026-07-27 01:22:46 +02:00
OfficeCom Codex
85f0682769 Simplify internal Sentinel dashboard
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 49s
2026-07-27 01:04:49 +02:00
OfficeCom Codex
6722b00ee7 Install PowerShell in Gitea build runner
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 48s
2026-07-27 00:58:51 +02:00
OfficeCom Codex
d3897c8e69 Publish stable client version 1.3.5
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 22s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-27 00:35:43 +02:00
OfficeCom Codex
f9941b0807 Harden release downloads for TLS failures
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-27 00:34:48 +02:00
OfficeCom Codex
c768e1be6b Publish stable client version 1.3.4
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 22s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 21:15:11 +02:00
OfficeCom Codex
2a780cd52f Add time-bounded burst scans
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 21:13:49 +02:00
OfficeCom Codex
daa494fade Publish stable client version 1.3.3
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-26 20:26:37 +02:00
OfficeCom Codex
e7fd4e7ef5 Add resilient upload queue and client health
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 20:25:25 +02:00
OfficeCom Codex
dfdae7a532 Manage weekly report recipients centrally
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-26 11:09:26 +02:00
OfficeCom Codex
854c99e3b2 Configure weekly report recipients
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:49:32 +02:00
OfficeCom Codex
2598de2ecc Polish OCSentinel dashboard interface
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:43:55 +02:00
OfficeCom Codex
6c791cc417 Rename dashboard overview heading
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:42:46 +02:00
OfficeCom Codex
0adac8a0d9 Email weekly organization reports
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:41:46 +02:00
OfficeCom Codex
a45a811040 Refine OCSentinel security dashboard
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-26 03:39:57 +02:00
OfficeCom Codex
2f2a553fc2 Add weekly organization security reports
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:16:47 +02:00
OfficeCom Codex
6ceb29a07b Add read-only OCSentinel debug dashboard
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 02:59:51 +02:00
OfficeCom Codex
1c2170090e Stagger daily scans across early morning
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 02:24:05 +02:00
OfficeCom Codex
91c5794502 Add daily scans and Ninja burst mode
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 02:17:03 +02:00
OfficeCom Codex
f392057535 Document n8n raw body signature validation
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-25 21:26:56 +02:00
OfficeCom Codex
7431c656d3 Use documented NinjaOne custom field commands
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-25 21:17:59 +02:00
OfficeCom Codex
49b0e3025d Fix Ninja client configuration parsing
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-25 21:14:50 +02:00
OfficeCom Codex
aefec51581 Fix NinjaOne environment variable lookup
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-25 21:10:24 +02:00
OfficeCom Codex
7555e92aac Add one-time NinjaOne installation script
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-25 21:01:02 +02:00
OfficeCom Codex
b97b554f84 Add NinjaOne client configuration and upload test
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-25 20:58:54 +02:00
OfficeCom Codex
77d7eaa0b5 Read NinjaOne rollout variables from environment
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-25 18:53:34 +02:00
OfficeCom Codex
f91f45ad92 Prepare automated release validation
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 17s
2026-07-25 10:25:07 +02:00
OfficeCom Codex
c27b53ea0d Use repository secret for Gitea releases
Some checks failed
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
OfficeCom Sentinel Client / validate-client (push) Has been cancelled
2026-07-25 10:24:56 +02:00
OfficeCom Codex
f9d7647046 Detect Gitea release tags by reference name
Some checks failed
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
2026-07-25 10:22:43 +02:00
OfficeCom Codex
d37fba137e Run Gitea release pipeline from tag environment
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-25 10:20:55 +02:00
OfficeCom Codex
e73d79b520 Publish stable manifest for v1.2.6
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 22s
OfficeCom Sentinel Client / build-client-windows (push) Has been skipped
2026-07-25 10:16:52 +02:00
OfficeCom Codex
b0e3e7dc74 Preserve upload configuration during scan and upload
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-25 10:15:23 +02:00
OfficeCom Codex
290033680b Publish release assets from tag workflow
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Has been skipped
2026-07-25 03:08:12 +02:00
OfficeCom Codex
3ea0baa147 Build Windows client packages on Linux runner
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Has been skipped
2026-07-25 03:06:31 +02:00
OfficeCom Codex
e01aa3dce3 Target Windows Gitea runner label
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 02:43:12 +02:00
OfficeCom Codex
8bc1d78fc9 Publish stable manifest for v1.2.5
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 02:40:40 +02:00
OfficeCom Codex
00778175fd Include NinjaOne identifiers in reports
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 02:39:39 +02:00
OfficeCom Codex
34eff4e012 Publish stable manifest for v1.2.4
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 02:35:52 +02:00
OfficeCom Codex
707275f992 Add signed report upload to client runtime
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 02:34:57 +02:00
OfficeCom Codex
b1ee79ca02 Configure upload during Ninja bootstrap
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 02:33:02 +02:00
OfficeCom Codex
053d601e93 Add internal development webhook configuration
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 02:13:13 +02:00
OfficeCom Codex
67a14c125e Document Dockge PostgreSQL deployment
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 01:56:49 +02:00
OfficeCom Codex
335410b418 Add PostgreSQL reporting schema and ingest contract
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 01:41:13 +02:00
OfficeCom Codex
f9f4d862bf Add NinjaOne bootstrap deployment script
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 01:34:52 +02:00
OfficeCom Codex
ea90ddd1f6 Add restricted Windows Gitea runner setup
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-25 01:31:00 +02:00
OfficeCom Codex
1ad720f919 Simplify runs-on labels for Gitea Actions
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 1m11s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-17 02:07:29 +02:00
OfficeCom Codex
61c5e7823a Split Linux validation and Windows release build
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Has been cancelled
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-17 02:03:43 +02:00
OfficeCom Codex
05029c9fb2 Track internal Postgres target in release process
Some checks failed
OfficeCom Sentinel Client / build-client (push) Has been cancelled
2026-07-17 01:12:38 +02:00
OfficeCom Codex
fde24f2616 Add standalone OCSentinel setup executable builder
Some checks failed
OfficeCom Sentinel Client / build-client (push) Has been cancelled
2026-07-17 01:07:37 +02:00
OfficeCom Codex
38a99f2706 Add stable manifest URL for NinjaOne deployments
Some checks failed
OfficeCom Sentinel Client / build-client (push) Has been cancelled
2026-07-17 01:05:56 +02:00
OfficeCom Codex
e8b7a2831d Document manual NinjaOne rollout for v1.2.3
Some checks failed
OfficeCom Sentinel Client / build-client (push) Has been cancelled
2026-07-17 01:00:34 +02:00
54 changed files with 2601 additions and 90 deletions

View File

@@ -7,12 +7,15 @@ on:
tags: tags:
- "v*" - "v*"
workflow_dispatch: workflow_dispatch:
inputs:
build_windows:
description: "Build the Windows release package"
required: false
default: "false"
jobs: jobs:
build-client: validate-client:
runs-on: runs-on: ubuntu-22.04
- self-hosted
- windows
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@v4
@@ -22,25 +25,110 @@ jobs:
with: with:
dotnet-version: "10.0.x" dotnet-version: "10.0.x"
- name: Restore client
run: dotnet restore ./src/OCSentinelCli/OCSentinelCli.csproj
- name: Build client
run: dotnet build ./src/OCSentinelCli/OCSentinelCli.csproj -c Release --no-restore
build-client-windows:
needs: validate-client
# .NET can publish a self-contained Windows x64 client from Linux.
# This keeps releases independent of a Windows Gitea runner.
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup .NET
uses: actions/setup-dotnet@v4
with:
dotnet-version: "10.0.x"
- name: Install PowerShell
shell: bash
run: |
set -euo pipefail
if command -v pwsh >/dev/null 2>&1; then
pwsh --version
exit 0
fi
if [ "$(id -u)" -eq 0 ]; then
SUDO=""
elif command -v sudo >/dev/null 2>&1; then
SUDO="sudo"
else
echo "PowerShell is missing and this runner cannot install packages."
exit 1
fi
. /etc/os-release
case "$ID" in
ubuntu) MICROSOFT_REPO="https://packages.microsoft.com/config/ubuntu/${VERSION_ID}/packages-microsoft-prod.deb" ;;
debian) MICROSOFT_REPO="https://packages.microsoft.com/config/debian/${VERSION_ID}/packages-microsoft-prod.deb" ;;
*) echo "Unsupported runner distribution: $ID"; exit 1 ;;
esac
$SUDO apt-get update
$SUDO apt-get install -y ca-certificates curl
curl -fsSL "$MICROSOFT_REPO" -o /tmp/packages-microsoft-prod.deb
$SUDO dpkg -i /tmp/packages-microsoft-prod.deb
$SUDO apt-get update
$SUDO apt-get install -y powershell
pwsh --version
- name: Build client package - name: Build client package
shell: pwsh shell: pwsh
run: | run: |
./build/build-client-package.ps1 ./build/build-client-package.ps1
- name: Build release manifest for tags - name: Build release manifest for tags
if: startsWith(github.ref, 'refs/tags/v')
shell: pwsh shell: pwsh
run: | run: |
$tag = "${{ github.ref_name }}" $ref = if ($env:GITHUB_REF) { $env:GITHUB_REF } else { $env:GITEA_REF }
$tag = if ($env:GITHUB_REF_NAME) { $env:GITHUB_REF_NAME } else { Split-Path -Leaf $ref }
if ($tag -notlike "v*") {
Write-Host "Not a version tag; skipping release manifest."
exit 0
}
$artifactUrl = "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/$tag/OCSentinelClient-win-x64.zip" $artifactUrl = "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/$tag/OCSentinelClient-win-x64.zip"
./build/build-release-manifest.ps1 -ArtifactUrl $artifactUrl ./build/build-release-manifest.ps1 -ArtifactUrl $artifactUrl
- name: Upload package artifacts - name: Publish Gitea release assets
uses: actions/upload-artifact@v4 shell: pwsh
with: env:
name: ocsentinel-client-${{ github.sha }} GITEA_TOKEN: ${{ secrets.RELEASE_TOKEN }}
path: | run: |
artifacts/OCSentinelClient-win-x64.zip $ref = if ($env:GITHUB_REF) { $env:GITHUB_REF } else { $env:GITEA_REF }
artifacts/OCSentinelClient-win-x64.zip.sha256 $tag = if ($env:GITHUB_REF_NAME) { $env:GITHUB_REF_NAME } else { Split-Path -Leaf $ref }
artifacts/version.json if ($tag -notlike "v*") {
if-no-files-found: warn Write-Host "Not a version tag; skipping Gitea release publication."
exit 0
}
$headers = @{ Authorization = "token $env:GITEA_TOKEN" }
$repository = if ($env:GITEA_REPOSITORY) { $env:GITEA_REPOSITORY } else { $env:GITHUB_REPOSITORY }
$serverUrl = if ($env:GITEA_SERVER_URL) { $env:GITEA_SERVER_URL } else { $env:GITHUB_SERVER_URL }
if ([string]::IsNullOrWhiteSpace($env:GITEA_TOKEN) -or [string]::IsNullOrWhiteSpace($repository) -or [string]::IsNullOrWhiteSpace($serverUrl)) {
throw "Gitea release environment is incomplete. Expected GITEA_TOKEN, repository, and server URL."
}
$baseUrl = "$serverUrl/api/v1/repos/$repository"
$releaseBody = @{
tag_name = $tag
target_commitish = "${{ github.sha }}"
name = "OfficeCom Sentinel $tag"
body = "Automated OfficeCom Sentinel client release."
} | ConvertTo-Json
try {
$release = Invoke-RestMethod -Method Get -Headers $headers -Uri "$baseUrl/releases/tags/$tag"
}
catch {
$release = Invoke-RestMethod -Method Post -Headers $headers -ContentType "application/json" -Body $releaseBody -Uri "$baseUrl/releases"
}
foreach ($file in @("artifacts/OCSentinelClient-win-x64.zip", "artifacts/OCSentinelClient-win-x64.zip.sha256", "artifacts/version.json")) {
$assetName = [System.IO.Path]::GetFileName($file)
Invoke-RestMethod -Method Post -Headers $headers -InFile $file -ContentType "application/octet-stream" -Uri "$baseUrl/releases/$($release.id)/assets?name=$assetName" | Out-Null
}

1
.gitignore vendored
View File

@@ -10,6 +10,7 @@ payload/
*.log *.log
*.zip *.zip
*.sha256 *.sha256
payload.zip
SetupAttackTracer.exe SetupAttackTracer.exe
decompiled/ decompiled/
msi-admin/ msi-admin/

View File

@@ -9,7 +9,10 @@ OfficeCom Sentinel is the hardened endpoint client for Windows event correlation
- Ninja monitor wrapper: `scripts/run-ocsentinel-monitor.ps1` - Ninja monitor wrapper: `scripts/run-ocsentinel-monitor.ps1`
- packaged installer runtime: `installer/runtime-run-ocsentinel.ps1` - packaged installer runtime: `installer/runtime-run-ocsentinel.ps1`
- package builder: `build/build-client-package.ps1` - package builder: `build/build-client-package.ps1`
- setup EXE builder: `build/build-client-installer.ps1`
- update manifest builder: `build/build-release-manifest.ps1` - update manifest builder: `build/build-release-manifest.ps1`
- release checklist: `docs/release-checklist.md`
- internal server-side target example: `infra/postgres-target.example.json`
## Build ## Build

View File

@@ -0,0 +1,50 @@
param(
[string]$Configuration = "Release"
)
$ErrorActionPreference = "Stop"
$repoRoot = Split-Path -Parent $PSScriptRoot
$artifactsRoot = Join-Path $repoRoot "artifacts"
$zipPath = Join-Path $artifactsRoot "OCSentinelClient-win-x64.zip"
$bootstrapperRoot = Join-Path $repoRoot "installer\OCSentinelBootstrapper"
$payloadPath = Join-Path $bootstrapperRoot "payload.zip"
$projectPath = Join-Path $bootstrapperRoot "OCSentinelBootstrapper.csproj"
$publishRoot = Join-Path $artifactsRoot "bootstrapper-publish\win-x64"
$outputExe = Join-Path $artifactsRoot "OCSentinelSetup.exe"
if (-not (Test-Path $zipPath)) {
& powershell.exe -ExecutionPolicy Bypass -File (Join-Path $repoRoot "build\build-client-package.ps1") -Configuration $Configuration
if ($LASTEXITCODE -ne 0) {
throw "build-client-package.ps1 failed"
}
}
Copy-Item -Path $zipPath -Destination $payloadPath -Force
if (Test-Path $publishRoot) {
Remove-Item -LiteralPath $publishRoot -Recurse -Force
}
if (Test-Path $outputExe) {
Remove-Item -LiteralPath $outputExe -Force
}
New-Item -ItemType Directory -Force -Path $publishRoot | Out-Null
& dotnet publish $projectPath `
-c $Configuration `
-r win-x64 `
--self-contained true `
-p:PublishSingleFile=true `
-p:EnableCompressionInSingleFile=true `
-p:IncludeNativeLibrariesForSelfExtract=true `
-o $publishRoot
if ($LASTEXITCODE -ne 0) {
throw "dotnet publish failed for bootstrapper"
}
Copy-Item -Path (Join-Path $publishRoot "OCSentinelBootstrapper.exe") -Destination $outputExe -Force
Write-Host "OfficeCom Sentinel setup executable created at $outputExe"

View File

@@ -54,10 +54,12 @@ Copy-Item -Path (Join-Path $installerRoot "uninstall-ocsentinel.ps1") -Destinati
Copy-Item -Path (Join-Path $installerRoot "update-ocsentinel.ps1") -Destination (Join-Path $packageRoot "scripts\update-ocsentinel.ps1") -Force Copy-Item -Path (Join-Path $installerRoot "update-ocsentinel.ps1") -Destination (Join-Path $packageRoot "scripts\update-ocsentinel.ps1") -Force
Copy-Item -Path (Join-Path $installerRoot "runtime-run-ocsentinel.ps1") -Destination (Join-Path $packageRoot "scripts\run-ocsentinel.ps1") -Force Copy-Item -Path (Join-Path $installerRoot "runtime-run-ocsentinel.ps1") -Destination (Join-Path $packageRoot "scripts\run-ocsentinel.ps1") -Force
Copy-Item -Path (Join-Path $installerRoot "runtime-run-ocsentinel-monitor.ps1") -Destination (Join-Path $packageRoot "scripts\run-ocsentinel-monitor.ps1") -Force Copy-Item -Path (Join-Path $installerRoot "runtime-run-ocsentinel-monitor.ps1") -Destination (Join-Path $packageRoot "scripts\run-ocsentinel-monitor.ps1") -Force
Copy-Item -Path (Join-Path $installerRoot "runtime-run-ocsentinel-scheduled.ps1") -Destination (Join-Path $packageRoot "scripts\run-ocsentinel-scheduled.ps1") -Force
Copy-Item -Path (Join-Path $repoRoot "scripts\protect-ocsentinel-secret.ps1") -Destination (Join-Path $packageRoot "scripts\protect-ocsentinel-secret.ps1") -Force Copy-Item -Path (Join-Path $repoRoot "scripts\protect-ocsentinel-secret.ps1") -Destination (Join-Path $packageRoot "scripts\protect-ocsentinel-secret.ps1") -Force
Copy-Item -Path (Join-Path $repoRoot "config\ocsentinel-settings.example.json") -Destination (Join-Path $packageRoot "config\ocsentinel-settings.example.json") -Force Copy-Item -Path (Join-Path $repoRoot "config\ocsentinel-settings.example.json") -Destination (Join-Path $packageRoot "config\ocsentinel-settings.example.json") -Force
Copy-Item -Path (Join-Path $repoRoot "config\ocsentinel-client.example.json") -Destination (Join-Path $packageRoot "config\ocsentinel-client.example.json") -Force Copy-Item -Path (Join-Path $repoRoot "config\ocsentinel-client.example.json") -Destination (Join-Path $packageRoot "config\ocsentinel-client.example.json") -Force
Copy-Item -Path (Join-Path $repoRoot "config\ocsentinel-client.dev.example.json") -Destination (Join-Path $packageRoot "config\ocsentinel-client.dev.example.json") -Force
Copy-Item -Path (Join-Path $repoRoot "config\update-channel.example.json") -Destination (Join-Path $packageRoot "config\update-channel.example.json") -Force Copy-Item -Path (Join-Path $repoRoot "config\update-channel.example.json") -Destination (Join-Path $packageRoot "config\update-channel.example.json") -Force
Copy-Item -Path (Join-Path $repoRoot "samples\ninja-vulnerability-export.example.csv") -Destination (Join-Path $packageRoot "samples\ninja-vulnerability-export.example.csv") -Force Copy-Item -Path (Join-Path $repoRoot "samples\ninja-vulnerability-export.example.csv") -Destination (Join-Path $packageRoot "samples\ninja-vulnerability-export.example.csv") -Force
Copy-Item -Path (Join-Path $repoRoot "samples\webhook-payload.example.json") -Destination (Join-Path $packageRoot "samples\webhook-payload.example.json") -Force Copy-Item -Path (Join-Path $repoRoot "samples\webhook-payload.example.json") -Destination (Join-Path $packageRoot "samples\webhook-payload.example.json") -Force

View File

@@ -0,0 +1,19 @@
{
"schemaVersion": "2.0",
"environment": "development",
"lookbackDays": 7,
"topFindings": 10,
"n8nWebhookUrl": "http://172.16.41.197:5678/webhook/ocsentinel-ingest",
"ninjaOrganizationId": "",
"ninjaOrganizationName": "",
"ninjaMachineId": "",
"ninjaNodeId": "",
"ninjaLocationId": "",
"ninjaLocationName": "",
"deviceIdentifierMode": "machineName",
"uploadTimeoutSeconds": 30,
"uploadQueueMaxReports": 100,
"enableVulnerabilityCorrelation": true,
"vulnerabilityCsvPath": "",
"secretReference": "device-default"
}

View File

@@ -4,8 +4,15 @@
"lookbackDays": 7, "lookbackDays": 7,
"topFindings": 10, "topFindings": 10,
"n8nWebhookUrl": "https://n8n.example.com/webhook/ocsentinel-ingest", "n8nWebhookUrl": "https://n8n.example.com/webhook/ocsentinel-ingest",
"ninjaOrganizationId": "",
"ninjaOrganizationName": "",
"ninjaMachineId": "",
"ninjaNodeId": "",
"ninjaLocationId": "",
"ninjaLocationName": "",
"deviceIdentifierMode": "machineName", "deviceIdentifierMode": "machineName",
"uploadTimeoutSeconds": 30, "uploadTimeoutSeconds": 30,
"uploadQueueMaxReports": 100,
"enableVulnerabilityCorrelation": true, "enableVulnerabilityCorrelation": true,
"vulnerabilityCsvPath": "", "vulnerabilityCsvPath": "",
"secretReference": "device-default" "secretReference": "device-default"

