47 Commits

Author SHA1 Message Date
OfficeCom Codex
64841d36e7 Correlate failed login activity before alerting
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 50s
2026-07-29 00:50:14 +02:00
OfficeCom Codex
66dcfe09b6 Show summarized security events above raw export
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 49s
2026-07-27 14:42:28 +02:00
OfficeCom Codex
c74d5582b0 Add device raw export summary
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 51s
2026-07-27 14:40:25 +02:00
OfficeCom Codex
4b9202b47c Redesign recipient management dashboard
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-27 14:39:10 +02:00
OfficeCom Codex
a5cea5ebad Unify dashboard background and administration styling
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 50s
2026-07-27 14:37:07 +02:00
OfficeCom Codex
db0533a4cf Fix Outlook report header and metrics layout
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 50s
2026-07-27 14:34:52 +02:00
OfficeCom Codex
f054702438 Provide importable Outlook weekly report workflow
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 51s
2026-07-27 14:31:37 +02:00
OfficeCom Codex
e357e6329d Add Outlook-compatible weekly report template
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 50s
2026-07-27 14:29:05 +02:00
OfficeCom Codex
585b4f91b1 Add robust weekly report templates
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 49s
2026-07-27 12:43:09 +02:00
OfficeCom Codex
1eedac4a76 Send weekly reports per organization
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 50s
2026-07-27 12:18:19 +02:00
OfficeCom Codex
5d5828db49 Publish stable client version 1.3.7
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 9m24s
2026-07-27 11:14:49 +02:00
OfficeCom Codex
2cf3281b4d Retry interrupted client package downloads
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Failing after 24s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-27 11:13:48 +02:00
OfficeCom Codex
b2da734c75 Publish stable client version 1.3.6
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 51s
2026-07-27 10:46:41 +02:00
OfficeCom Codex
40c6daada8 Persist Ninja context for scheduled scans
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 56s
2026-07-27 10:45:49 +02:00
OfficeCom Codex
5be4fb6c33 Show event freshness and device coverage
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 47s
2026-07-27 01:50:46 +02:00
OfficeCom Codex
0fe8a96057 Skip unsupported Gitea artifact upload
All checks were successful
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Successful in 47s
2026-07-27 01:33:31 +02:00
OfficeCom Codex
eb621ace5a Preserve updater exit code in bootstrap
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 22s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 48s
2026-07-27 01:25:26 +02:00
OfficeCom Codex
e997e6b58c Use Roboto for Sentinel dashboard
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 22s
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
2026-07-27 01:24:43 +02:00
OfficeCom Codex
3f09805999 Initialize TLS for legacy client updates
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 47s
2026-07-27 01:22:46 +02:00
OfficeCom Codex
85f0682769 Simplify internal Sentinel dashboard
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 49s
2026-07-27 01:04:49 +02:00
OfficeCom Codex
6722b00ee7 Install PowerShell in Gitea build runner
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 48s
2026-07-27 00:58:51 +02:00
OfficeCom Codex
d3897c8e69 Publish stable client version 1.3.5
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 22s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-27 00:35:43 +02:00
OfficeCom Codex
f9941b0807 Harden release downloads for TLS failures
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-27 00:34:48 +02:00
OfficeCom Codex
c768e1be6b Publish stable client version 1.3.4
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 22s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 21:15:11 +02:00
OfficeCom Codex
2a780cd52f Add time-bounded burst scans
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 21:13:49 +02:00
OfficeCom Codex
daa494fade Publish stable client version 1.3.3
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-26 20:26:37 +02:00
OfficeCom Codex
e7fd4e7ef5 Add resilient upload queue and client health
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 20:25:25 +02:00
OfficeCom Codex
dfdae7a532 Manage weekly report recipients centrally
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-26 11:09:26 +02:00
OfficeCom Codex
854c99e3b2 Configure weekly report recipients
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:49:32 +02:00
OfficeCom Codex
2598de2ecc Polish OCSentinel dashboard interface
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:43:55 +02:00
OfficeCom Codex
6c791cc417 Rename dashboard overview heading
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:42:46 +02:00
OfficeCom Codex
0adac8a0d9 Email weekly organization reports
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:41:46 +02:00
OfficeCom Codex
a45a811040 Refine OCSentinel security dashboard
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-26 03:39:57 +02:00
OfficeCom Codex
2f2a553fc2 Add weekly organization security reports
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 03:16:47 +02:00
OfficeCom Codex
6ceb29a07b Add read-only OCSentinel debug dashboard
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 02:59:51 +02:00
OfficeCom Codex
1c2170090e Stagger daily scans across early morning
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 02:24:05 +02:00
OfficeCom Codex
91c5794502 Add daily scans and Ninja burst mode
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-26 02:17:03 +02:00
OfficeCom Codex
f392057535 Document n8n raw body signature validation
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-25 21:26:56 +02:00
OfficeCom Codex
7431c656d3 Use documented NinjaOne custom field commands
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-25 21:17:59 +02:00
OfficeCom Codex
49b0e3025d Fix Ninja client configuration parsing
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
2026-07-25 21:14:50 +02:00
OfficeCom Codex
aefec51581 Fix NinjaOne environment variable lookup
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-25 21:10:24 +02:00
OfficeCom Codex
7555e92aac Add one-time NinjaOne installation script
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-25 21:01:02 +02:00
OfficeCom Codex
b97b554f84 Add NinjaOne client configuration and upload test
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 25s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-25 20:58:54 +02:00
OfficeCom Codex
77d7eaa0b5 Read NinjaOne rollout variables from environment
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 24s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 19s
2026-07-25 18:53:34 +02:00
OfficeCom Codex
f91f45ad92 Prepare automated release validation
Some checks failed
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
OfficeCom Sentinel Client / build-client-windows (push) Failing after 17s
2026-07-25 10:25:07 +02:00
OfficeCom Codex
c27b53ea0d Use repository secret for Gitea releases
Some checks failed
OfficeCom Sentinel Client / build-client-windows (push) Has been cancelled
OfficeCom Sentinel Client / validate-client (push) Has been cancelled
2026-07-25 10:24:56 +02:00
OfficeCom Codex
f9d7647046 Detect Gitea release tags by reference name
Some checks failed
OfficeCom Sentinel Client / build-client-windows (push) Failing after 18s
OfficeCom Sentinel Client / validate-client (push) Successful in 23s
2026-07-25 10:22:43 +02:00
48 changed files with 2307 additions and 117 deletions

View File

@@ -45,6 +45,39 @@ jobs:
with:
dotnet-version: "10.0.x"
- name: Install PowerShell
shell: bash
run: |
set -euo pipefail
if command -v pwsh >/dev/null 2>&1; then
pwsh --version
exit 0
fi
if [ "$(id -u)" -eq 0 ]; then
SUDO=""
elif command -v sudo >/dev/null 2>&1; then
SUDO="sudo"
else
echo "PowerShell is missing and this runner cannot install packages."
exit 1
fi
. /etc/os-release
case "$ID" in
ubuntu) MICROSOFT_REPO="https://packages.microsoft.com/config/ubuntu/${VERSION_ID}/packages-microsoft-prod.deb" ;;
debian) MICROSOFT_REPO="https://packages.microsoft.com/config/debian/${VERSION_ID}/packages-microsoft-prod.deb" ;;
*) echo "Unsupported runner distribution: $ID"; exit 1 ;;
esac
$SUDO apt-get update
$SUDO apt-get install -y ca-certificates curl
curl -fsSL "$MICROSOFT_REPO" -o /tmp/packages-microsoft-prod.deb
$SUDO dpkg -i /tmp/packages-microsoft-prod.deb
$SUDO apt-get update
$SUDO apt-get install -y powershell
pwsh --version
- name: Build client package
shell: pwsh
run: |
@@ -54,29 +87,22 @@ jobs:
shell: pwsh
run: |
$ref = if ($env:GITHUB_REF) { $env:GITHUB_REF } else { $env:GITEA_REF }
if ($ref -notlike "refs/tags/v*") {
$tag = if ($env:GITHUB_REF_NAME) { $env:GITHUB_REF_NAME } else { Split-Path -Leaf $ref }
if ($tag -notlike "v*") {
Write-Host "Not a version tag; skipping release manifest."
exit 0
}
$tag = Split-Path -Leaf $ref
$artifactUrl = "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/$tag/OCSentinelClient-win-x64.zip"
./build/build-release-manifest.ps1 -ArtifactUrl $artifactUrl
- name: Upload package artifacts
uses: actions/upload-artifact@v4
with:
name: ocsentinel-client-${{ github.sha }}
path: |
artifacts/OCSentinelClient-win-x64.zip
artifacts/OCSentinelClient-win-x64.zip.sha256
artifacts/version.json
if-no-files-found: warn
- name: Publish Gitea release assets
shell: pwsh
env:
GITEA_TOKEN: ${{ secrets.RELEASE_TOKEN }}
run: |
$ref = if ($env:GITHUB_REF) { $env:GITHUB_REF } else { $env:GITEA_REF }
if ($ref -notlike "refs/tags/v*") {
$tag = if ($env:GITHUB_REF_NAME) { $env:GITHUB_REF_NAME } else { Split-Path -Leaf $ref }
if ($tag -notlike "v*") {
Write-Host "Not a version tag; skipping Gitea release publication."
exit 0
}
@@ -88,7 +114,6 @@ jobs:
throw "Gitea release environment is incomplete. Expected GITEA_TOKEN, repository, and server URL."
}
$baseUrl = "$serverUrl/api/v1/repos/$repository"
$tag = Split-Path -Leaf $ref
$releaseBody = @{
tag_name = $tag
target_commitish = "${{ github.sha }}"

View File

@@ -54,6 +54,7 @@ Copy-Item -Path (Join-Path $installerRoot "uninstall-ocsentinel.ps1") -Destinati
Copy-Item -Path (Join-Path $installerRoot "update-ocsentinel.ps1") -Destination (Join-Path $packageRoot "scripts\update-ocsentinel.ps1") -Force
Copy-Item -Path (Join-Path $installerRoot "runtime-run-ocsentinel.ps1") -Destination (Join-Path $packageRoot "scripts\run-ocsentinel.ps1") -Force
Copy-Item -Path (Join-Path $installerRoot "runtime-run-ocsentinel-monitor.ps1") -Destination (Join-Path $packageRoot "scripts\run-ocsentinel-monitor.ps1") -Force
Copy-Item -Path (Join-Path $installerRoot "runtime-run-ocsentinel-scheduled.ps1") -Destination (Join-Path $packageRoot "scripts\run-ocsentinel-scheduled.ps1") -Force
Copy-Item -Path (Join-Path $repoRoot "scripts\protect-ocsentinel-secret.ps1") -Destination (Join-Path $packageRoot "scripts\protect-ocsentinel-secret.ps1") -Force
Copy-Item -Path (Join-Path $repoRoot "config\ocsentinel-settings.example.json") -Destination (Join-Path $packageRoot "config\ocsentinel-settings.example.json") -Force

View File

@@ -4,8 +4,15 @@
"lookbackDays": 7,
"topFindings": 10,
"n8nWebhookUrl": "http://172.16.41.197:5678/webhook/ocsentinel-ingest",
"ninjaOrganizationId": "",
"ninjaOrganizationName": "",
"ninjaMachineId": "",
"ninjaNodeId": "",
"ninjaLocationId": "",
"ninjaLocationName": "",
"deviceIdentifierMode": "machineName",
"uploadTimeoutSeconds": 30,
"uploadQueueMaxReports": 100,
"enableVulnerabilityCorrelation": true,
"vulnerabilityCsvPath": "",
"secretReference": "device-default"