View File

@@ -19,6 +19,15 @@ The repository now keeps only the client-side architecture:
- optional n8n upload - optional n8n upload
- packaged ZIP release flow for NinjaOne deployment - packaged ZIP release flow for NinjaOne deployment
The client must not depend on a PostgreSQL IP or hostname. PostgreSQL stays a server-side concern behind the ingest or n8n layer.
## PostgreSQL Handling
- PostgreSQL is not contacted directly by endpoint clients.
- The PostgreSQL host or IP should be tracked in the repository only as internal deployment metadata.
- Review that internal target on every release before publishing.
- Keep the actual production value in a private operational copy if it should not be visible in the public repository.
## Removed Model ## Removed Model
The following older pieces are intentionally no longer part of the repo: The following older pieces are intentionally no longer part of the repo:

View File

@@ -17,7 +17,7 @@ Build these locally with:
```powershell ```powershell
powershell -ExecutionPolicy Bypass -File .\build\build-client-package.ps1 powershell -ExecutionPolicy Bypass -File .\build\build-client-package.ps1
powershell -ExecutionPolicy Bypass -File .\build\build-release-manifest.ps1 ` powershell -ExecutionPolicy Bypass -File .\build\build-release-manifest.ps1 `
-ArtifactUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v2.0.0/OCSentinelClient-win-x64.zip" -ArtifactUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.3/OCSentinelClient-win-x64.zip"
``` ```
## Installed Layout ## Installed Layout
@@ -30,13 +30,70 @@ powershell -ExecutionPolicy Bypass -File .\build\build-release-manifest.ps1 `
- `config\ocsentinel-settings.json` - `config\ocsentinel-settings.json`
- `config\ocsentinel-client.json` - `config\ocsentinel-client.json`
## Local Schedule And Burst Mode
During a NinjaOne installation or update, OCSentinel stores the device's
NinjaOne organization, location, and device identifiers in its local client
configuration. Scheduled `SYSTEM` scans restore that context before creating a
report, so their uploads remain assigned to the correct organization.
The installer creates two Windows Scheduled Tasks running as `SYSTEM`:
- `OCSentinel Daily Scan`: runs once per day and uploads one signed report.
The installer deterministically assigns each device a stable slot between
`04:00` and `06:59`, derived from its Windows `MachineGuid`. This distributes
a fleet rollout instead of sending all reports at the same time.
- `OCSentinel Burst Check`: runs every five minutes. It performs no scan unless
the NinjaOne device custom field `ocsentinelburst` is enabled. Once enabled,
it scans for two hours and then disables itself automatically.
Create `ocsentinelburst` as a device-level `Checkbox` custom field and allow
automation read and write access. Set it to `true` for a device to begin the
five-minute burst scans; clear it to stop them early. The normal daily scan
continues regardless of the checkbox.
Create these accompanying device custom fields and allow automation write
access:
| Field name | Type | Purpose |
| --- | --- | --- |
| `ocsentinelburstuntilutc` | Date/Time | UTC time at which the active burst ends |
| `ocsentinelburststatus` | Text | `idle`, `active until ...`, or `completed` |
## Upload Reliability And Client Health
If the upload endpoint is temporarily unavailable, the client stores up to 100
signed report payloads locally under `C:\ProgramData\OCSentinel\upload-queue`.
The next scheduled run sends queued payloads before its new report. The local
health state is stored under `C:\ProgramData\OCSentinel\state`.
Create these additional device custom fields in NinjaOne and allow automation
write access:
| Field name | Type | Purpose |
| --- | --- | --- |
| `ocsentineluploadstatus` | Text | `ok`, `queued`, or `unknown` upload state |
| `ocsentinelqueuedreports` | Integer | Reports waiting for delivery |
| `ocsentinellastuploadutc` | Date/Time | Last successful upload time |
| `ocsentinellasterror` | Text | Last upload error, if any |
| `ocsentinelclientversion` | Text | Installed client version |
## NinjaOne Tasks ## NinjaOne Tasks
Initial install/update: Create a PowerShell script in NinjaOne named `OCSentinel - Installieren oder aktualisieren`.
Run it as `SYSTEM` in 64-bit PowerShell and copy the content of
`scripts/bootstrap-ocsentinel-ninja.ps1` into the NinjaOne script editor.
It is idempotent: new devices install the current package, while installed devices
only update when a newer manifest version is published.
Use it for the one-time rollout and, later, as the monthly update task. For an
initial validation scan, add `-RunInitialStatusScan` to the script parameters.
Installed-client update only:
```powershell ```powershell
& "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" ` & "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" `
-ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v2.0.0/version.json" ` -ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/raw/main/release/stable/version.json" `
-Force -Force
``` ```
@@ -44,7 +101,7 @@ Routine update:
```powershell ```powershell
& "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" ` & "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" `
-ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v2.0.0/version.json" -ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/raw/main/release/stable/version.json"
``` ```
Runtime: Runtime:
@@ -65,3 +122,31 @@ Runtime:
This writes: This writes:
- `C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat` - `C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat`
## Development Upload
For the internal development environment, copy
`config/ocsentinel-client.dev.example.json` to the installed client config
path and use its HTTP webhook URL. Production clients must use the HTTPS
configuration with the public Sentinel domain instead.
## Current Manual Release State
As of July 16, 2026, the first manual release is already published:
- tag: `v1.2.3`
- release URL: `https://gitea.officecom.cloud/officecom/oc-sentinel/releases/tag/v1.2.3`
- stable manifest URL: `https://gitea.officecom.cloud/officecom/oc-sentinel/raw/main/release/stable/version.json`
The manifest is intentionally version-independent for NinjaOne. Only the JSON content changes per release; the NinjaOne task URL stays the same.
This means NinjaOne rollout can start immediately without waiting for a Gitea runner.
## Later Automation
When a Gitea runner is added later, the usual next step is:
1. connect to the runner host through SSH or RDP, depending on the server type
2. install and register the Gitea runner
3. let `.gitea/workflows/client-build.yml` publish future release artifacts automatically
4. update `release/stable/version.json` automatically as part of the release flow

View File

@@ -25,3 +25,51 @@ n8n is responsible for:
- storage in the central backend - storage in the central backend
- organization-wide aggregation - organization-wide aggregation
- NinjaOne organization API updates - NinjaOne organization API updates
## Required n8n Workflow
The webhook itself may be reachable only on the internal network. It does not
require public access to the n8n editor or API. Every managed device must be
able to reach the webhook URL over HTTPS.
For the isolated development environment only, HTTP is permitted at
`http://172.16.41.197:5678/webhook/ocsentinel-ingest`. Do not reuse this URL,
the development shared secret, or a disabled-TLS configuration in production.
1. `Webhook`: accept `POST` on the configured private URL and enable **Raw Body**.
2. `Code`: reject a request if `X-ATN-Device`, `X-ATN-Timestamp`,
`X-ATN-Nonce`, `X-ATN-Version`, `X-ATN-Payload-SHA256`, or
`X-ATN-Signature` is missing; reject timestamps outside five minutes.
3. `Code`: calculate SHA-256 over the raw request body and compare it with
`X-ATN-Payload-SHA256`. Calculate HMAC-SHA256 over the following exact
newline-separated string and compare it in constant time with
`X-ATN-Signature`:
```text
<device>\n<timestamp>\n<nonce>\n<version>\n<payload-sha256>
```
In the current n8n Webhook node, the raw bytes are exposed as Base64 at
`$binary.data.data`. Decode this value before calculating the payload hash.
Do not hash `JSON.stringify($json.body)`: parsing and reserializing JSON
changes whitespace and can change the signed byte sequence.
4. `Postgres`: insert the nonce into `ocsentinel.ingest_nonce` with a short
expiry. If it already exists, return `409` and do not process the report.
5. `Postgres`: upsert the device, insert a row in `ocsentinel.scan_report`,
then return `202`.
6. A separate scheduled n8n workflow reads
`ocsentinel.organization_summary` and `ocsentinel.current_device_status`
to update the NinjaOne organization fields through the API.
Use an n8n credential for the shared HMAC secret and a separate n8n credential
for PostgreSQL. Do not store either value in workflow JSON or this repository.
For the current Docker deployment, use the private hostname
`ocsentinel-postgres` and the restricted database role `ocsentinel_n8n`; see
`infra/dockge/README.md` for the remaining credential fields.
## PostgreSQL Scope
- The client only knows its outward upload destination.
- PostgreSQL connection details belong to the internal ingest or n8n side.
- If the PostgreSQL IP changes, update the internal server-side configuration and review it during the next release.

25
docs/release-checklist.md Normal file
View File

@@ -0,0 +1,25 @@
# Release Checklist
## Goal
Use this checklist before publishing every OfficeCom Sentinel release.
## Infrastructure Check
1. Confirm the internal PostgreSQL target is still correct in `infra/postgres-target.example.json` or its private production counterpart.
2. Confirm the n8n internal base URL is still correct.
3. Confirm the public client ingest URL still forwards to the intended internal service.
4. Confirm no internal PostgreSQL host or IP is embedded in client configuration, installer output, or public release artifacts.
## Build Check
1. Build `OCSentinelClient-win-x64.zip`.
2. Build `OCSentinelSetup.exe`.
3. Generate `version.json`.
4. Verify SHA-256 output matches the released ZIP.
## Publish Check
1. Upload the ZIP, SHA256 file, and setup EXE to the release.
2. Update `release/stable/version.json` so NinjaOne keeps a version-independent manifest URL.
3. If infrastructure changed, update the internal Postgres target record in the repo at the same time.

View File

@@ -0,0 +1,6 @@
DB_HOST=ocsentinel-postgres
DB_PORT=5432
DB_NAME=ocsentinel
DB_USER=ocsentinel_debug
DB_PASSWORD=replace-with-server-generated-password
DASHBOARD_CSRF_SECRET=replace-with-server-generated-secret

View File

@@ -0,0 +1,15 @@
FROM python:3.13-alpine
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY app.py .
COPY templates ./templates
COPY static ./static
RUN addgroup -S ocsentinel && adduser -S ocsentinel -G ocsentinel
USER ocsentinel
EXPOSE 8080
CMD ["gunicorn", "--bind", "0.0.0.0:8080", "--workers", "2", "--threads", "4", "--timeout", "30", "app:app"]

View File

@@ -0,0 +1,301 @@
import hashlib
import hmac
import json
import os
from datetime import datetime, timezone
import psycopg
from flask import Flask, abort, redirect, render_template, request, url_for
app = Flask(__name__)
CURRENT_EVENT_HOURS = 24
STALE_REPORT_HOURS = 36
def db_connection():
return psycopg.connect(
host=os.environ["DB_HOST"],
port=os.getenv("DB_PORT", "5432"),
dbname=os.environ["DB_NAME"],
user=os.environ["DB_USER"],
password=os.environ["DB_PASSWORD"],
connect_timeout=5,
)
def csrf_token():
secret = os.environ["DASHBOARD_CSRF_SECRET"].encode("utf-8")
return hmac.new(secret, b"recipient-rules", hashlib.sha256).hexdigest()
def require_csrf():
supplied = request.form.get("csrf_token", "")
if not hmac.compare_digest(supplied, csrf_token()):
abort(400)
def event_metadata(payload):
latest_event = None
for event in (payload or {}).get("Events", []):
value = event.get("Timestamp")
if not value:
continue
try:
timestamp = datetime.fromisoformat(value.replace("Z", "+00:00"))
except ValueError:
continue
if timestamp.tzinfo is None:
timestamp = timestamp.replace(tzinfo=timezone.utc)
if latest_event is None or timestamp > latest_event:
latest_event = timestamp
if latest_event is None:
return {"is_current": False, "label": "keine Ereignisse", "timestamp": None}
age_seconds = max(0, int((datetime.now(timezone.utc) - latest_event.astimezone(timezone.utc)).total_seconds()))
if age_seconds < 3600:
age_label = f"vor {max(1, age_seconds // 60)} Min."
elif age_seconds < 86400:
age_label = f"vor {age_seconds // 3600} Std."
else:
age_label = f"vor {age_seconds // 86400} Tg."
return {
"is_current": age_seconds <= CURRENT_EVENT_HOURS * 3600,
"label": age_label,
"timestamp": latest_event,
}
@app.get("/")
def overview():
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute("SELECT * FROM ocsentinel.organization_summary")
summary = cursor.fetchone()
cursor.execute(
"""
SELECT machine_name, organization_name, received_at, alert_state,
total_events, unique_ip_count, cve_total, cve_critical, payload
FROM (
SELECT machine_name, received_at, alert_state, total_events,
unique_ip_count, cve_total, cve_critical,
payload #>> '{NinjaOne,OrganizationName}' AS organization_name,
payload
FROM ocsentinel.current_device_status
) AS status
ORDER BY received_at DESC NULLS LAST
LIMIT 100
"""
)
reports = cursor.fetchall()
cursor.execute(
"""
SELECT count(*) AS known_devices,
count(*) FILTER (WHERE received_at >= now() - interval '36 hours') AS reporting_devices,
count(*) FILTER (WHERE received_at IS NULL OR received_at < now() - interval '36 hours') AS stale_devices
FROM ocsentinel.current_device_status
"""
)
coverage = cursor.fetchone()
cursor.execute(
"""
SELECT machine_name, alert_state, total_events, unique_ip_count,
received_at, payload
FROM ocsentinel.current_device_status
WHERE alert_state IN ('warning', 'critical')
ORDER BY CASE alert_state WHEN 'critical' THEN 0 ELSE 1 END, received_at DESC
"""
)
alerts = cursor.fetchall()
report_rows = []
for row in reports:
event = event_metadata(row[8])
report_rows.append(
{
"machine_name": row[0],
"organization_name": row[1],
"received_at": row[2],
"alert_state": row[3],
"total_events": row[4],
"unique_ip_count": row[5],
"event": event,
}
)
alert_rows = []
for row in alerts:
event = event_metadata(row[5])
alert_rows.append(
{
"machine_name": row[0],
"alert_state": row[1],
"total_events": row[2],
"unique_ip_count": row[3],
"received_at": row[4],
"event": event,
}
)
return render_template(
"overview.html",
summary=summary,
coverage=coverage,
reports=report_rows,
alerts=alert_rows,
current_alert_count=sum(alert["event"]["is_current"] for alert in alert_rows),
)
@app.get("/device/<machine_name>")
def device(machine_name):
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
SELECT machine_name, first_seen_at, last_seen_at, last_client_version,
generated_at_utc, received_at, alert_state, base_alert_state,
total_events, unique_ip_count, cve_total, cve_critical, payload
FROM ocsentinel.current_device_status
WHERE machine_name = %s
""",
(machine_name,),
)
report = cursor.fetchone()
if report is None:
abort(404)
payload = report[12]
return render_template(
"device.html",
report=report,
event=event_metadata(payload),
payload=payload,
payload_pretty=json.dumps(payload, indent=2, ensure_ascii=False),
)
@app.get("/reports")
def reports():
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
SELECT id, organization_name, period_start_utc, period_end_utc,
generated_at, device_count, warning_count, critical_count,
total_events
FROM ocsentinel.weekly_organization_report
ORDER BY period_end_utc DESC, organization_name
"""
)
weekly_reports = cursor.fetchall()
return render_template("reports.html", reports=weekly_reports)
@app.get("/reports/<int:report_id>")
def weekly_report(report_id):
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
SELECT organization_name, period_start_utc, period_end_utc,
generated_at, report_html
FROM ocsentinel.weekly_organization_report
WHERE id = %s
""",
(report_id,),
)
report = cursor.fetchone()
if report is None:
abort(404)
return render_template("weekly_report.html", report=report)
@app.get("/recipients")
def recipients():
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
SELECT id, organization_id, organization_name, recipient_email, enabled
FROM ocsentinel.organization_report_recipient
ORDER BY organization_id = '*', organization_name, recipient_email
"""
)
rules = cursor.fetchall()
cursor.execute(
"""
SELECT DISTINCT payload #>> '{NinjaOne,OrganizationId}',
payload #>> '{NinjaOne,OrganizationName}'
FROM ocsentinel.current_device_status
WHERE coalesce(payload #>> '{NinjaOne,OrganizationId}', '') <> ''
ORDER BY 2
"""
)
organizations = cursor.fetchall()
return render_template("recipients.html", rules=rules, organizations=organizations, csrf_token=csrf_token())
@app.post("/recipients")
def add_recipient():
require_csrf()
organization_id = request.form.get("organization_id", "").strip()
organization_name = request.form.get("organization_name", "").strip()
recipient_email = request.form.get("recipient_email", "").strip().lower()
if not organization_id or not organization_name or "@" not in recipient_email:
abort(400)
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
INSERT INTO ocsentinel.organization_report_recipient
(organization_id, organization_name, recipient_email)
VALUES (%s, %s, %s)
ON CONFLICT (organization_id, recipient_email) DO NOTHING
""",
(organization_id, organization_name, recipient_email),
)
connection.commit()
return redirect(url_for("recipients"))
@app.post("/recipients/<int:rule_id>/toggle")
def toggle_recipient(rule_id):
require_csrf()
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"UPDATE ocsentinel.organization_report_recipient SET enabled = NOT enabled WHERE id = %s",
(rule_id,),
)
connection.commit()
return redirect(url_for("recipients"))
@app.post("/recipients/<int:rule_id>/delete")
def delete_recipient(rule_id):
require_csrf()
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute("DELETE FROM ocsentinel.organization_report_recipient WHERE id = %s", (rule_id,))
connection.commit()
return redirect(url_for("recipients"))
@app.get("/healthz")
def healthz():
try:
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute("SELECT 1")
return {"status": "ok"}
except Exception:
return {"status": "unavailable"}, 503
if __name__ == "__main__":
app.run(host="0.0.0.0", port=8080)

View File

@@ -0,0 +1,22 @@
services:
ocsentinel-debug:
build: .
container_name: ocsentinel-debug
restart: unless-stopped
env_file: .env
ports:
- "172.16.41.197:8090:8080"
networks:
- ocsentinel-network
read_only: true
tmpfs:
- /tmp
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
networks:
ocsentinel-network:
external: true
name: n8n_n8n-network

View File

@@ -0,0 +1,3 @@
Flask==3.1.1
gunicorn==23.0.0
psycopg[binary]==3.2.9

View File

@@ -0,0 +1,16 @@
:root { --ink:#17201d; --muted:#66736d; --paper:#f5f3eb; --panel:#fffdf7; --line:#d8d4c6; --green:#236342; --lime:#c7ee6b; --amber:#b86613; --red:#a8342b; }
* { box-sizing:border-box; }
body { margin:0; color:var(--ink); background:radial-gradient(circle at 86% -10%, #d6efad 0, transparent 28rem), var(--paper); font-family:'Roboto',sans-serif; }.app-shell:before { content:''; position:fixed; z-index:-1; inset:0; opacity:.28; background-image:linear-gradient(rgba(35,99,66,.06) 1px,transparent 1px),linear-gradient(90deg,rgba(35,99,66,.06) 1px,transparent 1px); background-size:34px 34px; mask-image:linear-gradient(to bottom,black,transparent 62%); }
.masthead { height:70px; padding:0 6vw; display:flex; align-items:center; justify-content:flex-end; border-bottom:1px solid var(--line); background:rgba(255,253,247,.88); box-shadow:0 4px 22px rgba(35,56,42,.06); backdrop-filter:blur(14px); }.header-links { display:flex; gap:8px; align-items:center; }.header-links a { padding:7px 9px; border-radius:7px; color:var(--muted); font:700 12px 'Roboto',sans-serif; text-decoration:none; transition:background .18s ease,color .18s ease; }.header-links a:hover,.header-links a.active { color:var(--green); background:#e6f1e9; }
.brand { color:var(--ink); font:700 20px/1 'Roboto',sans-serif; text-decoration:none; letter-spacing:-.04em; }.brand span { display:inline-grid; place-items:center; margin-right:7px; width:28px; height:28px; background:var(--green); color:#fff; border-radius:50%; font-size:11px; letter-spacing:0; }.badge,.eyebrow { color:var(--muted); font:700 10px/1 'Roboto',sans-serif; text-transform:uppercase; letter-spacing:.12em; }.badge { border:1px solid var(--line); padding:6px 8px; border-radius:20px; }
main { max-width:1280px; margin:auto; padding:32px 6vw 80px; }.hero { max-width:760px; margin-bottom:32px; }.hero h1 { font-size:clamp(34px,5vw,64px); line-height:.98; letter-spacing:-.06em; margin:10px 0; }.hero p { color:var(--muted); font-size:18px; }.hero.compact h1 { font-size:48px; }.hero-note { display:flex; align-items:center; gap:8px; margin-top:20px; color:var(--green); font:700 11px 'Roboto',sans-serif; letter-spacing:.03em; }.hero-note span { width:8px; height:8px; border-radius:50%; background:var(--lime); box-shadow:0 0 0 4px rgba(199,238,107,.25); }
.metrics { display:grid; grid-template-columns:repeat(5,1fr); gap:10px; margin:25px 0 46px; background:transparent; }.metrics article { min-height:130px; padding:20px; border:1px solid var(--line); border-radius:5px; background:var(--panel); box-shadow:0 5px 16px rgba(35,56,42,.035); transition:transform .18s ease,box-shadow .18s ease; }.metrics article:hover { transform:translateY(-3px); box-shadow:0 12px 24px rgba(35,56,42,.09); }.metrics span { display:block; color:var(--muted); font:700 10px 'Roboto',sans-serif; letter-spacing:.09em; text-transform:uppercase; }.metrics strong { display:block; margin-top:16px; font:700 31px 'Roboto',sans-serif; letter-spacing:-.05em; }.metrics .timestamp { font-size:14px; line-height:1.25; letter-spacing:-.02em; }.warning { color:var(--amber); }.critical { color:var(--red); }
.situation { display:flex; align-items:center; justify-content:space-between; gap:22px; margin:0 0 24px; padding:20px 22px; border:1px solid #b9d8c2; background:#edf8f0; color:#195235; }.situation.warning { border-color:#f2cf99; background:#fff6e8; color:#80450d; }.situation.critical { border-color:#edb4aa; background:#fff0ed; color:#8a2a20; }.situation strong { display:block; margin-top:7px; font:700 19px/1.15 'Roboto',sans-serif; letter-spacing:-.025em; }.situation > span { padding:7px 9px; border:1px solid currentColor; border-radius:20px; font:700 10px 'Roboto',sans-serif; letter-spacing:.1em; }
.panel { margin-top:26px; padding:26px; background:var(--panel); border:1px solid var(--line); border-radius:5px; box-shadow:0 6px 18px rgba(35,56,42,.035); }.panel-heading h2 { margin:8px 0 22px; font-size:28px; letter-spacing:-.04em; }.panel-heading h2 small { color:var(--muted); font-size:12px; font-weight:500; letter-spacing:0; }.alert-grid { display:grid; grid-template-columns:repeat(auto-fit,minmax(210px,1fr)); gap:12px; }.alert-card { padding:17px; border-left:5px solid var(--amber); border-radius:3px; background:#fff7e9; color:var(--ink); text-decoration:none; transition:transform .18s ease,box-shadow .18s ease; }.alert-card:hover { transform:translateY(-2px); box-shadow:0 9px 18px rgba(88,57,20,.12); }.alert-card.critical { border-color:var(--red); background:#fff0ed; }.alert-card span,.alert-card small { display:block; font:700 10px 'Roboto',sans-serif; letter-spacing:.08em; text-transform:uppercase; }.alert-card strong { display:block; margin:10px 0; font:700 22px 'Roboto',sans-serif; letter-spacing:-.04em; }
.coverage-panel { padding-bottom:22px; }.coverage-metrics { display:grid; grid-template-columns:repeat(3,1fr); gap:10px; }.coverage-metrics article { padding:15px; border:1px solid var(--line); border-radius:4px; background:#faf9f4; }.coverage-metrics span { display:block; color:var(--muted); font:700 10px 'Roboto',sans-serif; letter-spacing:.08em; text-transform:uppercase; }.coverage-metrics strong { display:block; margin-top:8px; font-size:26px; }.ok { color:var(--green); }
table { width:100%; border-collapse:collapse; font-family:'Roboto',sans-serif; font-size:13px; } th { text-align:left; color:var(--muted); font-size:10px; letter-spacing:.1em; text-transform:uppercase; } th,td { padding:13px 8px; border-bottom:1px solid var(--line); } td a { color:var(--green); font-weight:700; text-decoration:none; }.state { display:inline-block; margin:1px 3px 1px 0; padding:4px 7px; border-radius:12px; background:#e2efe6; color:var(--green); font:700 10px 'Roboto',sans-serif; text-transform:uppercase; }.state.warning { background:#fff0d7; color:var(--amber); }.state.critical { background:#ffe0db; color:var(--red); }.state.current { background:#e2efe6; color:var(--green); }.state.historic { background:#ece9e1; color:#68736e; } pre { margin:0; padding:18px; overflow:auto; color:#dce7da; background:#13221b; border-radius:4px; font:12px/1.5 'Cascadia Code',Consolas,monospace; }.table-wrap { overflow:auto; }
.report-frame { background:#fff; border:1px solid var(--line); box-shadow:0 12px 40px rgba(20,35,27,.1); }
.panel-heading p:last-child { max-width:720px; margin:-13px 0 20px; color:var(--muted); font-size:14px; }.calm-panel { border-color:#b9d8c2; background:#f4fbf5; }
.recipient-form { display:grid; grid-template-columns:minmax(220px,1fr) minmax(260px,1fr) auto; gap:14px; align-items:end; }.recipient-form label { display:grid; gap:6px; color:var(--muted); font:700 10px 'Roboto',sans-serif; letter-spacing:.08em; text-transform:uppercase; }.recipient-form input,.recipient-form select { min-height:40px; padding:9px 10px; border:1px solid var(--line); border-radius:4px; background:#fff; color:var(--ink); font:14px 'Roboto',sans-serif; }.recipient-form button,.rule-actions button { min-height:40px; padding:9px 13px; border:1px solid var(--green); border-radius:4px; background:var(--green); color:#fff; cursor:pointer; font:700 12px 'Roboto',sans-serif; }.rule-actions { display:flex; gap:8px; }.rule-actions form { margin:0; }.rule-actions .button-secondary { border-color:#d8d4c6; background:#fffdf7; color:var(--ink); }.rule-actions .button-danger { border-color:#e3afa7; background:#fff0ed; color:#8a2a20; }
@media (max-width:850px) { .recipient-form { grid-template-columns:1fr; }.rule-actions { min-width:220px; } }
@media (max-width:850px) { .metrics { grid-template-columns:repeat(2,1fr); }.metrics article:last-child { grid-column:span 2; }.masthead { height:auto; min-height:70px; padding:14px 5vw; align-items:flex-start; }.header-links { justify-content:flex-end; flex-wrap:wrap; }.badge { display:none; } main { padding:38px 5vw; }.situation { align-items:flex-start; flex-direction:column; } }

View File

@@ -0,0 +1,18 @@
<!doctype html>
<html lang="de">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>{% block title %}OC Sentinel{% endblock %}</title>
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap" rel="stylesheet">
<link rel="stylesheet" href="{{ url_for('static', filename='app.css') }}">
</head>
<body class="app-shell">
<header class="masthead">
<nav class="header-links"><a class="{{ 'active' if request.endpoint == 'overview' else '' }}" href="/">Uebersicht</a><a class="{{ 'active' if request.endpoint in ('reports', 'weekly_report') else '' }}" href="{{ url_for('reports') }}">Berichte</a><a class="{{ 'active' if request.endpoint in ('recipients', 'add_recipient', 'toggle_recipient', 'delete_recipient') else '' }}" href="{{ url_for('recipients') }}">Empfaenger</a></nav>
</header>
<main>{% block content %}{% endblock %}</main>
</body>
</html>

View File

@@ -0,0 +1,7 @@
{% extends "base.html" %}
{% block title %}{{ report[0] }} - OC Sentinel{% endblock %}
{% block content %}
<section class="panel"><div class="panel-heading"><h2>{{ report[0] }}</h2><span class="state {{ report[6] }}">{{ report[6] }}</span>{% if report[8] %}<span class="state {{ 'current' if event.is_current else 'historic' }}">{{ 'aktuell' if event.is_current else 'historisch' }}: {{ event.label }}</span>{% endif %}</div></section>
<section class="metrics compact-metrics"><article><span>Ereignisse</span><strong>{{ report[8] }}</strong></article><article><span>Quell-IPs</span><strong>{{ report[9] }}</strong></article><article><span>CVEs</span><strong>{{ report[10] }}</strong></article><article><span>Kritische CVEs</span><strong class="critical">{{ report[11] }}</strong></article></section>
<section class="panel"><pre>{{ payload_pretty }}</pre></section>
{% endblock %}

View File

@@ -0,0 +1,39 @@
{% extends "base.html" %}
{% block content %}
<section class="situation {% if summary[2] %}critical{% elif summary[1] %}warning{% else %}ok{% endif %}">
<div><strong>{% if summary[2] %}Kritische Ereignisse{% elif summary[1] %}Hinweise vorhanden{% else %}Keine kritischen Auffaelligkeiten{% endif %}</strong></div>
<span>{% if summary[2] %}KRITISCH{% elif summary[1] %}PRUEFEN{% else %}STABIL{% endif %}</span>
</section>
<section class="metrics">
<article><span>Geraete</span><strong>{{ summary[0] }}</strong></article>
<article><span>Warnungen</span><strong class="warning">{{ summary[1] }}</strong></article>
<article><span>Kritisch</span><strong class="critical">{{ summary[2] }}</strong></article>
<article><span>Ereignisse</span><strong>{{ summary[3] }}</strong></article>
<article><span>Letzte Meldung</span><strong class="timestamp">{{ summary[7] or '-' }}</strong></article>
</section>
<section class="panel coverage-panel">
<div class="panel-heading"><h2>Geraeteabdeckung</h2></div>
<div class="coverage-metrics"><article><span>Bekannt</span><strong>{{ coverage[0] }}</strong></article><article><span>Meldend &lt; 36 Std.</span><strong class="ok">{{ coverage[1] }}</strong></article><article><span>Stumm &gt; 36 Std.</span><strong class="{% if coverage[2] %}warning{% endif %}">{{ coverage[2] }}</strong></article></div>
</section>
{% if alerts %}
<section class="panel alert-panel">
<div class="panel-heading"><h2>Auffaellige Geraete <small>{{ current_alert_count }} aktuell, {{ alerts|length - current_alert_count }} historisch</small></h2></div>
<div class="alert-grid">
{% for alert in alerts %}
<a class="alert-card {{ alert.alert_state }}" href="{{ url_for('device', machine_name=alert.machine_name) }}">
<span>{{ alert.alert_state }} | {{ 'aktuell' if alert.event.is_current else 'historisch' }}</span><strong>{{ alert.machine_name }}</strong><small>{{ alert.total_events }} Ereignisse | {{ alert.unique_ip_count }} Quell-IPs | letztes Ereignis {{ alert.event.label }}</small>
</a>
{% endfor %}
</div>
</section>
{% endif %}
<section class="panel">
<div class="panel-heading"><h2>Geraetestatus</h2></div>
<div class="table-wrap"><table><thead><tr><th>Geraet</th><th>Organisation</th><th>Status</th><th>Ereignisse</th><th>Quell-IPs</th><th>Empfangen</th></tr></thead>
<tbody>{% for row in reports %}<tr><td><a href="{{ url_for('device', machine_name=row.machine_name) }}">{{ row.machine_name }}</a></td><td>{{ row.organization_name or '-' }}</td><td><span class="state {{ row.alert_state }}">{{ row.alert_state }}</span>{% if row.total_events %}<span class="state {{ 'current' if row.event.is_current else 'historic' }}">{{ 'aktuell' if row.event.is_current else 'historisch' }}</span>{% endif %}</td><td>{{ row.total_events }}</td><td>{{ row.unique_ip_count }}</td><td>{{ row.received_at or '-' }}</td></tr>{% else %}<tr><td colspan="6">Keine Geraeteberichte.</td></tr>{% endfor %}</tbody></table></div>
</section>
{% endblock %}

View File

@@ -0,0 +1,17 @@
{% extends "base.html" %}
{% block title %}Empfaenger - OC Sentinel{% endblock %}
{% block content %}
<section class="panel"><div class="panel-heading"><h2>Empfaenger hinzufuegen</h2></div>
<form class="recipient-form" method="post" action="{{ url_for('add_recipient') }}">
<input type="hidden" name="csrf_token" value="{{ csrf_token }}">
<label>Organisation<select name="organization_id" id="organization_id" required onchange="document.getElementById('organization_name').value=this.options[this.selectedIndex].dataset.name"><option value="*" data-name="Alle Organisationen">Alle Organisationen</option>{% for organization in organizations %}<option value="{{ organization[0] }}" data-name="{{ organization[1] }}">{{ organization[1] }}</option>{% endfor %}</select></label>
<input type="hidden" name="organization_name" id="organization_name" value="Alle Organisationen">
<label>E-Mail-Adresse<input type="email" name="recipient_email" placeholder="name@officecom.it" required></label>
<button type="submit">Speichern</button>
</form></section>
<section class="panel"><div class="panel-heading"><h2>E-Mail-Verteiler</h2></div>
<div class="table-wrap"><table><thead><tr><th>Organisation</th><th>E-Mail-Adresse</th><th>Status</th><th>Aktion</th></tr></thead><tbody>
{% for rule in rules %}<tr><td>{{ rule[2] }}</td><td>{{ rule[3] }}</td><td><span class="state {{ 'ok' if rule[4] else 'warning' }}">{{ 'aktiv' if rule[4] else 'pausiert' }}</span></td><td class="rule-actions"><form method="post" action="{{ url_for('toggle_recipient', rule_id=rule[0]) }}"><input type="hidden" name="csrf_token" value="{{ csrf_token }}"><button class="button-secondary" type="submit">{{ 'Pausieren' if rule[4] else 'Aktivieren' }}</button></form><form method="post" action="{{ url_for('delete_recipient', rule_id=rule[0]) }}"><input type="hidden" name="csrf_token" value="{{ csrf_token }}"><button class="button-danger" type="submit">Loeschen</button></form></td></tr>{% else %}<tr><td colspan="4">Keine Empfaengerregeln.</td></tr>{% endfor %}
</tbody></table></div></section>
{% endblock %}

View File

@@ -0,0 +1,7 @@
{% extends "base.html" %}
{% block title %}Berichte - OC Sentinel{% endblock %}
{% block content %}
<section class="panel"><div class="table-wrap"><table><thead><tr><th>Organisation</th><th>Zeitraum</th><th>Geraete</th><th>Warnung</th><th>Kritisch</th><th>Events</th><th>Erstellt</th></tr></thead><tbody>
{% for row in reports %}<tr><td><a href="{{ url_for('weekly_report', report_id=row[0]) }}">{{ row[1] }}</a></td><td>{{ row[2] }} bis {{ row[3] }}</td><td>{{ row[5] }}</td><td>{{ row[6] }}</td><td>{{ row[7] }}</td><td>{{ row[8] }}</td><td>{{ row[4] }}</td></tr>{% else %}<tr><td colspan="7">Keine Wochenberichte.</td></tr>{% endfor %}
</tbody></table></div></section>
{% endblock %}

View File

@@ -0,0 +1,5 @@
{% extends "base.html" %}
{% block title %}{{ report[0] }} - Wochenbericht{% endblock %}
{% block content %}
<section class="report-frame">{{ report[4] | safe }}</section>
{% endblock %}

44
infra/dockge/README.md Normal file
View File

@@ -0,0 +1,44 @@
# OCSentinel PostgreSQL Dockge Stack
Production is deployed as the Dockge stack directory:
```text
/dockerstacks/ocsentinel-postgres
```
The stack runs `postgres:16-alpine` as `ocsentinel-postgres` and joins the
existing Docker network `n8n_n8n-network`. It deliberately has no `ports:`
mapping, so PostgreSQL is not exposed on the host network or the Internet.
The stack owns these private files on the server:
```text
/dockerstacks/ocsentinel-postgres/compose.yaml
/dockerstacks/ocsentinel-postgres/.env
/dockerstacks/ocsentinel-postgres/init/
/dockerstacks/ocsentinel-postgres/data/
```
`.env` is root-readable only and contains both the PostgreSQL administrator
password and the restricted `ocsentinel_n8n` password. Never commit it or copy
it to endpoint devices.
## n8n PostgreSQL Credential
Create one credential in n8n with these non-secret values:
| Setting | Value |
| --- | --- |
| Host | `ocsentinel-postgres` |
| Port | `5432` |
| Database | `ocsentinel` |
| User | `ocsentinel_n8n` |
| SSL | disabled (private Docker network) |
Retrieve the password only on the server when entering the n8n credential:
```bash
sudo grep '^OCSENTINEL_N8N_PASSWORD=' /dockerstacks/ocsentinel-postgres/.env
```
The database schema source remains [../postgres/001_ocsentinel.sql](../postgres/001_ocsentinel.sql).