View File

@@ -4,8 +4,15 @@
"lookbackDays": 7,
"topFindings": 10,
"n8nWebhookUrl": "https://n8n.example.com/webhook/ocsentinel-ingest",
"ninjaOrganizationId": "",
"ninjaOrganizationName": "",
"ninjaMachineId": "",
"ninjaNodeId": "",
"ninjaLocationId": "",
"ninjaLocationName": "",
"deviceIdentifierMode": "machineName",
"uploadTimeoutSeconds": 30,
"uploadQueueMaxReports": 100,
"enableVulnerabilityCorrelation": true,
"vulnerabilityCsvPath": "",
"secretReference": "device-default"

View File

@@ -1,8 +1,13 @@
{
"warningEventThreshold": 1,
"criticalEventThreshold": 20,
"warningUniqueIpThreshold": 1,
"criticalUniqueIpThreshold": 10,
"warningEventThreshold": 10,
"criticalEventThreshold": 30,
"warningUniqueIpThreshold": 5,
"criticalUniqueIpThreshold": 12,
"loginBurstWindowMinutes": 15,
"warningLoginBurstCount": 5,
"criticalLoginBurstCount": 20,
"warningSprayAccountCount": 5,
"criticalSprayAccountCount": 10,
"correlationWarningCveThreshold": 1,
"correlationCriticalCveThreshold": 1,
"ftpRoots": [

View File

@@ -30,6 +30,54 @@ powershell -ExecutionPolicy Bypass -File .\build\build-release-manifest.ps1 `
- `config\ocsentinel-settings.json`
- `config\ocsentinel-client.json`
## Local Schedule And Burst Mode
During a NinjaOne installation or update, OCSentinel stores the device's
NinjaOne organization, location, and device identifiers in its local client
configuration. Scheduled `SYSTEM` scans restore that context before creating a
report, so their uploads remain assigned to the correct organization.
The installer creates two Windows Scheduled Tasks running as `SYSTEM`:
- `OCSentinel Daily Scan`: runs once per day and uploads one signed report.
The installer deterministically assigns each device a stable slot between
`04:00` and `06:59`, derived from its Windows `MachineGuid`. This distributes
a fleet rollout instead of sending all reports at the same time.
- `OCSentinel Burst Check`: runs every five minutes. It performs no scan unless
the NinjaOne device custom field `ocsentinelburst` is enabled. Once enabled,
it scans for two hours and then disables itself automatically.
Create `ocsentinelburst` as a device-level `Checkbox` custom field and allow
automation read and write access. Set it to `true` for a device to begin the
five-minute burst scans; clear it to stop them early. The normal daily scan
continues regardless of the checkbox.
Create these accompanying device custom fields and allow automation write
access:
| Field name | Type | Purpose |
| --- | --- | --- |
| `ocsentinelburstuntilutc` | Date/Time | UTC time at which the active burst ends |
| `ocsentinelburststatus` | Text | `idle`, `active until ...`, or `completed` |
## Upload Reliability And Client Health
If the upload endpoint is temporarily unavailable, the client stores up to 100
signed report payloads locally under `C:\ProgramData\OCSentinel\upload-queue`.
The next scheduled run sends queued payloads before its new report. The local
health state is stored under `C:\ProgramData\OCSentinel\state`.
Create these additional device custom fields in NinjaOne and allow automation
write access:
| Field name | Type | Purpose |
| --- | --- | --- |
| `ocsentineluploadstatus` | Text | `ok`, `queued`, or `unknown` upload state |
| `ocsentinelqueuedreports` | Integer | Reports waiting for delivery |
| `ocsentinellastuploadutc` | Date/Time | Last successful upload time |
| `ocsentinellasterror` | Text | Last upload error, if any |
| `ocsentinelclientversion` | Text | Installed client version |
## NinjaOne Tasks
Create a PowerShell script in NinjaOne named `OCSentinel - Installieren oder aktualisieren`.