View File

@@ -0,0 +1,92 @@
{
"id": "OCwRpt7eK3mQ2xL9",
"name": "OCSentinel - Weekly Organization Reports",
"nodes": [
{
"parameters": { "rule": { "interval": [{ "field": "weeks", "weeksInterval": 1, "triggerAtDay": [1], "triggerAtHour": 7, "triggerAtMinute": 20 }] } },
"id": "schedule-weekly-reports", "name": "Every Monday 07:20", "type": "n8n-nodes-base.scheduleTrigger", "typeVersion": 1.3, "position": [300, 300]
},
{
"parameters": { "operation": "executeQuery", "query": "WITH latest AS (\n SELECT DISTINCT ON (d.id) d.machine_name, r.alert_state, r.payload\n FROM ocsentinel.scan_report AS r\n JOIN ocsentinel.device AS d ON d.id = r.device_id\n WHERE r.received_at >= now() - interval '8 days'\n ORDER BY d.id, r.generated_at_utc DESC, r.received_at DESC\n)\nSELECT machine_name, alert_state, payload\nFROM latest\nORDER BY payload #>> '{NinjaOne,OrganizationName}', machine_name;" },
"id": "load-weekly-data", "name": "Load Latest Device Reports", "type": "n8n-nodes-base.postgres", "typeVersion": 2.5, "position": [560, 300],
"credentials": { "postgres": { "id": "WkjY0kIF3kHvREys", "name": "OCSentinel PostgreSQL" } }
},
{
"parameters": { "jsCode": "const esc=v=>String(v??'').replace(/&/g,'&amp;').replace(/</g,'&lt;').replace(/>/g,'&gt;').replace(/\\\"/g,'&quot;').replace(/'/g,'&#39;');\nconst now=new Date(),end=new Date(Date.UTC(now.getUTCFullYear(),now.getUTCMonth(),now.getUTCDate()));\nend.setUTCDate(end.getUTCDate()-((end.getUTCDay()+6)%7)); const start=new Date(end-7*86400000);\nconst groups=new Map();\nfor(const item of items){const p=item.json.payload||{},n=p.NinjaOne||p.ninjaOne||{},id=String(n.OrganizationId||n.organizationId||'unknown'),name=String(n.OrganizationName||n.organizationName||`Organisation ${id}`);if(!groups.has(id))groups.set(id,{id,name,devices:[]});groups.get(id).devices.push({machine:item.json.machine_name||p.MachineName||'Unbekannt',state:String(item.json.alert_state||p.AlertState||'unknown').toLowerCase(),p});}\nconst result=[];\nfor(const group of groups.values()){let warnings=0,criticals=0,total=0,cveTotal=0,cveCritical=0;const ips=new Set(),alerts=[],clean=[];for(const d of group.devices){if(d.state==='warning')warnings++;if(d.state==='critical')criticals++;const vc=d.p.VulnerabilityCorrelation||{};cveTotal+=Number(vc.TotalCount||0);cveCritical+=Number(vc.CriticalCount||0);const events=(d.p.Events||[]).filter(e=>{const t=new Date(e.Timestamp);return !Number.isNaN(t)&&t>=start&&t<end;});total+=events.length;if(!events.length){clean.push(`<tr class=\"clean\"><td>${esc(d.machine)}</td><td>Keine</td><td>-</td><td>-</td><td>0</td><td>-</td><td>Log sauber / Keine Angriffe</td></tr>`);continue;}const rows=new Map();for(const e of events){const ip=e.SourceIp||'-',account=e.Username||'-',type=e.Target||'Sicherheitsereignis',key=[type,account,ip].join('|'),row=rows.get(key)||{ip,account,type,count:0,last:e.Timestamp};row.count++;if(new Date(e.Timestamp)>new Date(row.last))row.last=e.Timestamp;rows.set(key,row);if(ip!=='-')ips.add(ip);}for(const r of rows.values()){alerts.push(`<tr class=\"alert\"><td>${esc(d.machine)}</td><td>${esc(r.type)}</td><td>${esc(r.account)}</td><td>${esc(new Date(r.last).toLocaleString('de-DE',{timeZone:'Europe/Berlin'}))}</td><td>${r.count}</td><td>${esc(r.ip)}</td><td>${d.state==='critical'?'Problem entdeckt (kritisch)':'Problem entdeckt'}</td></tr>`);}}const summary={deviceCount:group.devices.length,warningCount:warnings,criticalCount:criticals,totalEvents:total,uniqueIps:ips.size,cveTotal,cveCritical};const html=`<div class=\"ocsentinel-report\"><style>.ocsentinel-report{font-family:Arial,sans-serif;font-size:12px;color:#1f2937;max-width:1200px}.ocsentinel-report h2{font-size:16px;color:#183b79;margin:0 0 5px;border-bottom:1px solid #183b79;padding-bottom:5px}.ocsentinel-report .meta{font-size:11px;color:#4b5563;margin-bottom:12px}.ocsentinel-report .summary{margin:10px 0;padding:8px;background:#eef5ff;border:1px solid #bfd4f2;color:#183b79}.ocsentinel-report table{width:100%;border-collapse:collapse}.ocsentinel-report th{background:#1f4a99;color:#fff;text-align:left;padding:6px;font-size:11px}.ocsentinel-report td{border:1px solid #e5e7eb;padding:6px;vertical-align:top}.ocsentinel-report tr.alert{background:#fff4ed;color:#8a3d16}.ocsentinel-report tr.clean{background:#effcf4;color:#17643a}.ocsentinel-report .footer{margin-top:10px;font-size:10px;color:#6b7280;text-align:right}</style><h2>OCSentinel - Konsolidierter Sicherheitsbericht</h2><div class=\"meta\"><strong>${esc(group.name)}</strong><br>Berichtszeitraum: ${start.toLocaleDateString('de-DE')} bis ${end.toLocaleDateString('de-DE')}<br>Erstellt am: ${now.toLocaleString('de-DE',{timeZone:'Europe/Berlin'})}</div><div class=\"summary\"><strong>${summary.deviceCount} Geräte</strong> | <strong>${summary.criticalCount} kritisch</strong> | <strong>${summary.warningCount} Warnungen</strong> | <strong>${summary.totalEvents} Ereignisse</strong> | <strong>${summary.uniqueIps} IPs</strong> | <strong>${summary.cveCritical} kritische CVEs</strong></div><table><thead><tr><th>Server</th><th>Vorfall-Typ</th><th>Betroffenes Konto</th><th>Letzter Zeitpunkt</th><th>Anzahl</th><th>Angreifer-IP</th><th>Status / Bemerkung</th></tr></thead><tbody>${alerts.join('')}${clean.join('')}</tbody></table><div class=\"footer\">Automatisch durch OCSentinel und n8n erzeugt.</div></div>`;result.push({json:{organizationId:group.id,organizationName:group.name,periodStartUtc:start.toISOString(),periodEndUtc:end.toISOString(),...summary,reportHtml:html,summaryJson:JSON.stringify(summary)}});}return result;" },
"id": "build-weekly-reports", "name": "Build Organization HTML Reports", "type": "n8n-nodes-base.code", "typeVersion": 2, "position": [820, 300]
},
{
"parameters": { "operation": "executeQuery", "query": "INSERT INTO ocsentinel.weekly_organization_report (organization_id, organization_name, period_start_utc, period_end_utc, device_count, warning_count, critical_count, total_events, unique_ips, cve_total, cve_critical, report_html, summary)\nVALUES ($1, $2, $3::timestamptz, $4::timestamptz, $5, $6, $7, $8, $9, $10, $11, $12, $13::jsonb)\nON CONFLICT (organization_id, period_start_utc) DO UPDATE SET organization_name=EXCLUDED.organization_name, period_end_utc=EXCLUDED.period_end_utc, generated_at=now(), device_count=EXCLUDED.device_count, warning_count=EXCLUDED.warning_count, critical_count=EXCLUDED.critical_count, total_events=EXCLUDED.total_events, unique_ips=EXCLUDED.unique_ips, cve_total=EXCLUDED.cve_total, cve_critical=EXCLUDED.cve_critical, report_html=EXCLUDED.report_html, summary=EXCLUDED.summary\nRETURNING id;", "options": { "queryReplacement": "={{ [$json.organizationId, $json.organizationName, $json.periodStartUtc, $json.periodEndUtc, $json.deviceCount, $json.warningCount, $json.criticalCount, $json.totalEvents, $json.uniqueIps, $json.cveTotal, $json.cveCritical, $json.reportHtml, $json.summaryJson] }}" } },
"id": "store-weekly-reports", "name": "Store Weekly Organization Reports", "type": "n8n-nodes-base.postgres", "typeVersion": 2.5, "position": [1080, 300],
"credentials": { "postgres": { "id": "WkjY0kIF3kHvREys", "name": "OCSentinel PostgreSQL" } }
},
{
"parameters": {
"assignments": {
"assignments": [
{ "id": "email-enabled", "name": "emailEnabled", "value": true, "type": "boolean" }
]
},
"options": {}
},
"id": "email-delivery-toggle",
"name": "E-Mail-Versand aktiv",
"type": "n8n-nodes-base.set",
"typeVersion": 3.4,
"position": [1330, 300]
},
{
"parameters": {
"operation": "executeQuery",
"query": "SELECT coalesce(array_agg(recipient_email ORDER BY recipient_email), ARRAY[]::text[]) AS recipients\nFROM ocsentinel.organization_report_recipient\nWHERE enabled = TRUE AND (organization_id = '*' OR organization_id = $1);",
"options": { "queryReplacement": "={{ [ $('Build Organization HTML Reports').item.json.organizationId ] }}" }
},
"id": "load-report-recipients",
"name": "Empfaenger aus zentraler Zuordnung laden",
"type": "n8n-nodes-base.postgres",
"typeVersion": 2.5,
"position": [1560, 300]
,"credentials": { "postgres": { "id": "WkjY0kIF3kHvREys", "name": "OCSentinel PostgreSQL" } }
},
{
"parameters": {
"jsCode": "const report = $('Build Organization HTML Reports').item.json;\nconst emailEnabled = $('E-Mail-Versand aktiv').item.json.emailEnabled === true;\nif (!emailEnabled) return [];\nconst recipients = Array.from(new Set($json.recipients || []));\nif (recipients.length === 0) throw new Error(`No weekly report recipients configured for ${report.organizationName}.`);\nreturn [{ json: { ...report, recipients } }];"
},
"id": "prepare-report-email",
"name": "E-Mail vorbereiten",
"type": "n8n-nodes-base.code",
"typeVersion": 2,
"position": [1800, 300]
},
{
"parameters": {
"fromEmail": "donotreply@officecom.biz",
"toEmail": "={{ $json.recipients.join(', ') }}",
"subject": "=OCSentinel Wochenbericht - {{ $json.organizationName }}",
"html": "={{ $json.reportHtml }}",
"options": { "appendAttribution": false }
},
"id": "send-weekly-report-email",
"name": "Send Weekly Organization Report",
"type": "n8n-nodes-base.emailSend",
"typeVersion": 2.1,
"position": [2040, 300],
"credentials": { "smtp": { "id": "vafGYgYzM9SbxQbW", "name": "SMTP account" } }
}
],
"connections": {
"Every Monday 07:20": { "main": [[{ "node": "Load Latest Device Reports", "type": "main", "index": 0 }]] },
"Load Latest Device Reports": { "main": [[{ "node": "Build Organization HTML Reports", "type": "main", "index": 0 }]] },
"Build Organization HTML Reports": { "main": [[{ "node": "Store Weekly Organization Reports", "type": "main", "index": 0 }]] },
"Store Weekly Organization Reports": { "main": [[{ "node": "E-Mail-Versand aktiv", "type": "main", "index": 0 }]] },
"E-Mail-Versand aktiv": { "main": [[{ "node": "Empfaenger aus zentraler Zuordnung laden", "type": "main", "index": 0 }]] },
"Empfaenger aus zentraler Zuordnung laden": { "main": [[{ "node": "E-Mail vorbereiten", "type": "main", "index": 0 }]] },
"E-Mail vorbereiten": { "main": [[{ "node": "Send Weekly Organization Report", "type": "main", "index": 0 }]] }
},
"settings": { "executionOrder": "v1", "timezone": "Europe/Berlin" },
"active": true,
"pinData": {},
"versionId": "af98f45b-192e-49c8-9a1e-e7b1fc7e00b2",
"meta": { "templateCredsSetupCompleted": true },
"tags": []
}

View File

@@ -0,0 +1,10 @@
{
"role": "server-side-only",
"environment": "production",
"postgresHost": "10.0.0.25",
"postgresPort": 5432,
"postgresDatabase": "ocsentinel",
"postgresSslMode": "require",
"n8nInternalBaseUrl": "http://n8n.internal:5678",
"notes": "This file is for the internal ingest or n8n side only. Do not deploy this file to endpoint clients."
}

View File

@@ -0,0 +1,103 @@
-- OfficeCom Sentinel central reporting store.
-- Apply once as a PostgreSQL administrator to the dedicated ocsentinel database.
BEGIN;
CREATE SCHEMA IF NOT EXISTS ocsentinel;
CREATE TABLE IF NOT EXISTS ocsentinel.device (
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
machine_name TEXT NOT NULL,
machine_name_key TEXT NOT NULL UNIQUE,
first_seen_at TIMESTAMPTZ NOT NULL DEFAULT now(),
last_seen_at TIMESTAMPTZ NOT NULL DEFAULT now(),
last_client_version TEXT NOT NULL DEFAULT ''
);
CREATE TABLE IF NOT EXISTS ocsentinel.scan_report (
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
device_id BIGINT NOT NULL REFERENCES ocsentinel.device(id) ON DELETE CASCADE,
generated_at_utc TIMESTAMPTZ NOT NULL,
received_at TIMESTAMPTZ NOT NULL DEFAULT now(),
client_version TEXT NOT NULL,
alert_state TEXT NOT NULL CHECK (alert_state IN ('ok', 'warning', 'critical', 'unknown')),
base_alert_state TEXT NOT NULL CHECK (base_alert_state IN ('ok', 'warning', 'critical', 'unknown')),
total_events INTEGER NOT NULL CHECK (total_events >= 0),
unique_ip_count INTEGER NOT NULL CHECK (unique_ip_count >= 0),
cve_total INTEGER NOT NULL DEFAULT 0 CHECK (cve_total >= 0),
cve_critical INTEGER NOT NULL DEFAULT 0 CHECK (cve_critical >= 0),
payload_sha256 CHAR(64) NOT NULL,
payload JSONB NOT NULL,
UNIQUE (device_id, generated_at_utc, payload_sha256)
);
CREATE INDEX IF NOT EXISTS ix_ocsentinel_scan_report_device_received
ON ocsentinel.scan_report (device_id, received_at DESC);
CREATE INDEX IF NOT EXISTS ix_ocsentinel_scan_report_alert_received
ON ocsentinel.scan_report (alert_state, received_at DESC);
CREATE TABLE IF NOT EXISTS ocsentinel.ingest_nonce (
nonce CHAR(32) PRIMARY KEY,
device_id BIGINT NOT NULL REFERENCES ocsentinel.device(id) ON DELETE CASCADE,
received_at TIMESTAMPTZ NOT NULL DEFAULT now(),
expires_at TIMESTAMPTZ NOT NULL
);
CREATE INDEX IF NOT EXISTS ix_ocsentinel_ingest_nonce_expires
ON ocsentinel.ingest_nonce (expires_at);
CREATE TABLE IF NOT EXISTS ocsentinel.weekly_organization_report (
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
organization_id TEXT NOT NULL,
organization_name TEXT NOT NULL,
period_start_utc TIMESTAMPTZ NOT NULL,
period_end_utc TIMESTAMPTZ NOT NULL,
generated_at TIMESTAMPTZ NOT NULL DEFAULT now(),
device_count INTEGER NOT NULL DEFAULT 0,
warning_count INTEGER NOT NULL DEFAULT 0,
critical_count INTEGER NOT NULL DEFAULT 0,
total_events INTEGER NOT NULL DEFAULT 0,
unique_ips INTEGER NOT NULL DEFAULT 0,
cve_total INTEGER NOT NULL DEFAULT 0,
cve_critical INTEGER NOT NULL DEFAULT 0,
report_html TEXT NOT NULL,
summary JSONB NOT NULL DEFAULT '{}'::jsonb,
UNIQUE (organization_id, period_start_utc)
);
CREATE INDEX IF NOT EXISTS ix_ocsentinel_weekly_report_organization_generated
ON ocsentinel.weekly_organization_report (organization_id, generated_at DESC);
CREATE OR REPLACE VIEW ocsentinel.current_device_status AS
SELECT DISTINCT ON (d.id)
d.machine_name,
d.first_seen_at,
d.last_seen_at,
d.last_client_version,
r.generated_at_utc,
r.received_at,
r.alert_state,
r.base_alert_state,
r.total_events,
r.unique_ip_count,
r.cve_total,
r.cve_critical,
r.payload
FROM ocsentinel.device AS d
LEFT JOIN ocsentinel.scan_report AS r ON r.device_id = d.id
ORDER BY d.id, r.generated_at_utc DESC NULLS LAST, r.received_at DESC NULLS LAST;
CREATE OR REPLACE VIEW ocsentinel.organization_summary AS
SELECT
count(*) FILTER (WHERE generated_at_utc IS NOT NULL) AS devices_reporting,
count(*) FILTER (WHERE alert_state = 'warning') AS devices_warning,
count(*) FILTER (WHERE alert_state = 'critical') AS devices_critical,
coalesce(sum(total_events), 0) AS total_events,
coalesce(sum(unique_ip_count), 0) AS total_unique_ips,
coalesce(sum(cve_total), 0) AS total_cves,
coalesce(sum(cve_critical), 0) AS critical_cves,
max(received_at) AS last_report_received_at
FROM ocsentinel.current_device_status;
COMMIT;

View File

@@ -0,0 +1,25 @@
-- Central recipient rules for OCSentinel weekly organization reports.
-- The '*' organization ID applies to every organization.
BEGIN;
CREATE TABLE IF NOT EXISTS ocsentinel.organization_report_recipient (
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
organization_id TEXT NOT NULL,
organization_name TEXT NOT NULL,
recipient_email TEXT NOT NULL,
enabled BOOLEAN NOT NULL DEFAULT TRUE,
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
UNIQUE (organization_id, recipient_email)
);
INSERT INTO ocsentinel.organization_report_recipient
(organization_id, organization_name, recipient_email)
VALUES
('*', 'Alle Organisationen', 'lg@officecom.it'),
('*', 'Alle Organisationen', 'rk@officecom.biz'),
('9', 'Mildenberger Verlag', 'dd@officecom.it'),
('16', 'Kirsch GmbH', 'dd@officecom.it')
ON CONFLICT (organization_id, recipient_email) DO NOTHING;
COMMIT;

36
infra/postgres/README.md Normal file
View File

@@ -0,0 +1,36 @@
# OfficeCom Sentinel PostgreSQL
PostgreSQL is the private central store for endpoint reports. It is never
contacted directly by an endpoint; only n8n uses a database account.
## Provisioning
The production instance is deployed as the private Dockge stack documented in
[../dockge/README.md](../dockge/README.md). The bootstrap has already created
the database, schema, and restricted `ocsentinel_n8n` role.
For a separate future installation:
1. Create a database named `ocsentinel` on the private PostgreSQL server.
2. Apply `001_ocsentinel.sql` as a database administrator.
3. Create a non-superuser n8n login and grant only the necessary permissions:
```sql
GRANT USAGE ON SCHEMA ocsentinel TO ocsentinel_n8n;
GRANT SELECT, INSERT, UPDATE, DELETE ON ALL TABLES IN SCHEMA ocsentinel TO ocsentinel_n8n;
GRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA ocsentinel TO ocsentinel_n8n;
GRANT SELECT ON ocsentinel.current_device_status, ocsentinel.organization_summary TO ocsentinel_n8n;
ALTER DEFAULT PRIVILEGES IN SCHEMA ocsentinel
GRANT SELECT, INSERT, UPDATE, DELETE ON TABLES TO ocsentinel_n8n;
```
Keep the database host, password, and TLS settings only in n8n credentials.
They do not belong in Gitea, NinjaOne scripts, or endpoint configuration.
## Maintenance
Run monthly from n8n or an administrator session to remove expired replay tokens:
```sql
DELETE FROM ocsentinel.ingest_nonce WHERE expires_at < now();
```

View File

@@ -0,0 +1,22 @@
<Project Sdk="Microsoft.NET.Sdk">
<PropertyGroup>
<OutputType>Exe</OutputType>
<TargetFramework>net10.0-windows</TargetFramework>
<ImplicitUsings>enable</ImplicitUsings>
<Nullable>enable</Nullable>
<UseWindowsForms>false</UseWindowsForms>
<AssemblyName>OCSentinelBootstrapper</AssemblyName>
<RootNamespace>OCSentinelBootstrapper</RootNamespace>
<PublishSingleFile>true</PublishSingleFile>
<SelfContained>true</SelfContained>
<RuntimeIdentifier>win-x64</RuntimeIdentifier>
<EnableCompressionInSingleFile>true</EnableCompressionInSingleFile>
<IncludeNativeLibrariesForSelfExtract>true</IncludeNativeLibrariesForSelfExtract>
</PropertyGroup>
<ItemGroup>
<EmbeddedResource Include="payload.zip" LogicalName="payload.zip" />
</ItemGroup>
</Project>

View File

@@ -0,0 +1,76 @@
using System.Diagnostics;
using System.IO.Compression;
using System.Reflection;
namespace OCSentinelBootstrapper;
internal static class Program
{
private static int Main()
{
string tempRoot = Path.Combine(Path.GetTempPath(), "OCSentinelSetup", Guid.NewGuid().ToString("N"));
string zipPath = Path.Combine(tempRoot, "payload.zip");
string extractRoot = Path.Combine(tempRoot, "payload");
try
{
Directory.CreateDirectory(tempRoot);
Directory.CreateDirectory(extractRoot);
ExtractEmbeddedPayload(zipPath);
ZipFile.ExtractToDirectory(zipPath, extractRoot, overwriteFiles: true);
string installScript = Path.Combine(extractRoot, "scripts", "install-ocsentinel.ps1");
if (!File.Exists(installScript))
{
throw new FileNotFoundException("Embedded payload did not contain install-ocsentinel.ps1", installScript);
}
var process = new Process
{
StartInfo = new ProcessStartInfo
{
FileName = "powershell.exe",
Arguments = $"-ExecutionPolicy Bypass -File \"{installScript}\"",
UseShellExecute = false
}
};
process.Start();
process.WaitForExit();
return process.ExitCode;
}
catch (Exception ex)
{
Console.Error.WriteLine($"OCSentinel installer failed: {ex}");
return 1;
}
finally
{
try
{
if (Directory.Exists(tempRoot))
{
Directory.Delete(tempRoot, recursive: true);
}
}
catch
{
// Best-effort cleanup only.
}
}
}
private static void ExtractEmbeddedPayload(string destinationPath)
{
Assembly assembly = Assembly.GetExecutingAssembly();
using Stream? resourceStream = assembly.GetManifestResourceStream("payload.zip");
if (resourceStream is null)
{
throw new InvalidOperationException("Embedded payload.zip resource was not found.");
}
using FileStream output = File.Create(destinationPath);
resourceStream.CopyTo(output);
}
}

View File

@@ -26,9 +26,13 @@ Copy-Item -Path (Join-Path $packageRoot "config\ocsentinel-settings.example.json
if (Test-Path (Join-Path $packageRoot "config\ocsentinel-client.example.json")) { if (Test-Path (Join-Path $packageRoot "config\ocsentinel-client.example.json")) {
Copy-Item -Path (Join-Path $packageRoot "config\ocsentinel-client.example.json") -Destination (Join-Path $configRoot "ocsentinel-client.example.json") -Force Copy-Item -Path (Join-Path $packageRoot "config\ocsentinel-client.example.json") -Destination (Join-Path $configRoot "ocsentinel-client.example.json") -Force
} }
if (Test-Path (Join-Path $packageRoot "config\ocsentinel-client.dev.example.json")) {
Copy-Item -Path (Join-Path $packageRoot "config\ocsentinel-client.dev.example.json") -Destination (Join-Path $configRoot "ocsentinel-client.dev.example.json") -Force
}
Copy-Item -Path (Join-Path $packageRoot "samples\ninja-vulnerability-export.example.csv") -Destination (Join-Path $samplesRoot "ninja-vulnerability-export.example.csv") -Force Copy-Item -Path (Join-Path $packageRoot "samples\ninja-vulnerability-export.example.csv") -Destination (Join-Path $samplesRoot "ninja-vulnerability-export.example.csv") -Force
Copy-Item -Path (Join-Path $packageRoot "scripts\run-ocsentinel.ps1") -Destination $scriptRoot -Force Copy-Item -Path (Join-Path $packageRoot "scripts\run-ocsentinel.ps1") -Destination $scriptRoot -Force
Copy-Item -Path (Join-Path $packageRoot "scripts\run-ocsentinel-monitor.ps1") -Destination $scriptRoot -Force Copy-Item -Path (Join-Path $packageRoot "scripts\run-ocsentinel-monitor.ps1") -Destination $scriptRoot -Force
Copy-Item -Path (Join-Path $packageRoot "scripts\run-ocsentinel-scheduled.ps1") -Destination $scriptRoot -Force
if (Test-Path (Join-Path $packageRoot "scripts\protect-ocsentinel-secret.ps1")) { if (Test-Path (Join-Path $packageRoot "scripts\protect-ocsentinel-secret.ps1")) {
Copy-Item -Path (Join-Path $packageRoot "scripts\protect-ocsentinel-secret.ps1") -Destination $scriptRoot -Force Copy-Item -Path (Join-Path $packageRoot "scripts\protect-ocsentinel-secret.ps1") -Destination $scriptRoot -Force
} }
@@ -66,8 +70,34 @@ Set-ItemProperty -Path $uninstallKey -Name "QuietUninstallString" -Value $uninst
Set-ItemProperty -Path $uninstallKey -Name "NoModify" -Value 1 -Type DWord Set-ItemProperty -Path $uninstallKey -Name "NoModify" -Value 1 -Type DWord
Set-ItemProperty -Path $uninstallKey -Name "NoRepair" -Value 1 -Type DWord Set-ItemProperty -Path $uninstallKey -Name "NoRepair" -Value 1 -Type DWord
$scheduledScript = Join-Path $scriptRoot "run-ocsentinel-scheduled.ps1"
$taskPrincipal = New-ScheduledTaskPrincipal -UserId "SYSTEM" -LogonType ServiceAccount -RunLevel Highest
$taskSettings = New-ScheduledTaskSettingsSet -StartWhenAvailable -ExecutionTimeLimit (New-TimeSpan -Minutes 30) -MultipleInstances IgnoreNew
# Spread fleet uploads across the early-morning window while keeping each device's slot stable.
$machineGuid = (Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Cryptography" -Name "MachineGuid").MachineGuid
$guidBytes = [Text.Encoding]::UTF8.GetBytes([string]$machineGuid)
$sha256 = [Security.Cryptography.SHA256]::Create()
try {
$slotHash = $sha256.ComputeHash($guidBytes)
}
finally {
$sha256.Dispose()
}
$dailySlotMinutes = [BitConverter]::ToUInt32($slotHash, 0) % 180
$dailyRunAt = (Get-Date -Hour 4 -Minute 0 -Second 0).AddMinutes($dailySlotMinutes)
$dailyAction = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-NoProfile -ExecutionPolicy Bypass -File `"$scheduledScript`" -Kind daily" -WorkingDirectory $scriptRoot
$dailyTrigger = New-ScheduledTaskTrigger -Daily -At $dailyRunAt
Register-ScheduledTask -TaskName "OCSentinel Daily Scan" -Action $dailyAction -Trigger $dailyTrigger -Principal $taskPrincipal -Settings $taskSettings -Description "OfficeCom Sentinel daily signed scan and upload." -Force | Out-Null
$burstAction = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-NoProfile -ExecutionPolicy Bypass -File `"$scheduledScript`" -Kind burst" -WorkingDirectory $scriptRoot
$burstTrigger = New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(2) -RepetitionInterval (New-TimeSpan -Minutes 5) -RepetitionDuration (New-TimeSpan -Days 3650)
Register-ScheduledTask -TaskName "OCSentinel Burst Check" -Action $burstAction -Trigger $burstTrigger -Principal $taskPrincipal -Settings $taskSettings -Description "OfficeCom Sentinel burst check; scans only when Ninja field ocsentinelburst is enabled." -Force | Out-Null
Write-Host "Installation complete." Write-Host "Installation complete."
Write-Host "Main path: $installRoot" Write-Host "Main path: $installRoot"
Write-Host "Runner: $(Join-Path $scriptRoot 'run-ocsentinel.ps1')" Write-Host "Runner: $(Join-Path $scriptRoot 'run-ocsentinel.ps1')"
Write-Host "Monitor: $(Join-Path $scriptRoot 'run-ocsentinel-monitor.ps1')" Write-Host "Monitor: $(Join-Path $scriptRoot 'run-ocsentinel-monitor.ps1')"
Write-Host "Updater: $(Join-Path $scriptRoot 'update-ocsentinel.ps1')" Write-Host "Updater: $(Join-Path $scriptRoot 'update-ocsentinel.ps1')"
Write-Host "Schedule: Daily scan at $($dailyRunAt.ToString('HH:mm')) (deterministic 04:00-06:59 slot); burst check every 5 minutes."

View File

@@ -3,8 +3,13 @@ param(
[int]$TopCount = 10, [int]$TopCount = 10,
[string]$OutputPath = "..\reports\ocsentinel-summary.json", [string]$OutputPath = "..\reports\ocsentinel-summary.json",
[string]$ConfigPath = "..\config\ocsentinel-settings.json", [string]$ConfigPath = "..\config\ocsentinel-settings.json",
[string]$ClientConfigPath = "..\config\ocsentinel-client.json",
[string]$SecretPath = "",
[ValidateSet("disabled", "auto", "required")]
[string]$UploadMode = "auto",
[string]$VulnerabilityCsvPath = "", [string]$VulnerabilityCsvPath = "",
[string]$MirrorRoot = "", [string]$MirrorRoot = "",
[switch]$SuppressTriggerExit,
[ValidateSet("status", "attack-only", "cve-critical", "attack-plus-cve")] [ValidateSet("status", "attack-only", "cve-critical", "attack-plus-cve")]
[string]$Mode = "status" [string]$Mode = "status"
) )
@@ -42,8 +47,13 @@ function Initialize-NinjaFieldWriter {
return return
} }
if (Get-Command -Name "Set-NinjaProperty" -ErrorAction SilentlyContinue) {
$script:NinjaFieldBackend = "powershell-modern"
return
}
if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) { if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) {
$script:NinjaFieldBackend = "powershell" $script:NinjaFieldBackend = "powershell-legacy"
return return
} }
@@ -60,14 +70,20 @@ function Set-NinjaCustomFieldValue {
[Parameter(Mandatory)] [Parameter(Mandatory)]
[string]$Name, [string]$Name,
[AllowEmptyString()] [AllowEmptyString()]
[string]$Value [object]$Value,
[Parameter(Mandatory)]
[string]$Type
) )
Initialize-NinjaFieldWriter Initialize-NinjaFieldWriter
switch ($script:NinjaFieldBackend) { switch ($script:NinjaFieldBackend) {
"powershell" { "powershell-modern" {
Ninja-Property-Set $Name $Value | Out-Null Set-NinjaProperty -Name $Name -Value $Value -Type $Type -Force | Out-Null
return $true
}
"powershell-legacy" {
Ninja-Property-Set -Name $Name -Value $Value | Out-Null
return $true return $true
} }
"cli" { "cli" {
@@ -108,28 +124,43 @@ function Publish-NinjaCustomFields {
} }
} }
$fieldValues = [ordered]@{ $uploadStatus = [string]$Report.Runtime.UploadStatus
"ocsentinelstatus" = [string]$Report.AlertState if ([string]::IsNullOrWhiteSpace($uploadStatus)) { $uploadStatus = "unknown" }
"ocsentinelreason" = $Reason $queuedReports = [int]$Report.Runtime.QueuedReportCount
"ocsentinelbasestatus" = [string]$Report.BaseAlertState $lastUploadUtc = ""
"ocsentinelevents" = [string]([int]$Report.TotalEvents) if ($Report.Runtime.LastSuccessfulUploadUtc) {
"ocsentineluniqueips" = [string]([int]$Report.UniqueIpCount) try { $lastUploadUtc = ([DateTimeOffset]$Report.Runtime.LastSuccessfulUploadUtc).ToUniversalTime().ToString("o") } catch { $lastUploadUtc = [string]$Report.Runtime.LastSuccessfulUploadUtc }
"ocsentinelcvecritical" = [string]([int]$Report.VulnerabilityCorrelation.CriticalCount)
"ocsentinelcvetotal" = [string]([int]$Report.VulnerabilityCorrelation.TotalCount)
"ocsentinelmode" = $Mode
"ocsentineltriggered" = $Triggered.ToString().ToLowerInvariant()
"ocsentinellastscanutc" = $generatedAtUtc
} }
$lastUploadError = [string]$Report.Runtime.LastUploadError
if ($lastUploadError.Length -gt 900) { $lastUploadError = $lastUploadError.Substring(0, 900) }
$fieldValues = @(
[pscustomobject]@{ Name = "ocsentinelstatus"; Type = "Text"; Value = [string]$Report.AlertState }
[pscustomobject]@{ Name = "ocsentinelreason"; Type = "Text"; Value = $Reason }
[pscustomobject]@{ Name = "ocsentinelbasestatus"; Type = "Text"; Value = [string]$Report.BaseAlertState }
[pscustomobject]@{ Name = "ocsentinelevents"; Type = "Integer"; Value = [int]$Report.TotalEvents }
[pscustomobject]@{ Name = "ocsentineluniqueips"; Type = "Integer"; Value = [int]$Report.UniqueIpCount }
[pscustomobject]@{ Name = "ocsentinelcvecritical"; Type = "Integer"; Value = [int]$Report.VulnerabilityCorrelation.CriticalCount }
[pscustomobject]@{ Name = "ocsentinelcvetotal"; Type = "Integer"; Value = [int]$Report.VulnerabilityCorrelation.TotalCount }
[pscustomobject]@{ Name = "ocsentinelmode"; Type = "Text"; Value = $Mode }
[pscustomobject]@{ Name = "ocsentineltriggered"; Type = "Checkbox"; Value = $Triggered }
[pscustomobject]@{ Name = "ocsentinellastscanutc"; Type = "DateTime"; Value = $generatedAtUtc }
[pscustomobject]@{ Name = "ocsentineluploadstatus"; Type = "Text"; Value = $uploadStatus }
[pscustomobject]@{ Name = "ocsentinelqueuedreports"; Type = "Integer"; Value = $queuedReports }
[pscustomobject]@{ Name = "ocsentinellastuploadutc"; Type = "DateTime"; Value = $lastUploadUtc }
[pscustomobject]@{ Name = "ocsentinellasterror"; Type = "Text"; Value = $lastUploadError }
[pscustomobject]@{ Name = "ocsentinelclientversion"; Type = "Text"; Value = [string]$Report.ClientVersion }
)
$updated = 0 $updated = 0
foreach ($entry in $fieldValues.GetEnumerator()) { foreach ($entry in $fieldValues) {
try { try {
if (Set-NinjaCustomFieldValue -Name $entry.Key -Value $entry.Value) { if (Set-NinjaCustomFieldValue -Name $entry.Name -Value $entry.Value -Type $entry.Type) {
$updated++ $updated++
} }
} }
catch { catch {
Write-Warning "Failed to set Ninja custom field '$($entry.Key)': $($_.Exception.Message)" Write-Warning "Failed to set Ninja custom field '$($entry.Name)': $($_.Exception.Message)"
} }
} }
@@ -142,9 +173,15 @@ $runnerArgs = @(
"-LookbackDays", $LookbackDays, "-LookbackDays", $LookbackDays,
"-TopCount", $TopCount, "-TopCount", $TopCount,
"-OutputPath", $OutputPath, "-OutputPath", $OutputPath,
"-ConfigPath", $ConfigPath "-ConfigPath", $ConfigPath,
"-ClientConfigPath", $ClientConfigPath,
"-UploadMode", $UploadMode
) )
if (-not [string]::IsNullOrWhiteSpace($SecretPath)) {
$runnerArgs += @("-SecretPath", $SecretPath)
}
if (-not [string]::IsNullOrWhiteSpace($VulnerabilityCsvPath)) { if (-not [string]::IsNullOrWhiteSpace($VulnerabilityCsvPath)) {
$runnerArgs += @("-VulnerabilityCsvPath", $VulnerabilityCsvPath) $runnerArgs += @("-VulnerabilityCsvPath", $VulnerabilityCsvPath)
} }
@@ -168,6 +205,8 @@ $events = [int]$report.TotalEvents
$uniqueIps = [int]$report.UniqueIpCount $uniqueIps = [int]$report.UniqueIpCount
$criticalCves = [int]$report.VulnerabilityCorrelation.CriticalCount $criticalCves = [int]$report.VulnerabilityCorrelation.CriticalCount
$totalCves = [int]$report.VulnerabilityCorrelation.TotalCount $totalCves = [int]$report.VulnerabilityCorrelation.TotalCount
$uploadStatus = [string]$report.Runtime.UploadStatus
$queuedReports = [int]$report.Runtime.QueuedReportCount
$monitorTriggered = $false $monitorTriggered = $false
$monitorReason = "" $monitorReason = ""
@@ -203,11 +242,13 @@ Write-Host "Events: $events"
Write-Host "Unique IPs: $uniqueIps" Write-Host "Unique IPs: $uniqueIps"
Write-Host "Critical/High CVEs: $criticalCves" Write-Host "Critical/High CVEs: $criticalCves"
Write-Host "Total CVEs: $totalCves" Write-Host "Total CVEs: $totalCves"
Write-Host "Upload status: $uploadStatus"
Write-Host "Queued reports: $queuedReports"
Write-Host "Report: $outputFullPath" Write-Host "Report: $outputFullPath"
Write-Host "Runner exit code: $runnerExitCode" Write-Host "Runner exit code: $runnerExitCode"
if ($monitorTriggered) { if ($monitorTriggered -and -not $SuppressTriggerExit) {
exit 1 exit 1
} }
exit 0 exit $runnerExitCode

View File

@@ -0,0 +1,116 @@
[CmdletBinding()]
param(
[ValidateSet("daily", "burst")]
[string]$Kind = "daily",
[ValidateRange(15, 480)]
[int]$BurstDurationMinutes = 120
)
$ErrorActionPreference = "Stop"
$scriptDir = Split-Path -Parent $MyInvocation.MyCommand.Path
$monitorScript = Join-Path $scriptDir "run-ocsentinel-monitor.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
$mutexName = "Global\OfficeComSentinelScan"
function Get-NinjaBurstEnabled {
if (Get-Command -Name "Get-NinjaProperty" -ErrorAction SilentlyContinue) {
return [bool](Get-NinjaProperty -Name "ocsentinelburst" -Type "Checkbox")
}
if (Get-Command -Name "Ninja-Property-Get" -ErrorAction SilentlyContinue) {
$value = Ninja-Property-Get -Name "ocsentinelburst"
return [string]$value -match "^(1|true|yes)$"
}
Write-Warning "Ninja custom-field reader is unavailable; burst scan skipped."
return $false
}
function Get-NinjaValue {
param([Parameter(Mandatory)][string]$Name, [Parameter(Mandatory)][string]$Type)
try {
if (Get-Command -Name "Get-NinjaProperty" -ErrorAction SilentlyContinue) {
return Get-NinjaProperty -Name $Name -Type $Type
}
if (Get-Command -Name "Ninja-Property-Get" -ErrorAction SilentlyContinue) {
return Ninja-Property-Get -Name $Name
}
}
catch {
Write-Warning "Could not read Ninja field '$Name': $($_.Exception.Message)"
}
return $null
}
function Set-NinjaValue {
param([Parameter(Mandatory)][string]$Name, [AllowEmptyString()][string]$Value, [Parameter(Mandatory)][string]$Type)
try {
if (Get-Command -Name "Set-NinjaProperty" -ErrorAction SilentlyContinue) {
Set-NinjaProperty -Name $Name -Value $Value -Type $Type -Force | Out-Null
return $true
}
if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) {
Ninja-Property-Set -Name $Name -Value $Value | Out-Null
return $true
}
}
catch {
Write-Warning "Could not update Ninja field '$Name': $($_.Exception.Message)"
}
return $false
}
if ($Kind -eq "burst") {
if (-not (Get-NinjaBurstEnabled)) {
Set-NinjaValue -Name "ocsentinelburststatus" -Value "idle" -Type "Text" | Out-Null
Write-Host "OfficeCom Sentinel burst check: disabled."
exit 0
}
$now = [DateTimeOffset]::UtcNow
$untilValue = Get-NinjaValue -Name "ocsentinelburstuntilutc" -Type "DateTime"
$until = $null
if (-not [string]::IsNullOrWhiteSpace([string]$untilValue)) {
try { $until = [DateTimeOffset]$untilValue } catch { Write-Warning "Burst end time is invalid and will be restarted." }
}
if ($null -eq $until) {
$until = $now.AddMinutes($BurstDurationMinutes)
Set-NinjaValue -Name "ocsentinelburstuntilutc" -Value $until.ToString("o") -Type "DateTime" | Out-Null
Write-Host "OfficeCom Sentinel burst window started until $($until.ToString('u'))."
}
elseif ($until -le $now) {
Set-NinjaValue -Name "ocsentinelburst" -Value "false" -Type "Checkbox" | Out-Null
Set-NinjaValue -Name "ocsentinelburststatus" -Value "completed" -Type "Text" | Out-Null
Write-Host "OfficeCom Sentinel burst window completed and was disabled."
exit 0
}
Set-NinjaValue -Name "ocsentinelburststatus" -Value "active until $($until.ToUniversalTime().ToString('o'))" -Type "Text" | Out-Null
}
$createdNew = $false
$mutex = [Threading.Mutex]::new($false, $mutexName, [ref]$createdNew)
try {
if (-not $mutex.WaitOne(0)) {
Write-Host "OfficeCom Sentinel scan skipped: another scan is already running."
exit 0
}
Write-Host "OfficeCom Sentinel scheduled $Kind scan started."
$monitorArgs = @("-NoProfile", "-ExecutionPolicy", "Bypass", "-File", $monitorScript, "-Mode", "status", "-UploadMode", "required", "-SecretPath", $secretPath, "-SuppressTriggerExit")
if ($Kind -eq "burst") {
$monitorArgs += @("-LookbackDays", "1", "-TopCount", "25")
}
& powershell.exe @monitorArgs
exit $LASTEXITCODE
}
finally {
if ($null -ne $mutex) {
try { $mutex.ReleaseMutex() } catch { }
$mutex.Dispose()
}
}

View File

@@ -39,6 +39,40 @@ function Resolve-PathLike {
return [System.IO.Path]::GetFullPath((Join-Path $BasePath $PathValue)) return [System.IO.Path]::GetFullPath((Join-Path $BasePath $PathValue))
} }
function Restore-NinjaContextFromClientConfiguration {
param([Parameter(Mandatory)][string]$Path)
if (-not (Test-Path -LiteralPath $Path)) {
return
}
try {
$clientConfiguration = Get-Content -LiteralPath $Path -Raw | ConvertFrom-Json
$mappings = @(
@{ EnvironmentName = "NINJA_ORGANIZATION_ID"; PropertyName = "ninjaOrganizationId" },
@{ EnvironmentName = "NINJA_ORGANIZATION_NAME"; PropertyName = "ninjaOrganizationName" },
@{ EnvironmentName = "NINJA_AGENT_MACHINE_ID"; PropertyName = "ninjaMachineId" },
@{ EnvironmentName = "NINJA_AGENT_NODE_ID"; PropertyName = "ninjaNodeId" },
@{ EnvironmentName = "NINJA_LOCATION_ID"; PropertyName = "ninjaLocationId" },
@{ EnvironmentName = "NINJA_LOCATION_NAME"; PropertyName = "ninjaLocationName" }
)
foreach ($mapping in $mappings) {
if (-not [string]::IsNullOrWhiteSpace([Environment]::GetEnvironmentVariable($mapping.EnvironmentName, "Process"))) {
continue
}
$value = [string]$clientConfiguration.($mapping.PropertyName)
if (-not [string]::IsNullOrWhiteSpace($value)) {
[Environment]::SetEnvironmentVariable($mapping.EnvironmentName, $value, "Process")
}
}
}
catch {
Write-Warning "Could not restore stored NinjaOne context: $($_.Exception.Message)"
}
}
if (-not (Test-Path $appExe)) { if (-not (Test-Path $appExe)) {
throw "Application executable not found: $appExe" throw "Application executable not found: $appExe"
} }
@@ -54,6 +88,8 @@ else {
$secretFullPath = if ([string]::IsNullOrWhiteSpace($SecretPath)) { "" } else { Resolve-PathLike -PathValue $SecretPath -BasePath $scriptDir } $secretFullPath = if ([string]::IsNullOrWhiteSpace($SecretPath)) { "" } else { Resolve-PathLike -PathValue $SecretPath -BasePath $scriptDir }
$canUpload = (Test-Path $clientConfigFullPath) -and (-not [string]::IsNullOrWhiteSpace($secretFullPath)) -and (Test-Path $secretFullPath) $canUpload = (Test-Path $clientConfigFullPath) -and (-not [string]::IsNullOrWhiteSpace($secretFullPath)) -and (Test-Path $secretFullPath)
Restore-NinjaContextFromClientConfiguration -Path $clientConfigFullPath
if ($UploadMode -eq "required" -and -not $canUpload) { if ($UploadMode -eq "required" -and -not $canUpload) {
throw "UploadMode 'required' was set, but client config or protected secret is missing." throw "UploadMode 'required' was set, but client config or protected secret is missing."
} }

View File

@@ -5,6 +5,12 @@ $ErrorActionPreference = "Stop"
$installRoot = Join-Path ${env:ProgramFiles} "OCSentinel" $installRoot = Join-Path ${env:ProgramFiles} "OCSentinel"
$uninstallKey = "HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\OCSentinel" $uninstallKey = "HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\OCSentinel"
foreach ($taskName in @("OCSentinel Daily Scan", "OCSentinel Burst Check")) {
if (Get-ScheduledTask -TaskName $taskName -ErrorAction SilentlyContinue) {
Unregister-ScheduledTask -TaskName $taskName -Confirm:$false
}
}
if (Test-Path $uninstallKey) { if (Test-Path $uninstallKey) {
Remove-Item -Path $uninstallKey -Force -Recurse Remove-Item -Path $uninstallKey -Force -Recurse
} }