View File

@@ -36,7 +36,7 @@ For the isolated development environment only, HTTP is permitted at
`http://172.16.41.197:5678/webhook/ocsentinel-ingest`. Do not reuse this URL,
the development shared secret, or a disabled-TLS configuration in production.
1. `Webhook`: accept `POST` on the configured private URL.
1. `Webhook`: accept `POST` on the configured private URL and enable **Raw Body**.
2. `Code`: reject a request if `X-ATN-Device`, `X-ATN-Timestamp`,
`X-ATN-Nonce`, `X-ATN-Version`, `X-ATN-Payload-SHA256`, or
`X-ATN-Signature` is missing; reject timestamps outside five minutes.
@@ -49,6 +49,11 @@ the development shared secret, or a disabled-TLS configuration in production.
<device>\n<timestamp>\n<nonce>\n<version>\n<payload-sha256>
```
In the current n8n Webhook node, the raw bytes are exposed as Base64 at
`$binary.data.data`. Decode this value before calculating the payload hash.
Do not hash `JSON.stringify($json.body)`: parsing and reserializing JSON
changes whitespace and can change the signed byte sequence.
4. `Postgres`: insert the nonce into `ocsentinel.ingest_nonce` with a short
expiry. If it already exists, return `409` and do not process the report.
5. `Postgres`: upsert the device, insert a row in `ocsentinel.scan_report`,

View File

@@ -0,0 +1,6 @@
DB_HOST=ocsentinel-postgres
DB_PORT=5432
DB_NAME=ocsentinel
DB_USER=ocsentinel_debug
DB_PASSWORD=replace-with-server-generated-password
DASHBOARD_CSRF_SECRET=replace-with-server-generated-secret

View File

@@ -0,0 +1,15 @@
FROM python:3.13-alpine
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY app.py .
COPY templates ./templates
COPY static ./static
RUN addgroup -S ocsentinel && adduser -S ocsentinel -G ocsentinel
USER ocsentinel
EXPOSE 8080
CMD ["gunicorn", "--bind", "0.0.0.0:8080", "--workers", "2", "--threads", "4", "--timeout", "30", "app:app"]

View File

@@ -0,0 +1,322 @@
import hashlib
import hmac
import json
import os
from datetime import datetime, timezone
import psycopg
from flask import Flask, abort, redirect, render_template, request, url_for
app = Flask(__name__)
CURRENT_EVENT_HOURS = 24
STALE_REPORT_HOURS = 36
def db_connection():
return psycopg.connect(
host=os.environ["DB_HOST"],
port=os.getenv("DB_PORT", "5432"),
dbname=os.environ["DB_NAME"],
user=os.environ["DB_USER"],
password=os.environ["DB_PASSWORD"],
connect_timeout=5,
)
def csrf_token():
secret = os.environ["DASHBOARD_CSRF_SECRET"].encode("utf-8")
return hmac.new(secret, b"recipient-rules", hashlib.sha256).hexdigest()
def require_csrf():
supplied = request.form.get("csrf_token", "")
if not hmac.compare_digest(supplied, csrf_token()):
abort(400)
def event_metadata(payload):
latest_event = None
for event in (payload or {}).get("Events", []):
value = event.get("Timestamp")
if not value:
continue
try:
timestamp = datetime.fromisoformat(value.replace("Z", "+00:00"))
except ValueError:
continue
if timestamp.tzinfo is None:
timestamp = timestamp.replace(tzinfo=timezone.utc)
if latest_event is None or timestamp > latest_event:
latest_event = timestamp
if latest_event is None:
return {"is_current": False, "label": "keine Ereignisse", "timestamp": None}
age_seconds = max(0, int((datetime.now(timezone.utc) - latest_event.astimezone(timezone.utc)).total_seconds()))
if age_seconds < 3600:
age_label = f"vor {max(1, age_seconds // 60)} Min."
elif age_seconds < 86400:
age_label = f"vor {age_seconds // 3600} Std."
else:
age_label = f"vor {age_seconds // 86400} Tg."
return {
"is_current": age_seconds <= CURRENT_EVENT_HOURS * 3600,
"label": age_label,
"timestamp": latest_event,
}
@app.get("/")
def overview():
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute("SELECT * FROM ocsentinel.organization_summary")
summary = cursor.fetchone()
cursor.execute(
"""
SELECT machine_name, organization_name, received_at, alert_state,
total_events, unique_ip_count, cve_total, cve_critical, payload
FROM (
SELECT machine_name, received_at, alert_state, total_events,
unique_ip_count, cve_total, cve_critical,
payload #>> '{NinjaOne,OrganizationName}' AS organization_name,
payload
FROM ocsentinel.current_device_status
) AS status
ORDER BY received_at DESC NULLS LAST
LIMIT 100
"""
)
reports = cursor.fetchall()
cursor.execute(
"""
SELECT count(*) AS known_devices,
count(*) FILTER (WHERE received_at >= now() - interval '36 hours') AS reporting_devices,
count(*) FILTER (WHERE received_at IS NULL OR received_at < now() - interval '36 hours') AS stale_devices
FROM ocsentinel.current_device_status
"""
)
coverage = cursor.fetchone()
cursor.execute(
"""
SELECT machine_name, alert_state, total_events, unique_ip_count,
received_at, payload
FROM ocsentinel.current_device_status
WHERE alert_state IN ('warning', 'critical')
ORDER BY CASE alert_state WHEN 'critical' THEN 0 ELSE 1 END, received_at DESC
"""
)
alerts = cursor.fetchall()
report_rows = []
for row in reports:
event = event_metadata(row[8])
report_rows.append(
{
"machine_name": row[0],
"organization_name": row[1],
"received_at": row[2],
"alert_state": row[3],
"total_events": row[4],
"unique_ip_count": row[5],
"event": event,
}
)
alert_rows = []
for row in alerts:
event = event_metadata(row[5])
alert_rows.append(
{
"machine_name": row[0],
"alert_state": row[1],
"total_events": row[2],
"unique_ip_count": row[3],
"received_at": row[4],
"event": event,
}
)
return render_template(
"overview.html",
summary=summary,
coverage=coverage,
reports=report_rows,
alerts=alert_rows,
current_alert_count=sum(alert["event"]["is_current"] for alert in alert_rows),
)
@app.get("/device/<machine_name>")
def device(machine_name):
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
SELECT machine_name, first_seen_at, last_seen_at, last_client_version,
generated_at_utc, received_at, alert_state, base_alert_state,
total_events, unique_ip_count, cve_total, cve_critical, payload
FROM ocsentinel.current_device_status
WHERE machine_name = %s
""",
(machine_name,),
)
report = cursor.fetchone()
if report is None:
abort(404)
payload = report[12]
event_groups = {}
for entry in payload.get("Events") or payload.get("events") or []:
event_type = entry.get("Target") or entry.get("target") or "Sicherheitsereignis"
account = entry.get("Username") or entry.get("username") or "-"
source_ip = entry.get("SourceIp") or entry.get("sourceIp") or "-"
key = (event_type, account, source_ip)
group = event_groups.setdefault(
key,
{"type": event_type, "account": account, "source_ip": source_ip, "count": 0, "latest": "-"},
)
group["count"] += 1
timestamp = entry.get("Timestamp") or entry.get("timestamp") or "-"
if timestamp > group["latest"]:
group["latest"] = timestamp
security_events = sorted(
event_groups.values(),
key=lambda entry: (entry["latest"], entry["count"]),
reverse=True,
)[:25]
return render_template(
"device.html",
report=report,
event=event_metadata(payload),
payload=payload,
security_events=security_events,
payload_pretty=json.dumps(payload, indent=2, ensure_ascii=False),
)
@app.get("/reports")
def reports():
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
SELECT id, organization_name, period_start_utc, period_end_utc,
generated_at, device_count, warning_count, critical_count,
total_events
FROM ocsentinel.weekly_organization_report
ORDER BY period_end_utc DESC, organization_name
"""
)
weekly_reports = cursor.fetchall()
return render_template("reports.html", reports=weekly_reports)
@app.get("/reports/<int:report_id>")
def weekly_report(report_id):
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
SELECT organization_name, period_start_utc, period_end_utc,
generated_at, report_html
FROM ocsentinel.weekly_organization_report
WHERE id = %s
""",
(report_id,),
)
report = cursor.fetchone()
if report is None:
abort(404)
return render_template("weekly_report.html", report=report)
@app.get("/recipients")
def recipients():
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
SELECT id, organization_id, organization_name, recipient_email, enabled
FROM ocsentinel.organization_report_recipient
ORDER BY organization_id = '*', organization_name, recipient_email
"""
)
rules = cursor.fetchall()
cursor.execute(
"""
SELECT DISTINCT payload #>> '{NinjaOne,OrganizationId}',
payload #>> '{NinjaOne,OrganizationName}'
FROM ocsentinel.current_device_status
WHERE coalesce(payload #>> '{NinjaOne,OrganizationId}', '') <> ''
ORDER BY 2
"""
)
organizations = cursor.fetchall()
return render_template("recipients.html", rules=rules, organizations=organizations, csrf_token=csrf_token())
@app.post("/recipients")
def add_recipient():
require_csrf()
organization_id = request.form.get("organization_id", "").strip()
organization_name = request.form.get("organization_name", "").strip()
recipient_email = request.form.get("recipient_email", "").strip().lower()
if not organization_id or not organization_name or "@" not in recipient_email:
abort(400)
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"""
INSERT INTO ocsentinel.organization_report_recipient
(organization_id, organization_name, recipient_email)
VALUES (%s, %s, %s)
ON CONFLICT (organization_id, recipient_email) DO NOTHING
""",
(organization_id, organization_name, recipient_email),
)
connection.commit()
return redirect(url_for("recipients"))
@app.post("/recipients/<int:rule_id>/toggle")
def toggle_recipient(rule_id):
require_csrf()
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute(
"UPDATE ocsentinel.organization_report_recipient SET enabled = NOT enabled WHERE id = %s",
(rule_id,),
)
connection.commit()
return redirect(url_for("recipients"))
@app.post("/recipients/<int:rule_id>/delete")
def delete_recipient(rule_id):
require_csrf()
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute("DELETE FROM ocsentinel.organization_report_recipient WHERE id = %s", (rule_id,))
connection.commit()
return redirect(url_for("recipients"))
@app.get("/healthz")
def healthz():
try:
with db_connection() as connection, connection.cursor() as cursor:
cursor.execute("SELECT 1")
return {"status": "ok"}
except Exception:
return {"status": "unavailable"}, 503
if __name__ == "__main__":
app.run(host="0.0.0.0", port=8080)

View File

@@ -0,0 +1,22 @@
services:
ocsentinel-debug:
build: .
container_name: ocsentinel-debug
restart: unless-stopped
env_file: .env
ports:
- "172.16.41.197:8090:8080"
networks:
- ocsentinel-network
read_only: true
tmpfs:
- /tmp
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
networks:
ocsentinel-network:
external: true
name: n8n_n8n-network

View File

@@ -0,0 +1,3 @@
Flask==3.1.1
gunicorn==23.0.0
psycopg[binary]==3.2.9

View File

@@ -0,0 +1,30 @@
:root { --ink:#132a3d; --muted:#5f7180; --paper:#eaf1f7; --panel:#ffffff; --line:#d5e1eb; --green:#14735b; --lime:#b8e36a; --amber:#a55a0a; --red:#a52b31; }
* { box-sizing:border-box; }
body { margin:0; color:var(--ink); background:radial-gradient(circle at 10% -12%, #d9e9f7 0, transparent 30rem),radial-gradient(circle at 95% 8%, #dff2ec 0, transparent 24rem),var(--paper); font-family:'Roboto',sans-serif; }.app-shell:before { content:''; position:fixed; z-index:-1; inset:0; opacity:.34; background-image:linear-gradient(rgba(26,73,111,.045) 1px,transparent 1px),linear-gradient(90deg,rgba(26,73,111,.045) 1px,transparent 1px); background-size:36px 36px; mask-image:linear-gradient(to bottom,black,transparent 68%); }
.masthead { height:70px; padding:0 6vw; display:flex; align-items:center; justify-content:flex-end; border-bottom:1px solid #21445f; background:#102a43; box-shadow:0 5px 24px rgba(16,42,67,.2); }.header-links { display:flex; gap:8px; align-items:center; }.header-links a { padding:8px 10px; border-radius:6px; color:#c8d6e1; font:700 12px 'Roboto',sans-serif; text-decoration:none; transition:background .18s ease,color .18s ease; }.header-links a:hover,.header-links a.active { color:#fff; background:#245a85; }
.brand { color:var(--ink); font:700 20px/1 'Roboto',sans-serif; text-decoration:none; letter-spacing:-.04em; }.brand span { display:inline-grid; place-items:center; margin-right:7px; width:28px; height:28px; background:var(--green); color:#fff; border-radius:50%; font-size:11px; letter-spacing:0; }.badge,.eyebrow { color:var(--muted); font:700 10px/1 'Roboto',sans-serif; text-transform:uppercase; letter-spacing:.12em; }.badge { border:1px solid var(--line); padding:6px 8px; border-radius:20px; }
main { max-width:1280px; margin:auto; padding:32px 6vw 80px; }.hero { max-width:760px; margin-bottom:32px; }.hero h1 { font-size:clamp(34px,5vw,64px); line-height:.98; letter-spacing:-.06em; margin:10px 0; }.hero p { color:var(--muted); font-size:18px; }.hero.compact h1 { font-size:48px; }.hero-note { display:flex; align-items:center; gap:8px; margin-top:20px; color:var(--green); font:700 11px 'Roboto',sans-serif; letter-spacing:.03em; }.hero-note span { width:8px; height:8px; border-radius:50%; background:var(--lime); box-shadow:0 0 0 4px rgba(199,238,107,.25); }
.metrics { display:grid; grid-template-columns:repeat(5,1fr); gap:10px; margin:25px 0 46px; background:transparent; }.metrics article { min-height:130px; padding:20px; border:1px solid var(--line); border-radius:5px; background:var(--panel); box-shadow:0 5px 16px rgba(35,56,42,.035); transition:transform .18s ease,box-shadow .18s ease; }.metrics article:hover { transform:translateY(-3px); box-shadow:0 12px 24px rgba(35,56,42,.09); }.metrics span { display:block; color:var(--muted); font:700 10px 'Roboto',sans-serif; letter-spacing:.09em; text-transform:uppercase; }.metrics strong { display:block; margin-top:16px; font:700 31px 'Roboto',sans-serif; letter-spacing:-.05em; }.metrics .timestamp { font-size:14px; line-height:1.25; letter-spacing:-.02em; }.warning { color:var(--amber); }.critical { color:var(--red); }
.situation { display:flex; align-items:center; justify-content:space-between; gap:22px; margin:0 0 24px; padding:20px 22px; border:1px solid #b9d8c2; background:#edf8f0; color:#195235; }.situation.warning { border-color:#f2cf99; background:#fff6e8; color:#80450d; }.situation.critical { border-color:#edb4aa; background:#fff0ed; color:#8a2a20; }.situation strong { display:block; margin-top:7px; font:700 19px/1.15 'Roboto',sans-serif; letter-spacing:-.025em; }.situation > span { padding:7px 9px; border:1px solid currentColor; border-radius:20px; font:700 10px 'Roboto',sans-serif; letter-spacing:.1em; }
.panel { margin-top:26px; padding:26px; background:var(--panel); border:1px solid var(--line); border-radius:5px; box-shadow:0 6px 18px rgba(35,56,42,.035); }.panel-heading h2 { margin:8px 0 22px; font-size:28px; letter-spacing:-.04em; }.panel-heading h2 small { color:var(--muted); font-size:12px; font-weight:500; letter-spacing:0; }.alert-grid { display:grid; grid-template-columns:repeat(auto-fit,minmax(210px,1fr)); gap:12px; }.alert-card { padding:17px; border-left:5px solid var(--amber); border-radius:3px; background:#fff7e9; color:var(--ink); text-decoration:none; transition:transform .18s ease,box-shadow .18s ease; }.alert-card:hover { transform:translateY(-2px); box-shadow:0 9px 18px rgba(88,57,20,.12); }.alert-card.critical { border-color:var(--red); background:#fff0ed; }.alert-card span,.alert-card small { display:block; font:700 10px 'Roboto',sans-serif; letter-spacing:.08em; text-transform:uppercase; }.alert-card strong { display:block; margin:10px 0; font:700 22px 'Roboto',sans-serif; letter-spacing:-.04em; }
.coverage-panel { padding-bottom:22px; }.coverage-metrics { display:grid; grid-template-columns:repeat(3,1fr); gap:10px; }.coverage-metrics article { padding:15px; border:1px solid var(--line); border-radius:4px; background:#faf9f4; }.coverage-metrics span { display:block; color:var(--muted); font:700 10px 'Roboto',sans-serif; letter-spacing:.08em; text-transform:uppercase; }.coverage-metrics strong { display:block; margin-top:8px; font-size:26px; }.ok { color:var(--green); }
table { width:100%; border-collapse:collapse; font-family:'Roboto',sans-serif; font-size:13px; } th { text-align:left; color:var(--muted); font-size:10px; letter-spacing:.1em; text-transform:uppercase; } th,td { padding:13px 8px; border-bottom:1px solid var(--line); } td a { color:var(--green); font-weight:700; text-decoration:none; }.state { display:inline-block; margin:1px 3px 1px 0; padding:4px 7px; border-radius:12px; background:#e2efe6; color:var(--green); font:700 10px 'Roboto',sans-serif; text-transform:uppercase; }.state.warning { background:#fff0d7; color:var(--amber); }.state.critical { background:#ffe0db; color:var(--red); }.state.current { background:#e2efe6; color:var(--green); }.state.historic { background:#ece9e1; color:#68736e; } pre { margin:0; padding:18px; overflow:auto; color:#dce7da; background:#13221b; border-radius:4px; font:12px/1.5 'Cascadia Code',Consolas,monospace; }.table-wrap { overflow:auto; }
.report-frame { background:#fff; border:1px solid var(--line); border-radius:8px; box-shadow:0 18px 44px rgba(31,68,99,.12); overflow:hidden; }
.panel-heading p:last-child { max-width:720px; margin:-13px 0 20px; color:var(--muted); font-size:14px; }.calm-panel { border-color:#b9d8c2; background:#f4fbf5; }
.recipient-form { display:grid; grid-template-columns:minmax(220px,1fr) minmax(260px,1fr) auto; gap:14px; align-items:end; }.recipient-form label { display:grid; gap:6px; color:var(--muted); font:700 10px 'Roboto',sans-serif; letter-spacing:.08em; text-transform:uppercase; }.recipient-form input,.recipient-form select { min-height:40px; padding:9px 10px; border:1px solid var(--line); border-radius:4px; background:#fff; color:var(--ink); font:14px 'Roboto',sans-serif; }.recipient-form button,.rule-actions button { min-height:40px; padding:9px 13px; border:1px solid var(--green); border-radius:4px; background:var(--green); color:#fff; cursor:pointer; font:700 12px 'Roboto',sans-serif; }.rule-actions { display:flex; gap:8px; }.rule-actions form { margin:0; }.rule-actions .button-secondary { border-color:#d8d4c6; background:#fffdf7; color:var(--ink); }.rule-actions .button-danger { border-color:#e3afa7; background:#fff0ed; color:#8a2a20; }
@media (max-width:850px) { .recipient-form { grid-template-columns:1fr; }.rule-actions { min-width:220px; } }
@media (max-width:850px) { .metrics { grid-template-columns:repeat(2,1fr); }.metrics article:last-child { grid-column:span 2; }.masthead { height:auto; min-height:70px; padding:14px 5vw; align-items:flex-start; }.header-links { justify-content:flex-end; flex-wrap:wrap; }.badge { display:none; } main { padding:38px 5vw; }.situation { align-items:flex-start; flex-direction:column; } }
/* Keep the administration screens visually aligned with the Sentinel reports. */
.panel { border-radius:8px; box-shadow:0 14px 34px rgba(31,68,99,.08); }
.panel > .table-wrap { border:1px solid #dce6ee; border-radius:6px; background:#fbfdff; }
.panel > .table-wrap table { margin:0; }
.panel > .table-wrap th { padding:12px 10px; color:#456174; background:#f0f5f9; }
.panel > .table-wrap td { padding:14px 10px; }
.panel > .table-wrap tbody tr:hover { background:#f2f8fb; }
.recipient-form { padding:18px; border:1px solid #dce6ee; border-radius:6px; background:#f8fbfd; }
.recipient-form input,.recipient-form select { border-radius:5px; background:#fff; }
.recipient-form input:focus,.recipient-form select:focus { outline:2px solid rgba(36,90,133,.25); border-color:#245a85; }
.rule-actions .button-secondary { border-color:var(--line); background:#f8fbfd; }
.recipient-intro { max-width:720px; margin:6px 0 28px; }.recipient-intro h1 { margin:9px 0 10px; font-size:46px; line-height:1; letter-spacing:-.055em; }.recipient-intro p { margin:0; color:var(--muted); font-size:16px; line-height:1.55; }.recipient-intro strong { color:var(--ink); }.recipient-create-panel { margin-top:0; border-color:#c8dbe8; }.recipient-create-panel .panel-heading h2,.recipient-rules-panel .panel-heading h2 { margin:7px 0 8px; }.recipient-create-panel .panel-heading p { margin:0 0 20px; }.recipient-form button { white-space:nowrap; }.recipient-rules-panel { padding-bottom:12px; }.recipient-rules-panel .panel-heading { display:flex; align-items:end; justify-content:space-between; gap:16px; }.recipient-rules-panel .panel-heading h2 { margin-bottom:20px; }.recipient-rules-panel .panel-heading small { display:inline-block; margin-left:7px; padding:4px 7px; border-radius:12px; background:#edf4f8; color:#4d687b; font-size:10px; font-weight:700; letter-spacing:.04em; vertical-align:middle; }.recipient-table td { height:64px; }.recipient-table tr:last-child td { border-bottom:0; }.recipient-email { color:#245a85; font-weight:500; }.actions-heading { text-align:right; }.recipient-table .rule-actions { justify-content:flex-end; }.empty-state { padding:30px 10px !important; color:var(--muted); text-align:center; }
.compact-metrics { grid-template-columns:repeat(4,1fr); }.event-summary-panel { margin-top:8px; }.event-summary-panel .panel-heading h2,.raw-export-panel .panel-heading h2 { margin:7px 0 8px; }.event-summary-panel .panel-heading p,.raw-export-panel .panel-heading p { margin:0 0 20px; }.event-count { display:inline-grid; min-width:28px; min-height:28px; place-items:center; border-radius:14px; background:#fff0d7; color:var(--amber); font:700 12px 'Roboto',sans-serif; }.raw-export-panel { margin-top:8px; }.raw-json { margin-top:18px; border-top:1px solid var(--line); }.raw-json summary { padding:14px 0; color:#245a85; cursor:pointer; font:700 12px 'Roboto',sans-serif; }.raw-json pre { margin-bottom:0; } @media (max-width:850px) { .compact-metrics { grid-template-columns:repeat(2,1fr); }.compact-metrics article:last-child { grid-column:span 2; } }

View File

@@ -0,0 +1,18 @@
<!doctype html>
<html lang="de">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>{% block title %}OC Sentinel{% endblock %}</title>
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap" rel="stylesheet">
<link rel="stylesheet" href="{{ url_for('static', filename='app.css') }}">
</head>
<body class="app-shell">
<header class="masthead">
<nav class="header-links"><a class="{{ 'active' if request.endpoint == 'overview' else '' }}" href="/">Uebersicht</a><a class="{{ 'active' if request.endpoint in ('reports', 'weekly_report') else '' }}" href="{{ url_for('reports') }}">Berichte</a><a class="{{ 'active' if request.endpoint in ('recipients', 'add_recipient', 'toggle_recipient', 'delete_recipient') else '' }}" href="{{ url_for('recipients') }}">Empfaenger</a></nav>
</header>
<main>{% block content %}{% endblock %}</main>
</body>
</html>

View File

@@ -0,0 +1,8 @@
{% extends "base.html" %}
{% block title %}{{ report[0] }} - OC Sentinel{% endblock %}
{% block content %}
<section class="panel"><div class="panel-heading"><h2>{{ report[0] }}</h2><span class="state {{ report[6] }}">{{ report[6] }}</span>{% if report[8] %}<span class="state {{ 'current' if event.is_current else 'historic' }}">{{ 'aktuell' if event.is_current else 'historisch' }}: {{ event.label }}</span>{% endif %}</div></section>
<section class="metrics compact-metrics"><article><span>Ereignisse</span><strong>{{ report[8] }}</strong></article><article><span>Quell-IPs</span><strong>{{ report[9] }}</strong></article><article><span>CVEs</span><strong>{{ report[10] }}</strong></article><article><span>Kritische CVEs</span><strong class="critical">{{ report[11] }}</strong></article></section>