View File

@@ -7,6 +7,72 @@ param(
$ErrorActionPreference = "Stop" $ErrorActionPreference = "Stop"
function Initialize-OCSentinelTls {
$protocols = [Net.SecurityProtocolType]::Tls12
if ([Enum]::GetNames([Net.SecurityProtocolType]) -contains "Tls13") {
$protocols = $protocols -bor [Net.SecurityProtocolType]::Tls13
}
[Net.ServicePointManager]::SecurityProtocol = $protocols
[Net.ServicePointManager]::Expect100Continue = $false
}
function Get-OCSentinelManifest {
param([Parameter(Mandatory)][string]$Uri)
$parameters = @{ Method = "Get"; Uri = $Uri; TimeoutSec = 60 }
if ((Get-Command Invoke-RestMethod).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
return Invoke-RestMethod @parameters
}
catch {
if ($attempt -eq 3) {
throw "Could not retrieve the OCSentinel release manifest after 3 attempts. Verify that the device can reach gitea.officecom.cloud with TLS 1.2 or newer. Last error: $($_.Exception.Message)"
}
Start-Sleep -Seconds (3 * $attempt)
}
}
}
function Get-OCSentinelArtifact {
param(
[Parameter(Mandatory)][string]$Uri,
[Parameter(Mandatory)][string]$DestinationPath
)
$parameters = @{ Uri = $Uri; OutFile = $DestinationPath; TimeoutSec = 300 }
if ((Get-Command Invoke-WebRequest).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
Remove-Item -LiteralPath $DestinationPath -Force -ErrorAction SilentlyContinue
Invoke-WebRequest @parameters
if (-not (Test-Path -LiteralPath $DestinationPath) -or (Get-Item -LiteralPath $DestinationPath).Length -eq 0) {
throw "The downloaded artifact is empty."
}
return
}
catch {
if ($attempt -eq 3) {
throw "Could not download the OCSentinel package after 3 attempts. Last error: $($_.Exception.Message)"
}
Write-Warning "Package download attempt $attempt failed. Retrying."
Start-Sleep -Seconds (5 * $attempt)
}
}
}
Initialize-OCSentinelTls
$installRoot = Join-Path ${env:ProgramFiles} "OCSentinel" $installRoot = Join-Path ${env:ProgramFiles} "OCSentinel"
$appExe = Join-Path $installRoot "app\OCSentinelCli.exe" $appExe = Join-Path $installRoot "app\OCSentinelCli.exe"
$installScript = Join-Path $installRoot "scripts\install-ocsentinel.ps1" $installScript = Join-Path $installRoot "scripts\install-ocsentinel.ps1"
@@ -66,7 +132,7 @@ if ([string]::IsNullOrWhiteSpace($ManifestUrl)) {
$resolvedManifestUrl = Resolve-ManifestUrl -ManifestUrl $ManifestUrl -Channel $Channel $resolvedManifestUrl = Resolve-ManifestUrl -ManifestUrl $ManifestUrl -Channel $Channel
Write-Host "Checking update manifest: $resolvedManifestUrl" Write-Host "Checking update manifest: $resolvedManifestUrl"
$manifest = Invoke-RestMethod -Method Get -Uri $resolvedManifestUrl -TimeoutSec 60 $manifest = Get-OCSentinelManifest -Uri $resolvedManifestUrl
if (-not $manifest.version -or -not $manifest.artifactUrl -or -not $manifest.sha256) { if (-not $manifest.version -or -not $manifest.artifactUrl -or -not $manifest.sha256) {
throw "Update manifest is missing required fields: version, artifactUrl, sha256." throw "Update manifest is missing required fields: version, artifactUrl, sha256."
} }
@@ -89,7 +155,7 @@ $extractRoot = Join-Path $downloadRoot "payload"
New-Item -ItemType Directory -Force -Path $downloadRoot, $extractRoot | Out-Null New-Item -ItemType Directory -Force -Path $downloadRoot, $extractRoot | Out-Null
Write-Host "Downloading artifact: $($manifest.artifactUrl)" Write-Host "Downloading artifact: $($manifest.artifactUrl)"
Invoke-WebRequest -Uri ([string]$manifest.artifactUrl) -OutFile $zipPath -TimeoutSec 300 Get-OCSentinelArtifact -Uri ([string]$manifest.artifactUrl) -DestinationPath $zipPath
$actualHash = Get-Sha256Hex -Path $zipPath $actualHash = Get-Sha256Hex -Path $zipPath
$expectedHash = ([string]$manifest.sha256).ToLowerInvariant() $expectedHash = ([string]$manifest.sha256).ToLowerInvariant()

View File

@@ -0,0 +1,8 @@
{
"channel": "stable",
"version": "1.3.6",
"publishedAtUtc": "2026-07-27T08:45:53.0419623Z",
"artifactUrl": "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.3.6/OCSentinelClient-win-x64.zip",
"sha256": "48e9faa242a59797bed9732ae5b8914ab44843b9c949260a17bc15b47659a3d5",
"minUpdaterVersion": "1.0.0"
}

View File

@@ -0,0 +1,255 @@
[CmdletBinding()]
param(
[string]$ManifestUrl = "https://gitea.officecom.cloud/officecom/oc-sentinel/raw/main/release/stable/version.json",
[string]$WebhookUrl = "",
[string]$SecretValue = "",
[switch]$RunInitialStatusScan
)
$ErrorActionPreference = "Stop"
$ProgressPreference = "SilentlyContinue"
function Initialize-OCSentinelTls {
$protocols = [Net.SecurityProtocolType]::Tls12
if ([Enum]::GetNames([Net.SecurityProtocolType]) -contains "Tls13") {
$protocols = $protocols -bor [Net.SecurityProtocolType]::Tls13
}
[Net.ServicePointManager]::SecurityProtocol = $protocols
[Net.ServicePointManager]::Expect100Continue = $false
}
function Get-OCSentinelManifest {
param([Parameter(Mandatory)][string]$Uri)
$parameters = @{ Method = "Get"; Uri = $Uri; TimeoutSec = 60 }
if ((Get-Command Invoke-RestMethod).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
return Invoke-RestMethod @parameters
}
catch {
if ($attempt -eq 3) {
throw "Could not retrieve the OCSentinel release manifest after 3 attempts. Verify that the device can reach gitea.officecom.cloud with TLS 1.2 or newer. Last error: $($_.Exception.Message)"
}
Start-Sleep -Seconds (3 * $attempt)
}
}
}
function Invoke-OCSentinelUpdater {
param(
[Parameter(Mandatory)][string]$UpdaterPath,
[Parameter(Mandatory)][string]$ManifestUri
)
# Existing clients can still contain an older updater without TLS setup.
# Start it in a prepared child process so it can download the current package.
$escapedUpdaterPath = $UpdaterPath.Replace("'", "''")
$escapedManifestUri = $ManifestUri.Replace("'", "''")
$command = @"
`$protocols = [Net.SecurityProtocolType]::Tls12
if ([Enum]::GetNames([Net.SecurityProtocolType]) -contains 'Tls13') {
`$protocols = `$protocols -bor [Net.SecurityProtocolType]::Tls13
}
[Net.ServicePointManager]::SecurityProtocol = `$protocols
[Net.ServicePointManager]::Expect100Continue = `$false
& '$escapedUpdaterPath' -ManifestUrl '$escapedManifestUri'
exit `$LASTEXITCODE
"@
for ($attempt = 1; $attempt -le 3; $attempt++) {
& powershell.exe -NoProfile -ExecutionPolicy Bypass -Command $command | ForEach-Object { Write-Host $_ }
$exitCode = $LASTEXITCODE
if ($exitCode -eq 0) {
return
}
if ($attempt -lt 3) {
Write-Warning "OCSentinel update attempt $attempt failed. Retrying."
Start-Sleep -Seconds (5 * $attempt)
}
}
throw "OCSentinel updater exited with code $exitCode after 3 attempts."
}
function Get-OCSentinelArtifact {
param(
[Parameter(Mandatory)][string]$Uri,
[Parameter(Mandatory)][string]$DestinationPath
)
$parameters = @{ Uri = $Uri; OutFile = $DestinationPath; TimeoutSec = 300 }
if ((Get-Command Invoke-WebRequest).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
Remove-Item -LiteralPath $DestinationPath -Force -ErrorAction SilentlyContinue
Invoke-WebRequest @parameters
if (-not (Test-Path -LiteralPath $DestinationPath) -or (Get-Item -LiteralPath $DestinationPath).Length -eq 0) {
throw "The downloaded artifact is empty."
}
return
}
catch {
if ($attempt -eq 3) {
throw "Could not download the OCSentinel package after 3 attempts. Last error: $($_.Exception.Message)"
}
Write-Warning "Package download attempt $attempt failed. Retrying."
Start-Sleep -Seconds (5 * $attempt)
}
}
}
Initialize-OCSentinelTls
$installRoot = Join-Path $env:ProgramFiles "OCSentinel"
$updaterPath = Join-Path $installRoot "scripts\update-ocsentinel.ps1"
$monitorPath = Join-Path $installRoot "scripts\run-ocsentinel-monitor.ps1"
$appPath = Join-Path $installRoot "app\OCSentinelCli.exe"
$clientConfigPath = Join-Path $installRoot "config\ocsentinel-client.json"
$secretScriptPath = Join-Path $installRoot "scripts\protect-ocsentinel-secret.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
# NinjaOne script variables are exposed as process environment variables.
if ([string]::IsNullOrWhiteSpace($WebhookUrl)) {
$WebhookUrl = $env:WebhookUrl
}
if ([string]::IsNullOrWhiteSpace($SecretValue)) {
$SecretValue = $env:SecretValue
}
$runInitialScan = $RunInitialStatusScan.IsPresent
if (-not $runInitialScan -and -not [string]::IsNullOrWhiteSpace($env:RunInitialStatusScan)) {
$runInitialScan = $env:RunInitialStatusScan -match '^(1|true|yes|on)$'
}
function Assert-ArtifactSignature {
param([Parameter(Mandatory)][string]$ExecutablePath)
$signature = Get-AuthenticodeSignature -FilePath $ExecutablePath
if ($signature.Status -notin @("Valid", "NotSigned")) {
throw "Executable signature validation failed with status: $($signature.Status)"
}
if ($signature.Status -eq "NotSigned") {
Write-Warning "The package hash was verified, but OCSentinelCli.exe is not code-signed yet."
}
}
if (Test-Path -LiteralPath $updaterPath) {
Write-Host "Existing OCSentinel installation found. Checking for updates."
Invoke-OCSentinelUpdater -UpdaterPath $updaterPath -ManifestUri $ManifestUrl
}
else {
Write-Host "Reading OCSentinel release manifest: $ManifestUrl"
$manifest = Get-OCSentinelManifest -Uri $ManifestUrl
if ([string]::IsNullOrWhiteSpace($manifest.version) -or [string]::IsNullOrWhiteSpace($manifest.artifactUrl) -or [string]::IsNullOrWhiteSpace($manifest.sha256)) {
throw "Release manifest is missing version, artifactUrl, or sha256."
}
$downloadRoot = Join-Path $env:ProgramData ("OCSentinel\\bootstrap\\" + [Guid]::NewGuid().ToString("N"))
$zipPath = Join-Path $downloadRoot "OCSentinelClient.zip"
$extractRoot = Join-Path $downloadRoot "payload"
try {
New-Item -ItemType Directory -Force -Path $extractRoot | Out-Null
Write-Host "Downloading OCSentinel $($manifest.version)"
Get-OCSentinelArtifact -Uri ([string]$manifest.artifactUrl) -DestinationPath $zipPath
$actualHash = (Get-FileHash -LiteralPath $zipPath -Algorithm SHA256).Hash.ToLowerInvariant()
$expectedHash = ([string]$manifest.sha256).ToLowerInvariant()
if ($actualHash -ne $expectedHash) {
throw "SHA-256 mismatch for the downloaded OCSentinel package."
}
Write-Host "Package hash verified. Extracting release payload."
Expand-Archive -LiteralPath $zipPath -DestinationPath $extractRoot -Force
$payloadApp = Get-ChildItem -Path $extractRoot -Recurse -Filter "OCSentinelCli.exe" | Select-Object -First 1
$installer = Get-ChildItem -Path $extractRoot -Recurse -Filter "install-ocsentinel.ps1" | Select-Object -First 1
if ($null -eq $payloadApp -or $null -eq $installer) {
throw "The downloaded package is incomplete."
}
Assert-ArtifactSignature -ExecutablePath $payloadApp.FullName
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $installer.FullName
if ($LASTEXITCODE -ne 0) {
throw "OCSentinel installer exited with code $LASTEXITCODE"
}
}
finally {
if (Test-Path -LiteralPath $downloadRoot) {
Remove-Item -LiteralPath $downloadRoot -Recurse -Force
}
}
}
if (-not (Test-Path -LiteralPath $appPath)) {
throw "OCSentinel installation completed, but the client executable was not found."
}
if (-not [string]::IsNullOrWhiteSpace($WebhookUrl)) {
if (-not (Test-Path -LiteralPath $clientConfigPath)) {
throw "OCSentinel client configuration was not found: $clientConfigPath"
}
$clientConfig = Get-Content -LiteralPath $clientConfigPath -Raw | ConvertFrom-Json
$clientConfig.n8nWebhookUrl = $WebhookUrl
$clientConfig.environment = "production"
$ninjaContext = @(
@{ EnvironmentName = "NINJA_ORGANIZATION_ID"; PropertyName = "ninjaOrganizationId" },
@{ EnvironmentName = "NINJA_ORGANIZATION_NAME"; PropertyName = "ninjaOrganizationName" },
@{ EnvironmentName = "NINJA_AGENT_MACHINE_ID"; PropertyName = "ninjaMachineId" },
@{ EnvironmentName = "NINJA_AGENT_NODE_ID"; PropertyName = "ninjaNodeId" },
@{ EnvironmentName = "NINJA_LOCATION_ID"; PropertyName = "ninjaLocationId" },
@{ EnvironmentName = "NINJA_LOCATION_NAME"; PropertyName = "ninjaLocationName" }
)
foreach ($entry in $ninjaContext) {
$value = [Environment]::GetEnvironmentVariable($entry.EnvironmentName, "Process")
if (-not [string]::IsNullOrWhiteSpace($value)) {
$clientConfig | Add-Member -NotePropertyName $entry.PropertyName -NotePropertyValue $value.Trim() -Force
}
}
$clientConfig | ConvertTo-Json -Depth 10 | Set-Content -LiteralPath $clientConfigPath -Encoding UTF8
Write-Host "Configured OCSentinel upload endpoint and NinjaOne context."
}
if (-not [string]::IsNullOrWhiteSpace($SecretValue)) {
if (-not (Test-Path -LiteralPath $secretScriptPath)) {
throw "OCSentinel secret bootstrap script was not found: $secretScriptPath"
}
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $secretScriptPath -SecretValue $SecretValue
if ($LASTEXITCODE -ne 0) {
throw "OCSentinel secret bootstrap failed with code $LASTEXITCODE"
}
}
if ($runInitialScan) {
if (-not (Test-Path -LiteralPath $monitorPath)) {
throw "OCSentinel was installed, but the monitor script is missing."
}
Write-Host "Running initial OCSentinel status scan."
$scanArguments = @("-NoProfile", "-ExecutionPolicy", "Bypass", "-File", $monitorPath, "-Mode", "status", "-OutputPath", "..\\reports\\ocsentinel-summary.json")
if ((Test-Path -LiteralPath $clientConfigPath) -and (Test-Path -LiteralPath $secretPath)) {
$scanArguments += @("-ClientConfigPath", $clientConfigPath, "-SecretPath", $secretPath, "-UploadMode", "required")
}
& powershell.exe @scanArguments
if ($LASTEXITCODE -ne 0) {
throw "Initial OCSentinel status scan exited with code $LASTEXITCODE"
}
}
Write-Host "OCSentinel bootstrap completed successfully."

View File

@@ -0,0 +1,62 @@
[CmdletBinding()]
param(
[string]$WebhookUrl = "",
[string]$SecretValue = ""
)
$ErrorActionPreference = "Stop"
function Get-NinjaValue {
param([Parameter(Mandatory)][string]$Name)
$value = [Environment]::GetEnvironmentVariable($Name, "Process")
if ($null -eq $value) {
return ""
}
return $value.Trim()
}
if ([string]::IsNullOrWhiteSpace($WebhookUrl)) {
$WebhookUrl = Get-NinjaValue -Name "webhookurl"
}
if ([string]::IsNullOrWhiteSpace($SecretValue)) {
$SecretValue = Get-NinjaValue -Name "secretvalue"
}
if ([string]::IsNullOrWhiteSpace($WebhookUrl) -or [string]::IsNullOrWhiteSpace($SecretValue)) {
throw "WebhookUrl and SecretValue must be supplied as NinjaOne script variables."
}
$installRoot = Join-Path $env:ProgramFiles "OCSentinel"
$configPath = Join-Path $installRoot "config\ocsentinel-client.json"
$secretScript = Join-Path $installRoot "scripts\protect-ocsentinel-secret.ps1"
$monitorScript = Join-Path $installRoot "scripts\run-ocsentinel-monitor.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
foreach ($path in @($configPath, $secretScript, $monitorScript)) {
if (-not (Test-Path -LiteralPath $path)) {
throw "OCSentinel installation is incomplete. Missing: $path"
}
}
$config = Get-Content -LiteralPath $configPath -Raw | ConvertFrom-Json
$config.n8nWebhookUrl = $WebhookUrl
$config.environment = "production"
$config | ConvertTo-Json -Depth 10 | Set-Content -LiteralPath $configPath -Encoding UTF8
Write-Host "OCSentinel upload endpoint configured."
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $secretScript -SecretValue $SecretValue
if ($LASTEXITCODE -ne 0) {
throw "Writing the protected upload secret failed with code $LASTEXITCODE"
}
Write-Host "Running signed OCSentinel test scan and upload."
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $monitorScript `
-Mode status `
-ClientConfigPath $configPath `
-SecretPath $secretPath `
-UploadMode required
exit $LASTEXITCODE

View File

@@ -0,0 +1,106 @@
[CmdletBinding()]
param(
[string]$ManifestUrl = "https://gitea.officecom.cloud/officecom/oc-sentinel/raw/main/release/stable/version.json",
[string]$WebhookUrl = "",
[string]$SecretValue = ""
)
$ErrorActionPreference = "Stop"
$ProgressPreference = "SilentlyContinue"
function Initialize-OCSentinelTls {
$protocols = [Net.SecurityProtocolType]::Tls12
if ([Enum]::GetNames([Net.SecurityProtocolType]) -contains "Tls13") {
$protocols = $protocols -bor [Net.SecurityProtocolType]::Tls13
}
[Net.ServicePointManager]::SecurityProtocol = $protocols
[Net.ServicePointManager]::Expect100Continue = $false
}
function Get-OCSentinelManifest {
param([Parameter(Mandatory)][string]$Uri)
$parameters = @{ Method = "Get"; Uri = $Uri; TimeoutSec = 60 }
if ((Get-Command Invoke-RestMethod).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
return Invoke-RestMethod @parameters
}
catch {
if ($attempt -eq 3) {
throw "Could not retrieve the OCSentinel release manifest after 3 attempts. Verify that the device can reach gitea.officecom.cloud with TLS 1.2 or newer. Last error: $($_.Exception.Message)"
}
Start-Sleep -Seconds (3 * $attempt)
}
}
}
Initialize-OCSentinelTls
function Get-NinjaValue {
param([Parameter(Mandatory)][string]$Name)
$value = [Environment]::GetEnvironmentVariable($Name, "Process")
if ($null -eq $value) {
return ""
}
return $value.Trim()
}
if ([string]::IsNullOrWhiteSpace($WebhookUrl)) { $WebhookUrl = Get-NinjaValue -Name "webhookurl" }
if ([string]::IsNullOrWhiteSpace($SecretValue)) { $SecretValue = Get-NinjaValue -Name "secretvalue" }
if ([string]::IsNullOrWhiteSpace($WebhookUrl) -or [string]::IsNullOrWhiteSpace($SecretValue)) {
throw "WebhookUrl and SecretValue must be set as NinjaOne script variables."
}
$manifest = Get-OCSentinelManifest -Uri $ManifestUrl
if ([string]::IsNullOrWhiteSpace($manifest.artifactUrl) -or [string]::IsNullOrWhiteSpace($manifest.sha256)) {
throw "The release manifest is incomplete."
}
$downloadRoot = Join-Path $env:ProgramData ("OCSentinel\\install-" + [Guid]::NewGuid().ToString("N"))
$zipPath = Join-Path $downloadRoot "OCSentinelClient.zip"
$extractPath = Join-Path $downloadRoot "payload"
try {
New-Item -ItemType Directory -Force -Path $extractPath | Out-Null
Write-Host "Downloading OCSentinel $($manifest.version)."
Invoke-WebRequest -Uri $manifest.artifactUrl -OutFile $zipPath -TimeoutSec 300
$actualHash = (Get-FileHash -LiteralPath $zipPath -Algorithm SHA256).Hash.ToLowerInvariant()
if ($actualHash -ne ([string]$manifest.sha256).ToLowerInvariant()) {
throw "Release package SHA-256 validation failed."
}
Expand-Archive -LiteralPath $zipPath -DestinationPath $extractPath -Force
$installer = Get-ChildItem -Path $extractPath -Recurse -Filter "install-ocsentinel.ps1" | Select-Object -First 1
if ($null -eq $installer) { throw "The release package does not contain the installer." }
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $installer.FullName
if ($LASTEXITCODE -ne 0) { throw "Installer failed with code $LASTEXITCODE" }
}
finally {
if (Test-Path -LiteralPath $downloadRoot) { Remove-Item -LiteralPath $downloadRoot -Recurse -Force }
}
$installRoot = Join-Path $env:ProgramFiles "OCSentinel"
$configPath = Join-Path $installRoot "config\ocsentinel-client.json"
$secretScript = Join-Path $installRoot "scripts\protect-ocsentinel-secret.ps1"
$monitorScript = Join-Path $installRoot "scripts\run-ocsentinel-monitor.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
$config = Get-Content -LiteralPath $configPath -Raw | ConvertFrom-Json
$config.n8nWebhookUrl = $WebhookUrl
$config.environment = "production"
$config | ConvertTo-Json -Depth 10 | Set-Content -LiteralPath $configPath -Encoding UTF8
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $secretScript -SecretValue $SecretValue
if ($LASTEXITCODE -ne 0) { throw "Writing the protected upload secret failed with code $LASTEXITCODE" }
Write-Host "Running initial signed scan and upload."
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $monitorScript -Mode status -ClientConfigPath $configPath -SecretPath $secretPath -UploadMode required
exit $LASTEXITCODE