<section class="panel event-summary-panel"><div class="panel-heading"><span class="eyebrow">Schnelluebersicht</span><h2>Erkannte Sicherheitsereignisse</h2><p>Fehlgeschlagene Anmeldungen und weitere Vorfaelle aus dem letzten Scan, nach Konto und Quell-IP zusammengefasst.</p></div><div class="table-wrap"><table><thead><tr><th>Vorfall</th><th>Konto</th><th>Quell-IP</th><th>Letzter Zeitpunkt</th><th>Anzahl</th></tr></thead><tbody>{% for entry in security_events %}<tr><td><strong>{{ entry.type }}</strong></td><td>{{ entry.account }}</td><td>{{ entry.source_ip }}</td><td>{{ entry.latest }}</td><td><span class="event-count">{{ entry.count }}</span></td></tr>{% else %}<tr><td colspan="5" class="empty-state">Keine sicherheitsrelevanten Ereignisse im letzten Scan.</td></tr>{% endfor %}</tbody></table></div></section>
<section class="panel raw-export-panel"><div class="panel-heading"><span class="eyebrow">Technische Daten</span><h2>Roh-Export</h2><p>Vollstaendige, unveraenderte Nutzlast des zuletzt eingegangenen Scans.</p></div><details class="raw-json" open><summary>JSON-Rohdaten</summary><pre>{{ payload_pretty }}</pre></details></section>
{% endblock %}

View File

@@ -0,0 +1,39 @@
{% extends "base.html" %}
{% block content %}
<section class="situation {% if summary[2] %}critical{% elif summary[1] %}warning{% else %}ok{% endif %}">
<div><strong>{% if summary[2] %}Kritische Ereignisse{% elif summary[1] %}Hinweise vorhanden{% else %}Keine kritischen Auffaelligkeiten{% endif %}</strong></div>
<span>{% if summary[2] %}KRITISCH{% elif summary[1] %}PRUEFEN{% else %}STABIL{% endif %}</span>
</section>
<section class="metrics">
<article><span>Geraete</span><strong>{{ summary[0] }}</strong></article>
<article><span>Warnungen</span><strong class="warning">{{ summary[1] }}</strong></article>
<article><span>Kritisch</span><strong class="critical">{{ summary[2] }}</strong></article>
<article><span>Ereignisse</span><strong>{{ summary[3] }}</strong></article>
<article><span>Letzte Meldung</span><strong class="timestamp">{{ summary[7] or '-' }}</strong></article>
</section>
<section class="panel coverage-panel">
<div class="panel-heading"><h2>Geraeteabdeckung</h2></div>
<div class="coverage-metrics"><article><span>Bekannt</span><strong>{{ coverage[0] }}</strong></article><article><span>Meldend &lt; 36 Std.</span><strong class="ok">{{ coverage[1] }}</strong></article><article><span>Stumm &gt; 36 Std.</span><strong class="{% if coverage[2] %}warning{% endif %}">{{ coverage[2] }}</strong></article></div>
</section>
{% if alerts %}
<section class="panel alert-panel">
<div class="panel-heading"><h2>Auffaellige Geraete <small>{{ current_alert_count }} aktuell, {{ alerts|length - current_alert_count }} historisch</small></h2></div>
<div class="alert-grid">
{% for alert in alerts %}
<a class="alert-card {{ alert.alert_state }}" href="{{ url_for('device', machine_name=alert.machine_name) }}">
<span>{{ alert.alert_state }} | {{ 'aktuell' if alert.event.is_current else 'historisch' }}</span><strong>{{ alert.machine_name }}</strong><small>{{ alert.total_events }} Ereignisse | {{ alert.unique_ip_count }} Quell-IPs | letztes Ereignis {{ alert.event.label }}</small>
</a>
{% endfor %}
</div>
</section>
{% endif %}
<section class="panel">
<div class="panel-heading"><h2>Geraetestatus</h2></div>
<div class="table-wrap"><table><thead><tr><th>Geraet</th><th>Organisation</th><th>Status</th><th>Ereignisse</th><th>Quell-IPs</th><th>Empfangen</th></tr></thead>
<tbody>{% for row in reports %}<tr><td><a href="{{ url_for('device', machine_name=row.machine_name) }}">{{ row.machine_name }}</a></td><td>{{ row.organization_name or '-' }}</td><td><span class="state {{ row.alert_state }}">{{ row.alert_state }}</span>{% if row.total_events %}<span class="state {{ 'current' if row.event.is_current else 'historic' }}">{{ 'aktuell' if row.event.is_current else 'historisch' }}</span>{% endif %}</td><td>{{ row.total_events }}</td><td>{{ row.unique_ip_count }}</td><td>{{ row.received_at or '-' }}</td></tr>{% else %}<tr><td colspan="6">Keine Geraeteberichte.</td></tr>{% endfor %}</tbody></table></div>
</section>
{% endblock %}

View File

@@ -0,0 +1,27 @@
{% extends "base.html" %}
{% block title %}Empfaenger - OC Sentinel{% endblock %}
{% block content %}
<section class="recipient-intro">
<span class="eyebrow">Wochenberichte</span>
<h1>Empfaenger verwalten</h1>
<p>Lege fest, welche Personen den Sicherheitsbericht einer Organisation erhalten. Regeln fuer <strong>Alle Organisationen</strong> gelten zusaetzlich zu den einzelnen Organisationen.</p>
</section>
<section class="panel recipient-create-panel">
<div class="panel-heading"><span class="eyebrow">Neue Regel</span><h2>Bericht zustellen</h2><p>Die Adresse wird beim naechsten Wochenbericht automatisch beruecksichtigt.</p></div>
<form class="recipient-form" method="post" action="{{ url_for('add_recipient') }}">
<input type="hidden" name="csrf_token" value="{{ csrf_token }}">
<label>Organisation<select name="organization_id" id="organization_id" required onchange="document.getElementById('organization_name').value=this.options[this.selectedIndex].dataset.name"><option value="*" data-name="Alle Organisationen">Alle Organisationen</option>{% for organization in organizations %}<option value="{{ organization[0] }}" data-name="{{ organization[1] }}">{{ organization[1] }}</option>{% endfor %}</select></label>
<input type="hidden" name="organization_name" id="organization_name" value="Alle Organisationen">
<label>E-Mail-Adresse<input type="email" name="recipient_email" placeholder="name@officecom.it" required></label>
<button type="submit">Empfaenger hinzufuegen</button>
</form>
</section>
<section class="panel recipient-rules-panel">
<div class="panel-heading"><span class="eyebrow">Aktive Konfiguration</span><h2>E-Mail-Verteiler <small>{{ rules|length }} Regel{{ '' if rules|length == 1 else 'n' }}</small></h2></div>
<div class="table-wrap recipient-table"><table><thead><tr><th>Organisation</th><th>E-Mail-Adresse</th><th>Status</th><th class="actions-heading">Verwalten</th></tr></thead><tbody>
{% for rule in rules %}<tr><td><strong>{{ rule[2] }}</strong></td><td><a class="recipient-email" href="mailto:{{ rule[3] }}">{{ rule[3] }}</a></td><td><span class="state {{ 'ok' if rule[4] else 'warning' }}">{{ 'aktiv' if rule[4] else 'pausiert' }}</span></td><td class="rule-actions"><form method="post" action="{{ url_for('toggle_recipient', rule_id=rule[0]) }}"><input type="hidden" name="csrf_token" value="{{ csrf_token }}"><button class="button-secondary" type="submit">{{ 'Pausieren' if rule[4] else 'Aktivieren' }}</button></form><form method="post" action="{{ url_for('delete_recipient', rule_id=rule[0]) }}"><input type="hidden" name="csrf_token" value="{{ csrf_token }}"><button class="button-danger" type="submit">Loeschen</button></form></td></tr>{% else %}<tr><td colspan="4" class="empty-state">Noch keine Empfaengerregeln angelegt.</td></tr>{% endfor %}
</tbody></table></div>
</section>
{% endblock %}

View File

@@ -0,0 +1,7 @@
{% extends "base.html" %}
{% block title %}Berichte - OC Sentinel{% endblock %}
{% block content %}
<section class="panel"><div class="table-wrap"><table><thead><tr><th>Organisation</th><th>Zeitraum</th><th>Geraete</th><th>Warnung</th><th>Kritisch</th><th>Events</th><th>Erstellt</th></tr></thead><tbody>
{% for row in reports %}<tr><td><a href="{{ url_for('weekly_report', report_id=row[0]) }}">{{ row[1] }}</a></td><td>{{ row[2] }} bis {{ row[3] }}</td><td>{{ row[5] }}</td><td>{{ row[6] }}</td><td>{{ row[7] }}</td><td>{{ row[8] }}</td><td>{{ row[4] }}</td></tr>{% else %}<tr><td colspan="7">Keine Wochenberichte.</td></tr>{% endfor %}
</tbody></table></div></section>
{% endblock %}

View File

@@ -0,0 +1,5 @@
{% extends "base.html" %}
{% block title %}{{ report[0] }} - Wochenbericht{% endblock %}
{% block content %}
<section class="report-frame">{{ report[4] | safe }}</section>
{% endblock %}

File diff suppressed because one or more lines are too long

View File

@@ -0,0 +1,76 @@
{
"id": "OCwRpt7eK3mQ2xL9",
"name": "OCSentinel - Weekly Organization Reports",
"nodes": [
{
"parameters": { "rule": { "interval": [{ "field": "weeks", "weeksInterval": 1, "triggerAtDay": [1], "triggerAtHour": 7, "triggerAtMinute": 20 }] } },
"id": "schedule-weekly-reports", "name": "Every Monday 07:20", "type": "n8n-nodes-base.scheduleTrigger", "typeVersion": 1.3, "position": [300, 300]
},
{
"parameters": { "operation": "executeQuery", "query": "WITH latest AS (\n SELECT DISTINCT ON (d.id) d.machine_name, r.alert_state, r.payload\n FROM ocsentinel.scan_report AS r\n JOIN ocsentinel.device AS d ON d.id = r.device_id\n WHERE r.received_at >= now() - interval '8 days'\n ORDER BY d.id, r.generated_at_utc DESC, r.received_at DESC\n)\nSELECT machine_name, alert_state, payload\nFROM latest\nORDER BY payload #>> '{NinjaOne,OrganizationName}', machine_name;" },
"id": "load-weekly-data", "name": "Load Latest Device Reports", "type": "n8n-nodes-base.postgres", "typeVersion": 2.5, "position": [560, 300],
"credentials": { "postgres": { "id": "WkjY0kIF3kHvREys", "name": "OCSentinel PostgreSQL" } }
},
{
"parameters": { "jsCode": "const esc=v=>String(v??'').replace(/&/g,'&amp;').replace(/</g,'&lt;').replace(/>/g,'&gt;').replace(/\\\"/g,'&quot;').replace(/'/g,'&#39;');\nconst now=new Date(),end=new Date(Date.UTC(now.getUTCFullYear(),now.getUTCMonth(),now.getUTCDate()));\nend.setUTCDate(end.getUTCDate()-((end.getUTCDay()+6)%7)); const start=new Date(end-7*86400000);\nconst groups=new Map();\nfor(const item of items){const p=item.json.payload||{},n=p.NinjaOne||p.ninjaOne||{},id=String(n.OrganizationId||n.organizationId||'unknown'),name=String(n.OrganizationName||n.organizationName||`Organisation ${id}`);if(!groups.has(id))groups.set(id,{id,name,devices:[]});groups.get(id).devices.push({machine:item.json.machine_name||p.MachineName||'Unbekannt',state:String(item.json.alert_state||p.AlertState||'unknown').toLowerCase(),p});}\nconst result=[];\nfor(const group of groups.values()){let warnings=0,criticals=0,total=0,cveTotal=0,cveCritical=0;const ips=new Set(),alerts=[],clean=[];for(const d of group.devices){if(d.state==='warning')warnings++;if(d.state==='critical')criticals++;const vc=d.p.VulnerabilityCorrelation||{};cveTotal+=Number(vc.TotalCount||0);cveCritical+=Number(vc.CriticalCount||0);const events=(d.p.Events||[]).filter(e=>{const t=new Date(e.Timestamp);return !Number.isNaN(t)&&t>=start&&t<end;});total+=events.length;if(!events.length){clean.push(`<tr class=\"clean\"><td>${esc(d.machine)}</td><td>Keine</td><td>-</td><td>-</td><td>0</td><td>-</td><td>Log sauber / Keine Angriffe</td></tr>`);continue;}const rows=new Map();for(const e of events){const ip=e.SourceIp||'-',account=e.Username||'-',type=e.Target||'Sicherheitsereignis',key=[type,account,ip].join('|'),row=rows.get(key)||{ip,account,type,count:0,last:e.Timestamp};row.count++;if(new Date(e.Timestamp)>new Date(row.last))row.last=e.Timestamp;rows.set(key,row);if(ip!=='-')ips.add(ip);}for(const r of rows.values()){alerts.push(`<tr class=\"alert\"><td>${esc(d.machine)}</td><td>${esc(r.type)}</td><td>${esc(r.account)}</td><td>${esc(new Date(r.last).toLocaleString('de-DE',{timeZone:'Europe/Berlin'}))}</td><td>${r.count}</td><td>${esc(r.ip)}</td><td>${d.state==='critical'?'Problem entdeckt (kritisch)':'Problem entdeckt'}</td></tr>`);}}const summary={deviceCount:group.devices.length,warningCount:warnings,criticalCount:criticals,totalEvents:total,uniqueIps:ips.size,cveTotal,cveCritical};const html=`<div class=\"ocsentinel-report\"><style>.ocsentinel-report{font-family:Arial,sans-serif;font-size:12px;color:#1f2937;max-width:1200px}.ocsentinel-report h2{font-size:16px;color:#183b79;margin:0 0 5px;border-bottom:1px solid #183b79;padding-bottom:5px}.ocsentinel-report .meta{font-size:11px;color:#4b5563;margin-bottom:12px}.ocsentinel-report .summary{margin:10px 0;padding:8px;background:#eef5ff;border:1px solid #bfd4f2;color:#183b79}.ocsentinel-report table{width:100%;border-collapse:collapse}.ocsentinel-report th{background:#1f4a99;color:#fff;text-align:left;padding:6px;font-size:11px}.ocsentinel-report td{border:1px solid #e5e7eb;padding:6px;vertical-align:top}.ocsentinel-report tr.alert{background:#fff4ed;color:#8a3d16}.ocsentinel-report tr.clean{background:#effcf4;color:#17643a}.ocsentinel-report .footer{margin-top:10px;font-size:10px;color:#6b7280;text-align:right}</style><h2>OCSentinel - Konsolidierter Sicherheitsbericht</h2><div class=\"meta\"><strong>${esc(group.name)}</strong><br>Berichtszeitraum: ${start.toLocaleDateString('de-DE')} bis ${end.toLocaleDateString('de-DE')}<br>Erstellt am: ${now.toLocaleString('de-DE',{timeZone:'Europe/Berlin'})}</div><div class=\"summary\"><strong>${summary.deviceCount} Geräte</strong> | <strong>${summary.criticalCount} kritisch</strong> | <strong>${summary.warningCount} Warnungen</strong> | <strong>${summary.totalEvents} Ereignisse</strong> | <strong>${summary.uniqueIps} IPs</strong> | <strong>${summary.cveCritical} kritische CVEs</strong></div><table><thead><tr><th>Server</th><th>Vorfall-Typ</th><th>Betroffenes Konto</th><th>Letzter Zeitpunkt</th><th>Anzahl</th><th>Angreifer-IP</th><th>Status / Bemerkung</th></tr></thead><tbody>${alerts.join('')}${clean.join('')}</tbody></table><div class=\"footer\">Automatisch durch OCSentinel und n8n erzeugt.</div></div>`;result.push({json:{organizationId:group.id,organizationName:group.name,periodStartUtc:start.toISOString(),periodEndUtc:end.toISOString(),...summary,reportHtml:html,summaryJson:JSON.stringify(summary)}});}return result;" },
"id": "build-weekly-reports", "name": "Build Organization HTML Reports", "type": "n8n-nodes-base.code", "typeVersion": 2, "position": [820, 300]
},
{
"parameters": { "operation": "executeQuery", "query": "INSERT INTO ocsentinel.weekly_organization_report (organization_id, organization_name, period_start_utc, period_end_utc, device_count, warning_count, critical_count, total_events, unique_ips, cve_total, cve_critical, report_html, summary)\nVALUES ($1, $2, $3::timestamptz, $4::timestamptz, $5, $6, $7, $8, $9, $10, $11, $12, $13::jsonb)\nON CONFLICT (organization_id, period_start_utc) DO UPDATE SET organization_name=EXCLUDED.organization_name, period_end_utc=EXCLUDED.period_end_utc, generated_at=now(), device_count=EXCLUDED.device_count, warning_count=EXCLUDED.warning_count, critical_count=EXCLUDED.critical_count, total_events=EXCLUDED.total_events, unique_ips=EXCLUDED.unique_ips, cve_total=EXCLUDED.cve_total, cve_critical=EXCLUDED.cve_critical, report_html=EXCLUDED.report_html, summary=EXCLUDED.summary\nRETURNING id;", "options": { "queryReplacement": "={{ [$json.organizationId, $json.organizationName, $json.periodStartUtc, $json.periodEndUtc, $json.deviceCount, $json.warningCount, $json.criticalCount, $json.totalEvents, $json.uniqueIps, $json.cveTotal, $json.cveCritical, $json.reportHtml, $json.summaryJson] }}" } },
"id": "store-weekly-reports", "name": "Store Weekly Organization Reports", "type": "n8n-nodes-base.postgres", "typeVersion": 2.5, "position": [1080, 300],
"credentials": { "postgres": { "id": "WkjY0kIF3kHvREys", "name": "OCSentinel PostgreSQL" } }
},
{
"parameters": {
"operation": "executeQuery",
"query": "SELECT coalesce(array_agg(recipient_email ORDER BY recipient_email), ARRAY[]::text[]) AS recipients\nFROM ocsentinel.organization_report_recipient\nWHERE enabled = TRUE AND (organization_id = '*' OR organization_id = $1);",
"options": { "queryReplacement": "={{ [$json.organizationId] }}" }
},
"id": "load-report-recipients",
"name": "Empfaenger aus zentraler Zuordnung laden",
"type": "n8n-nodes-base.postgres",
"typeVersion": 2.5,
"position": [1560, 300]
,"credentials": { "postgres": { "id": "WkjY0kIF3kHvREys", "name": "OCSentinel PostgreSQL" } }
},
{
"parameters": {
"mode": "runOnceForEachItem",
"jsCode": "const report = $('Build Organization HTML Reports').item.json;\nconst recipients = Array.from(new Set($json.recipients || []));\nif (recipients.length === 0) return [];\nreturn { json: { ...report, recipients } };"
},
"id": "prepare-report-email",
"name": "E-Mail vorbereiten",
"type": "n8n-nodes-base.code",
"typeVersion": 2,
"position": [1800, 300]
},
{
"parameters": {
"fromEmail": "donotreply@officecom.biz",
"toEmail": "={{ $json.recipients.join(', ') }}",
"subject": "=OCSentinel Wochenbericht - {{ $json.organizationName }}",
"html": "={{ $json.reportHtml }}",
"options": { "appendAttribution": false }
},
"id": "send-weekly-report-email",
"name": "Send Weekly Organization Report",
"type": "n8n-nodes-base.emailSend",
"typeVersion": 2.1,
"position": [2040, 300],
"credentials": { "smtp": { "id": "vafGYgYzM9SbxQbW", "name": "SMTP account" } }
}
],
"connections": {
"Every Monday 07:20": { "main": [[{ "node": "Load Latest Device Reports", "type": "main", "index": 0 }]] },
"Load Latest Device Reports": { "main": [[{ "node": "Build Organization HTML Reports", "type": "main", "index": 0 }]] },
"Build Organization HTML Reports": { "main": [[{ "node": "Store Weekly Organization Reports", "type": "main", "index": 0 }, { "node": "Empfaenger aus zentraler Zuordnung laden", "type": "main", "index": 0 }]] },
"Empfaenger aus zentraler Zuordnung laden": { "main": [[{ "node": "E-Mail vorbereiten", "type": "main", "index": 0 }]] },
"E-Mail vorbereiten": { "main": [[{ "node": "Send Weekly Organization Report", "type": "main", "index": 0 }]] }
},
"settings": { "executionOrder": "v1", "timezone": "Europe/Berlin" },
"active": true,
"pinData": {},
"versionId": "af98f45b-192e-49c8-9a1e-e7b1fc7e00b2",
"meta": { "templateCredsSetupCompleted": true },
"tags": []
}

View File

@@ -0,0 +1,40 @@
const esc = (value) => String(value ?? '')
.replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;')
.replace(/"/g, '&quot;').replace(/'/g, '&#39;')
.replace(/[^\x20-\x7e]/g, (character) => `&#${character.codePointAt(0)};`);
const fmt = (value) => new Date(value).toLocaleString('de-DE', { timeZone: 'Europe/Berlin', dateStyle: 'medium', timeStyle: 'short' });
const now = new Date();
const end = new Date(Date.UTC(now.getUTCFullYear(), now.getUTCMonth(), now.getUTCDate()));
end.setUTCDate(end.getUTCDate() - ((end.getUTCDay() + 6) % 7));
const start = new Date(end.getTime() - 7 * 86400000);
const groups = new Map();
for (const item of items) {
const payload = item.json.payload || {}, ninja = payload.NinjaOne || payload.ninjaOne || {};
const id = String(ninja.OrganizationId || ninja.organizationId || 'unknown');
if (!groups.has(id)) groups.set(id, { id, name: String(ninja.OrganizationName || ninja.organizationName || `Organisation ${id}`), devices: [] });
groups.get(id).devices.push({ name: item.json.machine_name || payload.MachineName || 'Unbekannt', state: String(item.json.alert_state || payload.AlertState || 'unknown').toLowerCase(), payload });
}
const output = [];
for (const group of groups.values()) {
let warnings = 0, criticals = 0, totalEvents = 0, cveCritical = 0;
const ips = new Set(), rows = [];
for (const device of group.devices.sort((a, b) => a.name.localeCompare(b.name))) {
if (device.state === 'warning') warnings++;
if (device.state === 'critical') criticals++;
cveCritical += Number((device.payload.VulnerabilityCorrelation || {}).CriticalCount || 0);
const events = (device.payload.Events || []).filter((event) => { const date = new Date(event.Timestamp); return !Number.isNaN(date) && date >= start && date < end; });
totalEvents += events.length;
if (!events.length) { rows.push(`<tr class="clean"><td>${esc(device.name)}</td><td colspan="5">Keine sicherheitsrelevanten Ereignisse im Berichtszeitraum.</td><td><b class="ok">Sauber</b></td></tr>`); continue; }
const grouped = new Map();
for (const event of events) {
const ip = event.SourceIp || '-', account = event.Username || '-', type = event.Target || 'Sicherheitsereignis', key = [type, account, ip].join('|');
const entry = grouped.get(key) || { ip, account, type, count: 0, latest: event.Timestamp };
entry.count++; if (new Date(event.Timestamp) > new Date(entry.latest)) entry.latest = event.Timestamp; grouped.set(key, entry); if (ip !== '-') ips.add(ip);
}
for (const event of grouped.values()) rows.push(`<tr class="alert"><td>${esc(device.name)}</td><td>${esc(event.type)}</td><td>${esc(event.account)}</td><td>${esc(fmt(event.latest))}</td><td>${event.count}</td><td>${esc(event.ip)}</td><td><b class="${device.state === 'critical' ? 'critical' : 'warning'}">${device.state === 'critical' ? 'Kritisch' : 'Pruefen'}</b></td></tr>`);
}
const risk = criticals ? ['Kritisch', 'critical'] : warnings ? ['Beobachten', 'warning'] : ['Unauffaellig', 'ok'];
const html = `<div class="ocs"><style>.ocs{font:13px Segoe UI,Tahoma,sans-serif;color:#172033;max-width:1160px}.ocs .head{background:#102a43;color:#fff;padding:18px 20px;border-radius:8px 8px 0 0}.ocs h1{margin:0;font-size:20px}.ocs .meta{color:#d5e2ee;margin-top:5px}.ocs .risk{float:right;padding:4px 8px;border-radius:12px}.ocs .stats{width:100%;border-collapse:separate;border-spacing:8px;margin:8px -8px}.ocs .stats td{width:16%;padding:9px;background:#f4f8fc;border:1px solid #dbe5ef}.ocs .stats b{display:block;font-size:20px;color:#102a43}.ocs table{width:100%;border-collapse:collapse}.ocs th{background:#1d4e89;color:#fff;text-align:left;padding:8px;font-size:11px}.ocs td{padding:8px;border-bottom:1px solid #dbe5ef;vertical-align:top}.ocs .alert{background:#fff8f3}.ocs .clean{background:#f3fbf6}.ocs .ok,.ocs .warning,.ocs .critical{padding:3px 6px;border-radius:4px}.ocs .ok{background:#d1fae5;color:#065f46}.ocs .warning{background:#fef3c7;color:#92400e}.ocs .critical{background:#fee2e2;color:#991b1b}.ocs .foot{margin-top:12px;text-align:right;color:#64748b;font-size:10px}</style><div class="head"><b class="risk ${risk[1]}">${risk[0]}</b><h1>OfficeCom Sentinel Sicherheitsbericht</h1><div class="meta">${esc(group.name)} | ${esc(start.toLocaleDateString('de-DE'))} bis ${esc(end.toLocaleDateString('de-DE'))}</div></div><table class="stats"><tr><td><b>${group.devices.length}</b>Ger&auml;te</td><td><b>${criticals}</b>Kritisch</td><td><b>${warnings}</b>Warnungen</td><td><b>${totalEvents}</b>Ereignisse</td><td><b>${ips.size}</b>Quell-IP-Adressen</td><td><b>${cveCritical}</b>Kritische CVEs</td></tr></table><table><thead><tr><th>System</th><th>Vorfall</th><th>Konto</th><th>Letzter Zeitpunkt</th><th>Anzahl</th><th>Quell-IP</th><th>Bewertung</th></tr></thead><tbody>${rows.join('')}</tbody></table><div class="foot">Automatisch erstellt am ${esc(fmt(now))} durch OfficeCom Sentinel.</div></div>`;
output.push({ json: { organizationId: group.id, organizationName: group.name, periodStartUtc: start.toISOString(), periodEndUtc: end.toISOString(), deviceCount: group.devices.length, warningCount: warnings, criticalCount: criticals, totalEvents, uniqueIps: ips.size, cveTotal: 0, cveCritical, reportHtml: html, summaryJson: JSON.stringify({ deviceCount: group.devices.length, warningCount: warnings, criticalCount: criticals, totalEvents, uniqueIps: ips.size, cveCritical }) } });
}
return output;

View File

@@ -0,0 +1,129 @@
const esc = (value) => String(value ?? '')
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;')
// Numeric entities keep German text intact in every supported mail client.
.replace(/[^\x20-\x7e]/g, (character) => `&#${character.codePointAt(0)};`);