View File

@@ -3,8 +3,13 @@ param(
[int]$TopCount = 10, [int]$TopCount = 10,
[string]$OutputPath = ".\reports\ocsentinel-summary.json", [string]$OutputPath = ".\reports\ocsentinel-summary.json",
[string]$ConfigPath = ".\config\ocsentinel-settings.example.json", [string]$ConfigPath = ".\config\ocsentinel-settings.example.json",
[string]$ClientConfigPath = ".\config\ocsentinel-client.json",
[string]$SecretPath = "",
[ValidateSet("disabled", "auto", "required")]
[string]$UploadMode = "auto",
[string]$VulnerabilityCsvPath = "", [string]$VulnerabilityCsvPath = "",
[string]$MirrorRoot = "", [string]$MirrorRoot = "",
[switch]$SuppressTriggerExit,
[ValidateSet("status", "attack-only", "cve-critical", "attack-plus-cve")] [ValidateSet("status", "attack-only", "cve-critical", "attack-plus-cve")]
[string]$Mode = "status" [string]$Mode = "status"
) )
@@ -42,8 +47,13 @@ function Initialize-NinjaFieldWriter {
return return
} }
if (Get-Command -Name "Set-NinjaProperty" -ErrorAction SilentlyContinue) {
$script:NinjaFieldBackend = "powershell-modern"
return
}
if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) { if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) {
$script:NinjaFieldBackend = "powershell" $script:NinjaFieldBackend = "powershell-legacy"
return return
} }
@@ -60,14 +70,20 @@ function Set-NinjaCustomFieldValue {
[Parameter(Mandatory)] [Parameter(Mandatory)]
[string]$Name, [string]$Name,
[AllowEmptyString()] [AllowEmptyString()]
[string]$Value [object]$Value,
[Parameter(Mandatory)]
[string]$Type
) )
Initialize-NinjaFieldWriter Initialize-NinjaFieldWriter
switch ($script:NinjaFieldBackend) { switch ($script:NinjaFieldBackend) {
"powershell" { "powershell-modern" {
Ninja-Property-Set $Name $Value | Out-Null Set-NinjaProperty -Name $Name -Value $Value -Type $Type -Force | Out-Null
return $true
}
"powershell-legacy" {
Ninja-Property-Set -Name $Name -Value $Value | Out-Null
return $true return $true
} }
"cli" { "cli" {
@@ -108,28 +124,43 @@ function Publish-NinjaCustomFields {
} }
} }
$fieldValues = [ordered]@{ $uploadStatus = [string]$Report.Runtime.UploadStatus
"ocsentinelstatus" = [string]$Report.AlertState if ([string]::IsNullOrWhiteSpace($uploadStatus)) { $uploadStatus = "unknown" }
"ocsentinelreason" = $Reason $queuedReports = [int]$Report.Runtime.QueuedReportCount
"ocsentinelbasestatus" = [string]$Report.BaseAlertState $lastUploadUtc = ""
"ocsentinelevents" = [string]([int]$Report.TotalEvents) if ($Report.Runtime.LastSuccessfulUploadUtc) {
"ocsentineluniqueips" = [string]([int]$Report.UniqueIpCount) try { $lastUploadUtc = ([DateTimeOffset]$Report.Runtime.LastSuccessfulUploadUtc).ToUniversalTime().ToString("o") } catch { $lastUploadUtc = [string]$Report.Runtime.LastSuccessfulUploadUtc }
"ocsentinelcvecritical" = [string]([int]$Report.VulnerabilityCorrelation.CriticalCount)
"ocsentinelcvetotal" = [string]([int]$Report.VulnerabilityCorrelation.TotalCount)
"ocsentinelmode" = $Mode
"ocsentineltriggered" = $Triggered.ToString().ToLowerInvariant()
"ocsentinellastscanutc" = $generatedAtUtc
} }
$lastUploadError = [string]$Report.Runtime.LastUploadError
if ($lastUploadError.Length -gt 900) { $lastUploadError = $lastUploadError.Substring(0, 900) }
$fieldValues = @(
[pscustomobject]@{ Name = "ocsentinelstatus"; Type = "Text"; Value = [string]$Report.AlertState }
[pscustomobject]@{ Name = "ocsentinelreason"; Type = "Text"; Value = $Reason }
[pscustomobject]@{ Name = "ocsentinelbasestatus"; Type = "Text"; Value = [string]$Report.BaseAlertState }
[pscustomobject]@{ Name = "ocsentinelevents"; Type = "Integer"; Value = [int]$Report.TotalEvents }
[pscustomobject]@{ Name = "ocsentineluniqueips"; Type = "Integer"; Value = [int]$Report.UniqueIpCount }
[pscustomobject]@{ Name = "ocsentinelcvecritical"; Type = "Integer"; Value = [int]$Report.VulnerabilityCorrelation.CriticalCount }
[pscustomobject]@{ Name = "ocsentinelcvetotal"; Type = "Integer"; Value = [int]$Report.VulnerabilityCorrelation.TotalCount }
[pscustomobject]@{ Name = "ocsentinelmode"; Type = "Text"; Value = $Mode }
[pscustomobject]@{ Name = "ocsentineltriggered"; Type = "Checkbox"; Value = $Triggered }
[pscustomobject]@{ Name = "ocsentinellastscanutc"; Type = "DateTime"; Value = $generatedAtUtc }
[pscustomobject]@{ Name = "ocsentineluploadstatus"; Type = "Text"; Value = $uploadStatus }
[pscustomobject]@{ Name = "ocsentinelqueuedreports"; Type = "Integer"; Value = $queuedReports }
[pscustomobject]@{ Name = "ocsentinellastuploadutc"; Type = "DateTime"; Value = $lastUploadUtc }
[pscustomobject]@{ Name = "ocsentinellasterror"; Type = "Text"; Value = $lastUploadError }
[pscustomobject]@{ Name = "ocsentinelclientversion"; Type = "Text"; Value = [string]$Report.ClientVersion }
)
$updated = 0 $updated = 0
foreach ($entry in $fieldValues.GetEnumerator()) { foreach ($entry in $fieldValues) {
try { try {
if (Set-NinjaCustomFieldValue -Name $entry.Key -Value $entry.Value) { if (Set-NinjaCustomFieldValue -Name $entry.Name -Value $entry.Value -Type $entry.Type) {
$updated++ $updated++
} }
} }
catch { catch {
Write-Warning "Failed to set Ninja custom field '$($entry.Key)': $($_.Exception.Message)" Write-Warning "Failed to set Ninja custom field '$($entry.Name)': $($_.Exception.Message)"
} }
} }
@@ -142,9 +173,15 @@ $runnerArgs = @(
"-LookbackDays", $LookbackDays, "-LookbackDays", $LookbackDays,
"-TopCount", $TopCount, "-TopCount", $TopCount,
"-OutputPath", $OutputPath, "-OutputPath", $OutputPath,
"-ConfigPath", $ConfigPath "-ConfigPath", $ConfigPath,
"-ClientConfigPath", $ClientConfigPath,
"-UploadMode", $UploadMode
) )
if (-not [string]::IsNullOrWhiteSpace($SecretPath)) {
$runnerArgs += @("-SecretPath", $SecretPath)
}
if (-not [string]::IsNullOrWhiteSpace($VulnerabilityCsvPath)) { if (-not [string]::IsNullOrWhiteSpace($VulnerabilityCsvPath)) {
$runnerArgs += @("-VulnerabilityCsvPath", $VulnerabilityCsvPath) $runnerArgs += @("-VulnerabilityCsvPath", $VulnerabilityCsvPath)
} }
@@ -168,6 +205,8 @@ $events = [int]$report.TotalEvents
$uniqueIps = [int]$report.UniqueIpCount $uniqueIps = [int]$report.UniqueIpCount
$criticalCves = [int]$report.VulnerabilityCorrelation.CriticalCount $criticalCves = [int]$report.VulnerabilityCorrelation.CriticalCount
$totalCves = [int]$report.VulnerabilityCorrelation.TotalCount $totalCves = [int]$report.VulnerabilityCorrelation.TotalCount
$uploadStatus = [string]$report.Runtime.UploadStatus
$queuedReports = [int]$report.Runtime.QueuedReportCount
$monitorTriggered = $false $monitorTriggered = $false
$monitorReason = "" $monitorReason = ""
@@ -203,11 +242,13 @@ Write-Host "Events: $events"
Write-Host "Unique IPs: $uniqueIps" Write-Host "Unique IPs: $uniqueIps"
Write-Host "Critical/High CVEs: $criticalCves" Write-Host "Critical/High CVEs: $criticalCves"
Write-Host "Total CVEs: $totalCves" Write-Host "Total CVEs: $totalCves"
Write-Host "Upload status: $uploadStatus"
Write-Host "Queued reports: $queuedReports"
Write-Host "Report: $outputFullPath" Write-Host "Report: $outputFullPath"
Write-Host "Runner exit code: $runnerExitCode" Write-Host "Runner exit code: $runnerExitCode"
if ($monitorTriggered) { if ($monitorTriggered -and -not $SuppressTriggerExit) {
exit 1 exit 1
} }
exit 0 exit $runnerExitCode

View File

@@ -0,0 +1,116 @@
[CmdletBinding()]
param(
[ValidateSet("daily", "burst")]
[string]$Kind = "daily",
[ValidateRange(15, 480)]
[int]$BurstDurationMinutes = 120
)
$ErrorActionPreference = "Stop"
$scriptDir = Split-Path -Parent $MyInvocation.MyCommand.Path
$monitorScript = Join-Path $scriptDir "run-ocsentinel-monitor.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
$mutexName = "Global\OfficeComSentinelScan"
function Get-NinjaBurstEnabled {
if (Get-Command -Name "Get-NinjaProperty" -ErrorAction SilentlyContinue) {
return [bool](Get-NinjaProperty -Name "ocsentinelburst" -Type "Checkbox")
}
if (Get-Command -Name "Ninja-Property-Get" -ErrorAction SilentlyContinue) {
$value = Ninja-Property-Get -Name "ocsentinelburst"
return [string]$value -match "^(1|true|yes)$"
}
Write-Warning "Ninja custom-field reader is unavailable; burst scan skipped."
return $false
}
function Get-NinjaValue {
param([Parameter(Mandatory)][string]$Name, [Parameter(Mandatory)][string]$Type)
try {
if (Get-Command -Name "Get-NinjaProperty" -ErrorAction SilentlyContinue) {
return Get-NinjaProperty -Name $Name -Type $Type
}
if (Get-Command -Name "Ninja-Property-Get" -ErrorAction SilentlyContinue) {
return Ninja-Property-Get -Name $Name
}
}
catch {
Write-Warning "Could not read Ninja field '$Name': $($_.Exception.Message)"
}
return $null
}
function Set-NinjaValue {
param([Parameter(Mandatory)][string]$Name, [AllowEmptyString()][string]$Value, [Parameter(Mandatory)][string]$Type)
try {
if (Get-Command -Name "Set-NinjaProperty" -ErrorAction SilentlyContinue) {
Set-NinjaProperty -Name $Name -Value $Value -Type $Type -Force | Out-Null
return $true
}
if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) {
Ninja-Property-Set -Name $Name -Value $Value | Out-Null
return $true
}
}
catch {
Write-Warning "Could not update Ninja field '$Name': $($_.Exception.Message)"
}
return $false
}
if ($Kind -eq "burst") {
if (-not (Get-NinjaBurstEnabled)) {
Set-NinjaValue -Name "ocsentinelburststatus" -Value "idle" -Type "Text" | Out-Null
Write-Host "OfficeCom Sentinel burst check: disabled."
exit 0
}
$now = [DateTimeOffset]::UtcNow
$untilValue = Get-NinjaValue -Name "ocsentinelburstuntilutc" -Type "DateTime"
$until = $null
if (-not [string]::IsNullOrWhiteSpace([string]$untilValue)) {
try { $until = [DateTimeOffset]$untilValue } catch { Write-Warning "Burst end time is invalid and will be restarted." }
}
if ($null -eq $until) {
$until = $now.AddMinutes($BurstDurationMinutes)
Set-NinjaValue -Name "ocsentinelburstuntilutc" -Value $until.ToString("o") -Type "DateTime" | Out-Null
Write-Host "OfficeCom Sentinel burst window started until $($until.ToString('u'))."
}
elseif ($until -le $now) {
Set-NinjaValue -Name "ocsentinelburst" -Value "false" -Type "Checkbox" | Out-Null
Set-NinjaValue -Name "ocsentinelburststatus" -Value "completed" -Type "Text" | Out-Null
Write-Host "OfficeCom Sentinel burst window completed and was disabled."
exit 0
}
Set-NinjaValue -Name "ocsentinelburststatus" -Value "active until $($until.ToUniversalTime().ToString('o'))" -Type "Text" | Out-Null
}
$createdNew = $false
$mutex = [Threading.Mutex]::new($false, $mutexName, [ref]$createdNew)
try {
if (-not $mutex.WaitOne(0)) {
Write-Host "OfficeCom Sentinel scan skipped: another scan is already running."
exit 0
}
Write-Host "OfficeCom Sentinel scheduled $Kind scan started."
$monitorArgs = @("-NoProfile", "-ExecutionPolicy", "Bypass", "-File", $monitorScript, "-Mode", "status", "-UploadMode", "required", "-SecretPath", $secretPath, "-SuppressTriggerExit")
if ($Kind -eq "burst") {
$monitorArgs += @("-LookbackDays", "1", "-TopCount", "25")
}
& powershell.exe @monitorArgs
exit $LASTEXITCODE
}
finally {
if ($null -ne $mutex) {
try { $mutex.ReleaseMutex() } catch { }
$mutex.Dispose()
}
}

View File

@@ -40,6 +40,40 @@ function Resolve-PathLike {
return [System.IO.Path]::GetFullPath((Join-Path $BasePath $PathValue)) return [System.IO.Path]::GetFullPath((Join-Path $BasePath $PathValue))
} }
function Restore-NinjaContextFromClientConfiguration {
param([Parameter(Mandatory)][string]$Path)
if (-not (Test-Path -LiteralPath $Path)) {
return
}
try {
$clientConfiguration = Get-Content -LiteralPath $Path -Raw | ConvertFrom-Json
$mappings = @(
@{ EnvironmentName = "NINJA_ORGANIZATION_ID"; PropertyName = "ninjaOrganizationId" },
@{ EnvironmentName = "NINJA_ORGANIZATION_NAME"; PropertyName = "ninjaOrganizationName" },
@{ EnvironmentName = "NINJA_AGENT_MACHINE_ID"; PropertyName = "ninjaMachineId" },
@{ EnvironmentName = "NINJA_AGENT_NODE_ID"; PropertyName = "ninjaNodeId" },
@{ EnvironmentName = "NINJA_LOCATION_ID"; PropertyName = "ninjaLocationId" },
@{ EnvironmentName = "NINJA_LOCATION_NAME"; PropertyName = "ninjaLocationName" }
)
foreach ($mapping in $mappings) {
if (-not [string]::IsNullOrWhiteSpace([Environment]::GetEnvironmentVariable($mapping.EnvironmentName, "Process"))) {
continue
}
$value = [string]$clientConfiguration.($mapping.PropertyName)
if (-not [string]::IsNullOrWhiteSpace($value)) {
[Environment]::SetEnvironmentVariable($mapping.EnvironmentName, $value, "Process")
}
}
}
catch {
Write-Warning "Could not restore stored NinjaOne context: $($_.Exception.Message)"
}
}
$arguments = @( $arguments = @(
$dllPath $dllPath
) )
@@ -53,6 +87,8 @@ else {
$secretFullPath = if ([string]::IsNullOrWhiteSpace($SecretPath)) { "" } else { Resolve-PathLike -PathValue $SecretPath -BasePath $repoRoot } $secretFullPath = if ([string]::IsNullOrWhiteSpace($SecretPath)) { "" } else { Resolve-PathLike -PathValue $SecretPath -BasePath $repoRoot }
$canUpload = (Test-Path $clientConfigFullPath) -and (-not [string]::IsNullOrWhiteSpace($secretFullPath)) -and (Test-Path $secretFullPath) $canUpload = (Test-Path $clientConfigFullPath) -and (-not [string]::IsNullOrWhiteSpace($secretFullPath)) -and (Test-Path $secretFullPath)
Restore-NinjaContextFromClientConfiguration -Path $clientConfigFullPath
if ($UploadMode -eq "required" -and -not $canUpload) { if ($UploadMode -eq "required" -and -not $canUpload) {
throw "UploadMode 'required' was set, but client config or protected secret is missing." throw "UploadMode 'required' was set, but client config or protected secret is missing."
} }