const formatDate = (value) => new Date(value).toLocaleString('de-DE', {
timeZone: 'Europe/Berlin',
dateStyle: 'medium',
timeStyle: 'short'
});
const now = new Date();
const periodEnd = new Date(Date.UTC(now.getUTCFullYear(), now.getUTCMonth(), now.getUTCDate()));
periodEnd.setUTCDate(periodEnd.getUTCDate() - ((periodEnd.getUTCDay() + 6) % 7));
const periodStart = new Date(periodEnd.getTime() - 7 * 86400000);
const groups = new Map();
for (const item of items) {
const payload = item.json.payload || {};
const ninja = payload.NinjaOne || payload.ninjaOne || {};
const organizationId = String(ninja.OrganizationId || ninja.organizationId || 'unknown');
const organizationName = String(ninja.OrganizationName || ninja.organizationName || `Organisation ${organizationId}`);
if (!groups.has(organizationId)) {
groups.set(organizationId, { organizationId, organizationName, devices: [] });
}
groups.get(organizationId).devices.push({
machineName: item.json.machine_name || payload.MachineName || 'Unbekannt',
state: String(item.json.alert_state || payload.AlertState || 'unknown').toLowerCase(),
payload
});
}
const reportItems = [];
for (const group of groups.values()) {
let warningCount = 0;
let criticalCount = 0;
let totalEvents = 0;
let cveTotal = 0;
let cveCritical = 0;
const uniqueIps = new Set();
const alertRows = [];
const cleanRows = [];
for (const device of group.devices.sort((left, right) => left.machineName.localeCompare(right.machineName))) {
if (device.state === 'warning') warningCount++;
if (device.state === 'critical') criticalCount++;
const vulnerabilities = device.payload.VulnerabilityCorrelation || {};
cveTotal += Number(vulnerabilities.TotalCount || 0);
cveCritical += Number(vulnerabilities.CriticalCount || 0);
const events = (device.payload.Events || []).filter((event) => {
const timestamp = new Date(event.Timestamp);
return !Number.isNaN(timestamp) && timestamp >= periodStart && timestamp < periodEnd;
});
totalEvents += events.length;
if (events.length === 0) {
cleanRows.push(`<tr class="clean"><td>${esc(device.machineName)}</td><td colspan="5">Keine sicherheitsrelevanten Ereignisse im Berichtszeitraum.</td><td><span class="badge badge-ok">Sauber</span></td></tr>`);
continue;
}
const groupedEvents = new Map();
for (const event of events) {
const sourceIp = event.SourceIp || '-';
const account = event.Username || '-';
const type = event.Target || 'Sicherheitsereignis';
const key = [type, account, sourceIp].join('|');
const row = groupedEvents.get(key) || { type, account, sourceIp, count: 0, latest: event.Timestamp };
row.count++;
if (new Date(event.Timestamp) > new Date(row.latest)) row.latest = event.Timestamp;
groupedEvents.set(key, row);
if (sourceIp !== '-') uniqueIps.add(sourceIp);
}
for (const event of groupedEvents.values()) {
const severity = device.state === 'critical' ? 'Kritisch' : 'Pruefen';
const badge = device.state === 'critical' ? 'badge-critical' : 'badge-warning';
alertRows.push(`<tr class="alert"><td>${esc(device.machineName)}</td><td>${esc(event.type)}</td><td>${esc(event.account)}</td><td>${esc(formatDate(event.latest))}</td><td>${event.count}</td><td>${esc(event.sourceIp)}</td><td><span class="badge ${badge}">${severity}</span></td></tr>`);
}
}
const summary = {
deviceCount: group.devices.length,
warningCount,
criticalCount,
totalEvents,
uniqueIps: uniqueIps.size,
cveTotal,
cveCritical
};
const riskLabel = criticalCount > 0 ? 'Kritisch' : warningCount > 0 ? 'Beobachten' : 'Unauffaellig';
const riskClass = criticalCount > 0 ? 'risk-critical' : warningCount > 0 ? 'risk-warning' : 'risk-ok';
const rows = alertRows.length > 0 ? `${alertRows.join('')}${cleanRows.join('')}` : cleanRows.join('');
const reportHtml = `<div class="ocsentinel-report">
<style>
.ocsentinel-report{max-width:1180px;margin:0 auto;font-family:Segoe UI,Tahoma,sans-serif;font-size:13px;line-height:1.35;color:#172033;background:#fff}
.ocsentinel-report .header{padding:18px 20px;background:#102a43;color:#fff;border-radius:8px 8px 0 0}
.ocsentinel-report h1{margin:0;font-size:20px;line-height:1.2}.ocsentinel-report .subtitle{margin-top:5px;color:#cbd5e1;font-size:12px}
.ocsentinel-report .risk{float:right;padding:5px 9px;border-radius:999px;font-size:11px;font-weight:700}.ocsentinel-report .risk-ok{background:#d1fae5;color:#065f46}.ocsentinel-report .risk-warning{background:#fef3c7;color:#92400e}.ocsentinel-report .risk-critical{background:#fee2e2;color:#991b1b}
.ocsentinel-report .body{padding:16px 20px 20px;border:1px solid #dbe5ef;border-top:0}.ocsentinel-report .metrics{width:100%;border-collapse:separate;border-spacing:8px 0;margin:0 -8px 15px}.ocsentinel-report .metrics td{width:16.66%;padding:10px;background:#f6f9fc;border:1px solid #dbe5ef;border-radius:5px}.ocsentinel-report .metric-value{display:block;font-size:20px;font-weight:700;color:#102a43}.ocsentinel-report .metric-label{display:block;font-size:10px;color:#526577;text-transform:uppercase;letter-spacing:.04em}
.ocsentinel-report table{width:100%;border-collapse:collapse}.ocsentinel-report th{padding:8px;background:#1d4e89;color:#fff;text-align:left;font-size:11px}.ocsentinel-report td{padding:8px;border-bottom:1px solid #dbe5ef;vertical-align:top}.ocsentinel-report tr.alert{background:#fff8f3}.ocsentinel-report tr.clean{background:#f3fbf6;color:#275b3b}.ocsentinel-report .badge{display:inline-block;padding:3px 6px;border-radius:4px;font-size:10px;font-weight:700}.ocsentinel-report .badge-ok{background:#d1fae5;color:#065f46}.ocsentinel-report .badge-warning{background:#fef3c7;color:#92400e}.ocsentinel-report .badge-critical{background:#fee2e2;color:#991b1b}.ocsentinel-report .footer{margin-top:14px;color:#64748b;font-size:10px;text-align:right}
</style>
<div class="header"><span class="risk ${riskClass}">${riskLabel}</span><h1>OfficeCom Sentinel Sicherheitsbericht</h1><div class="subtitle">${esc(group.organizationName)} | ${esc(periodStart.toLocaleDateString('de-DE'))} bis ${esc(periodEnd.toLocaleDateString('de-DE'))}</div></div>
<div class="body"><table class="metrics"><tr><td><span class="metric-value">${summary.deviceCount}</span><span class="metric-label">Ger&auml;te</span></td><td><span class="metric-value">${summary.criticalCount}</span><span class="metric-label">Kritisch</span></td><td><span class="metric-value">${summary.warningCount}</span><span class="metric-label">Warnungen</span></td><td><span class="metric-value">${summary.totalEvents}</span><span class="metric-label">Ereignisse</span></td><td><span class="metric-value">${summary.uniqueIps}</span><span class="metric-label">Quell-IP-Adressen</span></td><td><span class="metric-value">${summary.cveCritical}</span><span class="metric-label">Kritische CVEs</span></td></tr></table>
<table><thead><tr><th>System</th><th>Vorfall</th><th>Konto</th><th>Letzter Zeitpunkt</th><th>Anzahl</th><th>Quell-IP</th><th>Bewertung</th></tr></thead><tbody>${rows}</tbody></table><div class="footer">Automatisch erstellt am ${esc(formatDate(now))} durch OfficeCom Sentinel.</div></div></div>`;
reportItems.push({
json: {
organizationId: group.organizationId,
organizationName: group.organizationName,
periodStartUtc: periodStart.toISOString(),
periodEndUtc: periodEnd.toISOString(),
...summary,
reportHtml,
summaryJson: JSON.stringify(summary)
}
});
}
return reportItems;

View File

@@ -0,0 +1,41 @@
const esc = (value) => String(value ?? '')
.replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;')
.replace(/"/g, '&quot;').replace(/'/g, '&#39;')
.replace(/[^\x20-\x7e]/g, (character) => `&#${character.codePointAt(0)};`);
const now = new Date();
const end = new Date(Date.UTC(now.getUTCFullYear(), now.getUTCMonth(), now.getUTCDate()));
end.setUTCDate(end.getUTCDate() - ((end.getUTCDay() + 6) % 7));
const start = new Date(end.getTime() - 7 * 86400000);
const formatDate = (value) => new Date(value).toLocaleString('de-DE', { timeZone: 'Europe/Berlin', dateStyle: 'medium', timeStyle: 'short' });
const groups = new Map();
for (const item of items) {
const payload = item.json.payload || {}, ninja = payload.NinjaOne || payload.ninjaOne || {};
const id = String(ninja.OrganizationId || ninja.organizationId || 'unknown');
if (!groups.has(id)) groups.set(id, { id, name: String(ninja.OrganizationName || ninja.organizationName || `Organisation ${id}`), devices: [] });
groups.get(id).devices.push({ name: item.json.machine_name || payload.MachineName || 'Unbekannt', state: String(item.json.alert_state || payload.AlertState || 'unknown').toLowerCase(), payload });
}
const output = [];
for (const group of groups.values()) {
let warnings = 0, criticals = 0, totalEvents = 0, cveCritical = 0;
const ips = new Set(), rows = [];
for (const device of group.devices.sort((a, b) => a.name.localeCompare(b.name))) {
if (device.state === 'warning') warnings++;
if (device.state === 'critical') criticals++;
cveCritical += Number((device.payload.VulnerabilityCorrelation || {}).CriticalCount || 0);
const events = (device.payload.Events || []).filter((event) => { const timestamp = new Date(event.Timestamp); return !Number.isNaN(timestamp) && timestamp >= start && timestamp < end; });
totalEvents += events.length;
if (!events.length) { rows.push(`<tr bgcolor="#f0fdf4"><td style="padding:8px;border-bottom:1px solid #dbe5ef;font-family:Arial,sans-serif;font-size:12px">${esc(device.name)}</td><td colspan="5" style="padding:8px;border-bottom:1px solid #dbe5ef;font-family:Arial,sans-serif;font-size:12px;color:#166534">Keine sicherheitsrelevanten Ereignisse im Berichtszeitraum.</td><td style="padding:8px;border-bottom:1px solid #dbe5ef;font-family:Arial,sans-serif;font-size:12px;color:#166534"><b>Sauber</b></td></tr>`); continue; }
const grouped = new Map();
for (const event of events) {
const ip = event.SourceIp || '-', account = event.Username || '-', type = event.Target || 'Sicherheitsereignis', key = [type, account, ip].join('|');
const entry = grouped.get(key) || { ip, account, type, count: 0, latest: event.Timestamp };
entry.count++; if (new Date(event.Timestamp) > new Date(entry.latest)) entry.latest = event.Timestamp; grouped.set(key, entry); if (ip !== '-') ips.add(ip);
}
for (const event of grouped.values()) { const critical = device.state === 'critical'; rows.push(`<tr bgcolor="#fff7ed"><td style="padding:8px;border-bottom:1px solid #fed7aa;font-family:Arial,sans-serif;font-size:12px">${esc(device.name)}</td><td style="padding:8px;border-bottom:1px solid #fed7aa;font-family:Arial,sans-serif;font-size:12px">${esc(event.type)}</td><td style="padding:8px;border-bottom:1px solid #fed7aa;font-family:Arial,sans-serif;font-size:12px">${esc(event.account)}</td><td style="padding:8px;border-bottom:1px solid #fed7aa;font-family:Arial,sans-serif;font-size:12px">${esc(formatDate(event.latest))}</td><td style="padding:8px;border-bottom:1px solid #fed7aa;font-family:Arial,sans-serif;font-size:12px">${event.count}</td><td style="padding:8px;border-bottom:1px solid #fed7aa;font-family:Arial,sans-serif;font-size:12px">${esc(event.ip)}</td><td style="padding:8px;border-bottom:1px solid #fed7aa;font-family:Arial,sans-serif;font-size:12px;color:${critical ? '#991b1b' : '#92400e'}"><b>${critical ? 'Kritisch' : 'Pruefen'}</b></td></tr>`); }
}
const risk = criticals ? ['Kritisch', '#991b1b', '#fee2e2'] : warnings ? ['Beobachten', '#92400e', '#fef3c7'] : ['Unauffaellig', '#166534', '#dcfce7'];
const metric = (value, label) => `<td width="16.66%" valign="top" style="padding:10px;background:#f8fafc;border:1px solid #dbe5ef;font-family:Arial,sans-serif"><b style="font-size:20px;color:#102a43">${value}</b><br><span style="font-size:10px;color:#526577">${label}</span></td>`;