View File

@@ -0,0 +1,124 @@
[CmdletBinding()]
param(
[string]$RegistrationToken,
[string]$InstanceUrl = "https://gitea.officecom.cloud",
[string]$RunnerName = "officecom-oc-sentinel-windows-01",
[string]$RunnerVersion = "1.0.8",
[string]$RunnerAccount = "OCGiteaRunner",
[string]$InstallRoot = "$env:ProgramData\\OCGiteaRunner"
)
$ErrorActionPreference = "Stop"
function Test-IsAdministrator {
$identity = [Security.Principal.WindowsIdentity]::GetCurrent()
$principal = New-Object Security.Principal.WindowsPrincipal($identity)
return $principal.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)
}
function New-RunnerPassword {
# The account is only used by Task Scheduler; no password is persisted in this script or repository.
$bytes = New-Object byte[] 36
[Security.Cryptography.RandomNumberGenerator]::Create().GetBytes($bytes)
return [Convert]::ToBase64String($bytes).Replace('+', 'A').Replace('/', 'B').Replace('=', 'C') + "!9z"
}
if (-not (Test-IsAdministrator)) {
throw "Run this script from an elevated PowerShell window (Run as administrator)."
}
if ([string]::IsNullOrWhiteSpace($RegistrationToken)) {
$secureToken = Read-Host "Paste the repository runner registration token" -AsSecureString
$tokenPointer = [Runtime.InteropServices.Marshal]::SecureStringToBSTR($secureToken)
try {
$RegistrationToken = [Runtime.InteropServices.Marshal]::PtrToStringBSTR($tokenPointer)
}
finally {
[Runtime.InteropServices.Marshal]::ZeroFreeBSTR($tokenPointer)
}
}
if ([string]::IsNullOrWhiteSpace($RegistrationToken)) {
throw "A repository runner registration token is required."
}
$taskName = "OCSentinel Gitea Windows Runner"
$runnerPath = Join-Path $InstallRoot "gitea-runner.exe"
$configPath = Join-Path $InstallRoot "config.yaml"
$runnerStatePath = Join-Path $InstallRoot ".runner"
$logDirectory = Join-Path $InstallRoot "logs"
$downloadUrl = "https://gitea.com/gitea/act_runner/releases/download/v$RunnerVersion/gitea-runner-$RunnerVersion-windows-amd64.exe"
$checksumUrl = "$downloadUrl.sha256"
$accountQualifiedName = "$env:COMPUTERNAME\\$RunnerAccount"
if (Test-Path -LiteralPath $runnerStatePath) {
throw "A runner is already registered at $InstallRoot. Remove it in Gitea first, then remove this directory if a new registration is needed."
}
$existingAccount = Get-LocalUser -Name $RunnerAccount -ErrorAction SilentlyContinue
if ($existingAccount) {
throw "The local account '$RunnerAccount' already exists. Stop and remove the existing runner before reinstalling it."
}
New-Item -ItemType Directory -Force -Path $InstallRoot, $logDirectory | Out-Null
try {
Write-Host "Downloading Gitea runner $RunnerVersion..."
Invoke-WebRequest -UseBasicParsing -Uri $downloadUrl -OutFile $runnerPath
$checksumText = (Invoke-WebRequest -UseBasicParsing -Uri $checksumUrl).Content.Trim()
$expectedHash = ($checksumText -split '\s+')[0].ToLowerInvariant()
$actualHash = (Get-FileHash -LiteralPath $runnerPath -Algorithm SHA256).Hash.ToLowerInvariant()
if ($actualHash -ne $expectedHash) {
throw "Runner checksum verification failed."
}
$password = New-RunnerPassword
$securePassword = ConvertTo-SecureString -String $password -AsPlainText -Force
New-LocalUser -Name $RunnerAccount -Password $securePassword -Description "Restricted account for the OCSentinel Gitea Actions runner." -AccountNeverExpires | Out-Null
$config = & $runnerPath generate-config
$config = $config -replace '(?m)^ labels:.*$', ' labels: ["windows:host"]'
Set-Content -LiteralPath $configPath -Value $config -Encoding utf8
# Build jobs run only with this non-administrative account and only for the repository runner token supplied.
$acl = Get-Acl -LiteralPath $InstallRoot
$acl.SetAccessRuleProtection($true, $false)
$systemRule = New-Object Security.AccessControl.FileSystemAccessRule("SYSTEM", "FullControl", "ContainerInherit,ObjectInherit", "None", "Allow")
$adminRule = New-Object Security.AccessControl.FileSystemAccessRule("BUILTIN\\Administrators", "FullControl", "ContainerInherit,ObjectInherit", "None", "Allow")
$runnerRule = New-Object Security.AccessControl.FileSystemAccessRule($accountQualifiedName, "Modify", "ContainerInherit,ObjectInherit", "None", "Allow")
$acl.AddAccessRule($systemRule)
$acl.AddAccessRule($adminRule)
$acl.AddAccessRule($runnerRule)
Set-Acl -LiteralPath $InstallRoot -AclObject $acl
$credential = New-Object Management.Automation.PSCredential($accountQualifiedName, $securePassword)
$registerArgs = @(
"--config", "`"$configPath`"", "register", "--no-interactive",
"--instance", "`"$InstanceUrl`"", "--token", "`"$RegistrationToken`"",
"--name", "`"$RunnerName`"", "--labels", "windows:host"
) -join " "
$registration = Start-Process -FilePath $runnerPath -ArgumentList $registerArgs -WorkingDirectory $InstallRoot -Credential $credential -Wait -PassThru
if ($registration.ExitCode -ne 0 -or -not (Test-Path -LiteralPath $runnerStatePath)) {
throw "Runner registration failed with exit code $($registration.ExitCode)."
}
$action = New-ScheduledTaskAction -Execute $runnerPath -Argument "--config `"$configPath`" daemon" -WorkingDirectory $InstallRoot
$trigger = New-ScheduledTaskTrigger -AtStartup
Register-ScheduledTask -TaskName $taskName -Action $action -Trigger $trigger -User $accountQualifiedName -Password $password -RunLevel Limited -Description "Runs the repository-scoped OCSentinel Gitea Actions runner." -Force | Out-Null
Start-ScheduledTask -TaskName $taskName
Start-Sleep -Seconds 3
$task = Get-ScheduledTask -TaskName $taskName
Write-Host "Gitea runner installed successfully."
Write-Host "Runner: $RunnerName"
Write-Host "Labels: windows:host"
Write-Host "Task: $taskName ($($task.State))"
Write-Host "Install path: $InstallRoot"
}
catch {
if (Get-ScheduledTask -TaskName $taskName -ErrorAction SilentlyContinue) {
Unregister-ScheduledTask -TaskName $taskName -Confirm:$false
}
throw
}

View File

@@ -66,6 +66,7 @@ internal sealed class AttackScanner
{ {
SchemaVersion = "2.0", SchemaVersion = "2.0",
MachineName = Environment.MachineName, MachineName = Environment.MachineName,
NinjaOne = GetNinjaOneContext(),
GeneratedAtLocal = generatedAtLocal, GeneratedAtLocal = generatedAtLocal,
GeneratedAtUtc = generatedAtUtc, GeneratedAtUtc = generatedAtUtc,
ClientVersion = BuildMetadata.Version, ClientVersion = BuildMetadata.Version,
@@ -89,6 +90,24 @@ internal sealed class AttackScanner
}; };
} }
private static NinjaOneContext GetNinjaOneContext()
{
return new NinjaOneContext
{
OrganizationId = ReadEnvironmentVariable("NINJA_ORGANIZATION_ID"),
OrganizationName = ReadEnvironmentVariable("NINJA_ORGANIZATION_NAME"),
MachineId = ReadEnvironmentVariable("NINJA_AGENT_MACHINE_ID"),
NodeId = ReadEnvironmentVariable("NINJA_AGENT_NODE_ID"),
LocationId = ReadEnvironmentVariable("NINJA_LOCATION_ID"),
LocationName = ReadEnvironmentVariable("NINJA_LOCATION_NAME")
};
}
private static string ReadEnvironmentVariable(string name)
{
return Environment.GetEnvironmentVariable(name)?.Trim() ?? string.Empty;
}
private static ScannerConfiguration LoadConfiguration(ScanOptions options) private static ScannerConfiguration LoadConfiguration(ScanOptions options)
{ {
if (string.IsNullOrWhiteSpace(options.ConfigPath)) if (string.IsNullOrWhiteSpace(options.ConfigPath))

View File

@@ -5,7 +5,10 @@ internal static class ScanAndUploadCommand
public static int Execute(string[] args) public static int Execute(string[] args)
{ {
string outputPath = @"C:\ProgramData\OCSentinel\reports\latest.json"; string outputPath = @"C:\ProgramData\OCSentinel\reports\latest.json";
string? clientConfigPath = null;
string? secretPath = null;
bool hasOutput = false; bool hasOutput = false;
var scanArgs = new List<string>();
for (int i = 0; i < args.Length; i++) for (int i = 0; i < args.Length; i++)
{ {
@@ -13,11 +16,26 @@ internal static class ScanAndUploadCommand
{ {
outputPath = args[i + 1]; outputPath = args[i + 1];
hasOutput = true; hasOutput = true;
break; scanArgs.Add(args[i]);
} scanArgs.Add(args[++i]);
continue;
}
if (string.Equals(args[i], "--client-config", StringComparison.OrdinalIgnoreCase) && i + 1 < args.Length)
{
clientConfigPath = args[++i];
continue;
}
if (string.Equals(args[i], "--secret-path", StringComparison.OrdinalIgnoreCase) && i + 1 < args.Length)
{
secretPath = args[++i];
continue;
}
scanArgs.Add(args[i]);
} }
List<string> scanArgs = [.. args];
if (!hasOutput) if (!hasOutput)
{ {
scanArgs.Add("--output"); scanArgs.Add("--output");
@@ -36,6 +54,16 @@ internal static class ScanAndUploadCommand
outputPath outputPath
}; };
if (!string.IsNullOrWhiteSpace(clientConfigPath))
{
uploadArgs.AddRange(["--client-config", clientConfigPath]);
}
if (!string.IsNullOrWhiteSpace(secretPath))
{
uploadArgs.AddRange(["--secret-path", secretPath]);
}
return UploadCommand.Execute([.. uploadArgs]); return UploadCommand.Execute([.. uploadArgs]);
} }
} }

View File

@@ -1,4 +1,5 @@
using OCSentinelCli.Configuration; using OCSentinelCli.Configuration;
using OCSentinelCli.Models;
using System.Text.Json; using System.Text.Json;
using OCSentinelCli.Security; using OCSentinelCli.Security;
using OCSentinelCli.Transport; using OCSentinelCli.Transport;
@@ -56,30 +57,52 @@ internal static class UploadCommand
string reportFullPath = Path.GetFullPath(reportPath); string reportFullPath = Path.GetFullPath(reportPath);
string json = File.ReadAllText(reportFullPath); string json = File.ReadAllText(reportFullPath);
string secret = ProtectedSecretStore.LoadSecret(resolvedSecretPath);
var client = new N8nUploadClient();
var queue = new UploadQueue(config.UploadQueueMaxReports);
UploadHealth health = queue.LoadHealth();
DateTimeOffset attemptTime = DateTimeOffset.UtcNow;
ScanResult? parsedReport = JsonSerializer.Deserialize<ScanResult>(json, JsonOptions.Default); ScanResult? parsedReport = JsonSerializer.Deserialize<ScanResult>(json, JsonOptions.Default);
if (parsedReport is not null) if (parsedReport is not null)
{ {
parsedReport = parsedReport with parsedReport = parsedReport with
{ {
Runtime = parsedReport.Runtime with Runtime = parsedReport.Runtime with
{ {
UploadAttempted = true UploadAttempted = true,
UploadStatus = "attempting",
QueuedReportCount = health.QueuedReportCount,
LastSuccessfulUploadUtc = health.LastSuccessfulUploadUtc
} }
}; };
json = JsonSerializer.Serialize(parsedReport, JsonOptions.Default); json = JsonSerializer.Serialize(parsedReport, JsonOptions.Default);
File.WriteAllText(reportFullPath, json); File.WriteAllText(reportFullPath, json);
} }
string secret = ProtectedSecretStore.LoadSecret(resolvedSecretPath); UploadResult? deferredFailure = queue.Drain(
var client = new N8nUploadClient(); client,
var result = client.UploadJson(config.N8nWebhookUrl, Environment.MachineName, BuildMetadata.Version, json, secret, config.UploadTimeoutSeconds); config.N8nWebhookUrl,
Environment.MachineName,
BuildMetadata.Version,
secret,
config.UploadTimeoutSeconds);
if (!result.Success) if (deferredFailure is null)
{ {
Console.Error.WriteLine($"Upload failed ({result.StatusCode}): {result.Message}"); var result = client.UploadJson(config.N8nWebhookUrl, Environment.MachineName, BuildMetadata.Version, json, secret, config.UploadTimeoutSeconds);
return 1; if (result.Success)
} {
UploadHealth successHealth = new()
{
LastUploadAttemptUtc = attemptTime,
LastSuccessfulUploadUtc = DateTimeOffset.UtcNow,
LastUploadStatus = "ok",
LastUploadError = string.Empty,
QueuedReportCount = queue.GetQueueDepth()
};
queue.SaveHealth(successHealth);
WriteReportRuntime(reportFullPath, parsedReport, successHealth, true);
Console.WriteLine($"Upload succeeded ({result.StatusCode})"); Console.WriteLine($"Upload succeeded ({result.StatusCode})");
Console.WriteLine($"Nonce: {result.Nonce}"); Console.WriteLine($"Nonce: {result.Nonce}");
@@ -87,6 +110,50 @@ internal static class UploadCommand
return 0; return 0;
} }
deferredFailure = result;
}
UploadResult failure = deferredFailure ?? throw new InvalidOperationException("Upload failed without a result.");
int queuedCount = queue.Enqueue(json);
UploadHealth queuedHealth = new()
{
LastUploadAttemptUtc = attemptTime,
LastSuccessfulUploadUtc = health.LastSuccessfulUploadUtc,
LastUploadStatus = "queued",
LastUploadError = failure.Message,
QueuedReportCount = queuedCount
};
queue.SaveHealth(queuedHealth);
WriteReportRuntime(reportFullPath, parsedReport, queuedHealth, true);
Console.WriteLine($"Upload deferred ({failure.StatusCode}): {failure.Message}");
Console.WriteLine($"Queued reports: {queuedCount}");
Console.WriteLine("The report will be retried automatically on the next scheduled run.");
return 0;
}
private static void WriteReportRuntime(string reportPath, ScanResult? report, UploadHealth health, bool attempted)
{
if (report is null)
{
return;
}
ScanResult updated = report with
{
Runtime = report.Runtime with
{
UploadAttempted = attempted,
UploadSucceeded = string.Equals(health.LastUploadStatus, "ok", StringComparison.Ordinal),
UploadStatus = health.LastUploadStatus,
QueuedReportCount = health.QueuedReportCount,
LastSuccessfulUploadUtc = health.LastSuccessfulUploadUtc,
LastUploadError = health.LastUploadError
}
};
File.WriteAllText(reportPath, JsonSerializer.Serialize(updated, JsonOptions.Default));
}
private static string ReadValue(string[] args, ref int index, string argName) private static string ReadValue(string[] args, ref int index, string argName)
{ {
if (index + 1 >= args.Length) if (index + 1 >= args.Length)

View File

@@ -18,6 +18,8 @@ internal sealed record ClientConfiguration
public int UploadTimeoutSeconds { get; init; } = 30; public int UploadTimeoutSeconds { get; init; } = 30;
public int UploadQueueMaxReports { get; init; } = 100;
public bool EnableVulnerabilityCorrelation { get; init; } = true; public bool EnableVulnerabilityCorrelation { get; init; } = true;
public string VulnerabilityCsvPath { get; init; } = string.Empty; public string VulnerabilityCsvPath { get; init; } = string.Empty;

View File

@@ -8,6 +8,9 @@ internal static class JsonOptions
public static readonly JsonSerializerOptions Default = new() public static readonly JsonSerializerOptions Default = new()
{ {
WriteIndented = true, WriteIndented = true,
// Client configuration is also written by PowerShell/NinjaOne scripts.
// Accept their conventional camelCase names (for example n8nWebhookUrl).
PropertyNameCaseInsensitive = true,
DefaultIgnoreCondition = JsonIgnoreCondition.WhenWritingNull DefaultIgnoreCondition = JsonIgnoreCondition.WhenWritingNull
}; };
} }

View File

@@ -80,6 +80,9 @@ internal sealed record ScanResult
public string MachineName { get; init; } = string.Empty; public string MachineName { get; init; } = string.Empty;
// Populated only for runs launched by NinjaOne automation.
public NinjaOneContext NinjaOne { get; init; } = new();
public DateTimeOffset GeneratedAtLocal { get; init; } public DateTimeOffset GeneratedAtLocal { get; init; }
public DateTimeOffset GeneratedAtUtc { get; init; } public DateTimeOffset GeneratedAtUtc { get; init; }
@@ -111,6 +114,21 @@ internal sealed record ScanResult
public List<string> Errors { get; init; } = []; public List<string> Errors { get; init; } = [];
} }
internal sealed record NinjaOneContext
{
public string OrganizationId { get; init; } = string.Empty;
public string OrganizationName { get; init; } = string.Empty;
public string MachineId { get; init; } = string.Empty;
public string NodeId { get; init; } = string.Empty;
public string LocationId { get; init; } = string.Empty;
public string LocationName { get; init; } = string.Empty;
}
internal sealed record ScanRuntimeMetadata internal sealed record ScanRuntimeMetadata
{ {
public DateTimeOffset StartedAtUtc { get; init; } public DateTimeOffset StartedAtUtc { get; init; }
@@ -118,6 +136,16 @@ internal sealed record ScanRuntimeMetadata
public DateTimeOffset FinishedAtUtc { get; init; } public DateTimeOffset FinishedAtUtc { get; init; }
public bool UploadAttempted { get; init; } public bool UploadAttempted { get; init; }
public bool UploadSucceeded { get; init; }
public string UploadStatus { get; init; } = "not-attempted";
public int QueuedReportCount { get; init; }
public DateTimeOffset? LastSuccessfulUploadUtc { get; init; }
public string LastUploadError { get; init; } = string.Empty;
} }
internal sealed record VulnerabilityFinding internal sealed record VulnerabilityFinding

View File

@@ -9,10 +9,10 @@
<RootNamespace>OCSentinelCli</RootNamespace> <RootNamespace>OCSentinelCli</RootNamespace>
<Product>OfficeCom Sentinel</Product> <Product>OfficeCom Sentinel</Product>
<Company>OfficeCom</Company> <Company>OfficeCom</Company>
<Version>1.2.3</Version> <Version>1.3.7</Version>
<AssemblyVersion>1.2.3.0</AssemblyVersion> <AssemblyVersion>1.3.7.0</AssemblyVersion>
<FileVersion>1.2.3.0</FileVersion> <FileVersion>1.3.7.0</FileVersion>
<InformationalVersion>1.2.3</InformationalVersion> <InformationalVersion>1.3.7</InformationalVersion>
</PropertyGroup> </PropertyGroup>
<ItemGroup> <ItemGroup>

View File

@@ -38,6 +38,8 @@ internal sealed class N8nUploadClient
request.Headers.Add("X-ATN-Payload-SHA256", payloadHash); request.Headers.Add("X-ATN-Payload-SHA256", payloadHash);
request.Headers.Add("X-ATN-Signature", signature); request.Headers.Add("X-ATN-Signature", signature);
try
{
using HttpResponseMessage response = httpClient.Send(request); using HttpResponseMessage response = httpClient.Send(request);
string responseText = response.Content.ReadAsStringAsync().GetAwaiter().GetResult(); string responseText = response.Content.ReadAsStringAsync().GetAwaiter().GetResult();
@@ -50,6 +52,18 @@ internal sealed class N8nUploadClient
PayloadSha256 = payloadHash PayloadSha256 = payloadHash
}; };
} }
catch (Exception exception) when (exception is HttpRequestException or TaskCanceledException)
{
return new UploadResult
{
Success = false,
StatusCode = 0,
Message = exception.Message,
Nonce = nonce,
PayloadSha256 = payloadHash
};
}
}
private static string ComputeSha256(string value) private static string ComputeSha256(string value)
{ {

View File

@@ -0,0 +1,106 @@
using System.Text.Json;
using OCSentinelCli.Models;
namespace OCSentinelCli.Transport;
internal sealed record UploadHealth
{
public DateTimeOffset? LastUploadAttemptUtc { get; init; }
public DateTimeOffset? LastSuccessfulUploadUtc { get; init; }
public string LastUploadStatus { get; init; } = "not-attempted";
public string LastUploadError { get; init; } = string.Empty;
public int QueuedReportCount { get; init; }
}
internal sealed class UploadQueue
{
private readonly string queueDirectory;
private readonly string healthPath;
private readonly int maxReports;
public UploadQueue(int maxReports)
{
string root = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.CommonApplicationData), "OCSentinel");
queueDirectory = Path.Combine(root, "upload-queue");
healthPath = Path.Combine(root, "state", "upload-health.json");
this.maxReports = Math.Clamp(maxReports, 10, 500);
}
public UploadHealth LoadHealth()
{
try
{
if (!File.Exists(healthPath))
{
return new UploadHealth { QueuedReportCount = GetQueueDepth() };
}
UploadHealth? health = JsonSerializer.Deserialize<UploadHealth>(File.ReadAllText(healthPath), JsonOptions.Default);
return (health ?? new UploadHealth()) with { QueuedReportCount = GetQueueDepth() };
}
catch (Exception)
{
return new UploadHealth { QueuedReportCount = GetQueueDepth() };
}
}
public void SaveHealth(UploadHealth health)
{
Directory.CreateDirectory(Path.GetDirectoryName(healthPath)!);
WriteAtomically(healthPath, JsonSerializer.Serialize(health, JsonOptions.Default));
}
public UploadResult? Drain(N8nUploadClient client, string webhookUrl, string machineName, string clientVersion, string secret, int timeoutSeconds)
{
foreach (string path in GetQueuedPaths())
{
string payload = File.ReadAllText(path);
UploadResult result = client.UploadJson(webhookUrl, machineName, clientVersion, payload, secret, timeoutSeconds);
if (!result.Success)
{
return result;
}
File.Delete(path);
}
return null;
}
public int Enqueue(string payloadJson)
{
Directory.CreateDirectory(queueDirectory);
string fileName = $"{DateTimeOffset.UtcNow:yyyyMMddHHmmssfff}-{Guid.NewGuid():N}.json";
WriteAtomically(Path.Combine(queueDirectory, fileName), payloadJson);
foreach (string stalePath in GetQueuedPaths().Take(Math.Max(0, GetQueueDepth() - maxReports)))
{
File.Delete(stalePath);
}
return GetQueueDepth();
}
public int GetQueueDepth()
{
return Directory.Exists(queueDirectory) ? Directory.EnumerateFiles(queueDirectory, "*.json").Count() : 0;
}
private IEnumerable<string> GetQueuedPaths()
{
return Directory.Exists(queueDirectory)
? Directory.EnumerateFiles(queueDirectory, "*.json").OrderBy(static path => path, StringComparer.Ordinal)
: Enumerable.Empty<string>();
}
private static void WriteAtomically(string path, string content)
{
string temporaryPath = path + ".tmp";
File.WriteAllText(temporaryPath, content);
File.Move(temporaryPath, path, true);
}
}