const html = `<table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="max-width:1100px;border-collapse:collapse"><tr><td style="padding:18px 20px;background:#102a43"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0"><tr><td valign="top" style="font-family:Arial,sans-serif;color:#ffffff"><h2 style="margin:0;font-size:20px;color:#ffffff">OfficeCom Sentinel Sicherheitsbericht</h2><p style="margin:6px 0 0;color:#d5e2ee;font-size:12px">${esc(group.name)} | ${esc(start.toLocaleDateString('de-DE'))} bis ${esc(end.toLocaleDateString('de-DE'))}</p></td><td width="100" align="right" valign="top" style="font-family:Arial,sans-serif"><span style="display:inline-block;padding:5px 9px;background:${risk[2]};color:${risk[1]};font-size:11px"><b>${risk[0]}</b></span></td></tr></table></td></tr><tr><td style="padding:16px 20px;border:1px solid #dbe5ef"><table role="presentation" width="100%" cellspacing="6" cellpadding="0" border="0"><tr>${metric(group.devices.length, 'Ger&auml;te')}${metric(criticals, 'Kritisch')}${metric(warnings, 'Warnungen')}${metric(totalEvents, 'Ereignisse')}${metric(ips.size, 'Quell-IP-Adressen')}${metric(cveCritical, 'Kritische CVEs')}</tr></table><table width="100%" cellspacing="0" cellpadding="0" border="0" style="border-collapse:collapse"><thead><tr bgcolor="#1d4e89"><th align="left" style="padding:8px;color:#fff;font-family:Arial,sans-serif;font-size:11px">System</th><th align="left" style="padding:8px;color:#fff;font-family:Arial,sans-serif;font-size:11px">Vorfall</th><th align="left" style="padding:8px;color:#fff;font-family:Arial,sans-serif;font-size:11px">Konto</th><th align="left" style="padding:8px;color:#fff;font-family:Arial,sans-serif;font-size:11px">Letzter Zeitpunkt</th><th align="left" style="padding:8px;color:#fff;font-family:Arial,sans-serif;font-size:11px">Anzahl</th><th align="left" style="padding:8px;color:#fff;font-family:Arial,sans-serif;font-size:11px">Quell-IP</th><th align="left" style="padding:8px;color:#fff;font-family:Arial,sans-serif;font-size:11px">Bewertung</th></tr></thead><tbody>${rows.join('')}</tbody></table><p style="margin:14px 0 0;text-align:right;color:#64748b;font-family:Arial,sans-serif;font-size:10px">Automatisch erstellt am ${esc(formatDate(now))} durch OfficeCom Sentinel.</p></td></tr></table>`;
output.push({ json: { organizationId: group.id, organizationName: group.name, periodStartUtc: start.toISOString(), periodEndUtc: end.toISOString(), deviceCount: group.devices.length, warningCount: warnings, criticalCount: criticals, totalEvents, uniqueIps: ips.size, cveTotal: 0, cveCritical, reportHtml: html, summaryJson: JSON.stringify({ deviceCount: group.devices.length, warningCount: warnings, criticalCount: criticals, totalEvents, uniqueIps: ips.size, cveCritical }) } });
}
return output;

View File

@@ -47,6 +47,28 @@ CREATE TABLE IF NOT EXISTS ocsentinel.ingest_nonce (
CREATE INDEX IF NOT EXISTS ix_ocsentinel_ingest_nonce_expires
ON ocsentinel.ingest_nonce (expires_at);
CREATE TABLE IF NOT EXISTS ocsentinel.weekly_organization_report (
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
organization_id TEXT NOT NULL,
organization_name TEXT NOT NULL,
period_start_utc TIMESTAMPTZ NOT NULL,
period_end_utc TIMESTAMPTZ NOT NULL,
generated_at TIMESTAMPTZ NOT NULL DEFAULT now(),
device_count INTEGER NOT NULL DEFAULT 0,
warning_count INTEGER NOT NULL DEFAULT 0,
critical_count INTEGER NOT NULL DEFAULT 0,
total_events INTEGER NOT NULL DEFAULT 0,
unique_ips INTEGER NOT NULL DEFAULT 0,
cve_total INTEGER NOT NULL DEFAULT 0,
cve_critical INTEGER NOT NULL DEFAULT 0,
report_html TEXT NOT NULL,
summary JSONB NOT NULL DEFAULT '{}'::jsonb,
UNIQUE (organization_id, period_start_utc)
);
CREATE INDEX IF NOT EXISTS ix_ocsentinel_weekly_report_organization_generated
ON ocsentinel.weekly_organization_report (organization_id, generated_at DESC);
CREATE OR REPLACE VIEW ocsentinel.current_device_status AS
SELECT DISTINCT ON (d.id)
d.machine_name,

View File

@@ -0,0 +1,25 @@
-- Central recipient rules for OCSentinel weekly organization reports.
-- The '*' organization ID applies to every organization.
BEGIN;
CREATE TABLE IF NOT EXISTS ocsentinel.organization_report_recipient (
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
organization_id TEXT NOT NULL,
organization_name TEXT NOT NULL,
recipient_email TEXT NOT NULL,
enabled BOOLEAN NOT NULL DEFAULT TRUE,
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
UNIQUE (organization_id, recipient_email)
);
INSERT INTO ocsentinel.organization_report_recipient
(organization_id, organization_name, recipient_email)
VALUES
('*', 'Alle Organisationen', 'lg@officecom.it'),
('*', 'Alle Organisationen', 'rk@officecom.biz'),
('9', 'Mildenberger Verlag', 'dd@officecom.it'),
('16', 'Kirsch GmbH', 'dd@officecom.it')
ON CONFLICT (organization_id, recipient_email) DO NOTHING;
COMMIT;

View File

@@ -32,6 +32,7 @@ if (Test-Path (Join-Path $packageRoot "config\ocsentinel-client.dev.example.json
Copy-Item -Path (Join-Path $packageRoot "samples\ninja-vulnerability-export.example.csv") -Destination (Join-Path $samplesRoot "ninja-vulnerability-export.example.csv") -Force
Copy-Item -Path (Join-Path $packageRoot "scripts\run-ocsentinel.ps1") -Destination $scriptRoot -Force
Copy-Item -Path (Join-Path $packageRoot "scripts\run-ocsentinel-monitor.ps1") -Destination $scriptRoot -Force
Copy-Item -Path (Join-Path $packageRoot "scripts\run-ocsentinel-scheduled.ps1") -Destination $scriptRoot -Force
if (Test-Path (Join-Path $packageRoot "scripts\protect-ocsentinel-secret.ps1")) {
Copy-Item -Path (Join-Path $packageRoot "scripts\protect-ocsentinel-secret.ps1") -Destination $scriptRoot -Force
}
@@ -69,8 +70,34 @@ Set-ItemProperty -Path $uninstallKey -Name "QuietUninstallString" -Value $uninst
Set-ItemProperty -Path $uninstallKey -Name "NoModify" -Value 1 -Type DWord
Set-ItemProperty -Path $uninstallKey -Name "NoRepair" -Value 1 -Type DWord
$scheduledScript = Join-Path $scriptRoot "run-ocsentinel-scheduled.ps1"
$taskPrincipal = New-ScheduledTaskPrincipal -UserId "SYSTEM" -LogonType ServiceAccount -RunLevel Highest
$taskSettings = New-ScheduledTaskSettingsSet -StartWhenAvailable -ExecutionTimeLimit (New-TimeSpan -Minutes 30) -MultipleInstances IgnoreNew
# Spread fleet uploads across the early-morning window while keeping each device's slot stable.
$machineGuid = (Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Cryptography" -Name "MachineGuid").MachineGuid
$guidBytes = [Text.Encoding]::UTF8.GetBytes([string]$machineGuid)
$sha256 = [Security.Cryptography.SHA256]::Create()
try {
$slotHash = $sha256.ComputeHash($guidBytes)
}
finally {
$sha256.Dispose()
}
$dailySlotMinutes = [BitConverter]::ToUInt32($slotHash, 0) % 180
$dailyRunAt = (Get-Date -Hour 4 -Minute 0 -Second 0).AddMinutes($dailySlotMinutes)
$dailyAction = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-NoProfile -ExecutionPolicy Bypass -File `"$scheduledScript`" -Kind daily" -WorkingDirectory $scriptRoot
$dailyTrigger = New-ScheduledTaskTrigger -Daily -At $dailyRunAt
Register-ScheduledTask -TaskName "OCSentinel Daily Scan" -Action $dailyAction -Trigger $dailyTrigger -Principal $taskPrincipal -Settings $taskSettings -Description "OfficeCom Sentinel daily signed scan and upload." -Force | Out-Null
$burstAction = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-NoProfile -ExecutionPolicy Bypass -File `"$scheduledScript`" -Kind burst" -WorkingDirectory $scriptRoot
$burstTrigger = New-ScheduledTaskTrigger -Once -At (Get-Date).AddMinutes(2) -RepetitionInterval (New-TimeSpan -Minutes 5) -RepetitionDuration (New-TimeSpan -Days 3650)
Register-ScheduledTask -TaskName "OCSentinel Burst Check" -Action $burstAction -Trigger $burstTrigger -Principal $taskPrincipal -Settings $taskSettings -Description "OfficeCom Sentinel burst check; scans only when Ninja field ocsentinelburst is enabled." -Force | Out-Null
Write-Host "Installation complete."
Write-Host "Main path: $installRoot"
Write-Host "Runner: $(Join-Path $scriptRoot 'run-ocsentinel.ps1')"
Write-Host "Monitor: $(Join-Path $scriptRoot 'run-ocsentinel-monitor.ps1')"
Write-Host "Updater: $(Join-Path $scriptRoot 'update-ocsentinel.ps1')"
Write-Host "Schedule: Daily scan at $($dailyRunAt.ToString('HH:mm')) (deterministic 04:00-06:59 slot); burst check every 5 minutes."

View File

@@ -9,6 +9,7 @@ param(
[string]$UploadMode = "auto",
[string]$VulnerabilityCsvPath = "",
[string]$MirrorRoot = "",
[switch]$SuppressTriggerExit,
[ValidateSet("status", "attack-only", "cve-critical", "attack-plus-cve")]
[string]$Mode = "status"
)
@@ -46,8 +47,13 @@ function Initialize-NinjaFieldWriter {
return
}
if (Get-Command -Name "Set-NinjaProperty" -ErrorAction SilentlyContinue) {
$script:NinjaFieldBackend = "powershell-modern"
return
}
if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) {
$script:NinjaFieldBackend = "powershell"
$script:NinjaFieldBackend = "powershell-legacy"
return
}
@@ -64,14 +70,20 @@ function Set-NinjaCustomFieldValue {
[Parameter(Mandatory)]
[string]$Name,
[AllowEmptyString()]
[string]$Value
[object]$Value,
[Parameter(Mandatory)]
[string]$Type
)
Initialize-NinjaFieldWriter
switch ($script:NinjaFieldBackend) {
"powershell" {
Ninja-Property-Set $Name $Value | Out-Null
"powershell-modern" {
Set-NinjaProperty -Name $Name -Value $Value -Type $Type -Force | Out-Null
return $true
}
"powershell-legacy" {
Ninja-Property-Set -Name $Name -Value $Value | Out-Null
return $true
}
"cli" {
@@ -112,28 +124,43 @@ function Publish-NinjaCustomFields {
}
}
$fieldValues = [ordered]@{
"ocsentinelstatus" = [string]$Report.AlertState
"ocsentinelreason" = $Reason
"ocsentinelbasestatus" = [string]$Report.BaseAlertState
"ocsentinelevents" = [string]([int]$Report.TotalEvents)
"ocsentineluniqueips" = [string]([int]$Report.UniqueIpCount)
"ocsentinelcvecritical" = [string]([int]$Report.VulnerabilityCorrelation.CriticalCount)
"ocsentinelcvetotal" = [string]([int]$Report.VulnerabilityCorrelation.TotalCount)
"ocsentinelmode" = $Mode
"ocsentineltriggered" = $Triggered.ToString().ToLowerInvariant()
"ocsentinellastscanutc" = $generatedAtUtc
$uploadStatus = [string]$Report.Runtime.UploadStatus
if ([string]::IsNullOrWhiteSpace($uploadStatus)) { $uploadStatus = "unknown" }
$queuedReports = [int]$Report.Runtime.QueuedReportCount
$lastUploadUtc = ""
if ($Report.Runtime.LastSuccessfulUploadUtc) {
try { $lastUploadUtc = ([DateTimeOffset]$Report.Runtime.LastSuccessfulUploadUtc).ToUniversalTime().ToString("o") } catch { $lastUploadUtc = [string]$Report.Runtime.LastSuccessfulUploadUtc }
}
$lastUploadError = [string]$Report.Runtime.LastUploadError
if ($lastUploadError.Length -gt 900) { $lastUploadError = $lastUploadError.Substring(0, 900) }
$fieldValues = @(
[pscustomobject]@{ Name = "ocsentinelstatus"; Type = "Text"; Value = [string]$Report.AlertState }
[pscustomobject]@{ Name = "ocsentinelreason"; Type = "Text"; Value = $Reason }
[pscustomobject]@{ Name = "ocsentinelbasestatus"; Type = "Text"; Value = [string]$Report.BaseAlertState }
[pscustomobject]@{ Name = "ocsentinelevents"; Type = "Integer"; Value = [int]$Report.TotalEvents }
[pscustomobject]@{ Name = "ocsentineluniqueips"; Type = "Integer"; Value = [int]$Report.UniqueIpCount }
[pscustomobject]@{ Name = "ocsentinelcvecritical"; Type = "Integer"; Value = [int]$Report.VulnerabilityCorrelation.CriticalCount }
[pscustomobject]@{ Name = "ocsentinelcvetotal"; Type = "Integer"; Value = [int]$Report.VulnerabilityCorrelation.TotalCount }
[pscustomobject]@{ Name = "ocsentinelmode"; Type = "Text"; Value = $Mode }
[pscustomobject]@{ Name = "ocsentineltriggered"; Type = "Checkbox"; Value = $Triggered }
[pscustomobject]@{ Name = "ocsentinellastscanutc"; Type = "DateTime"; Value = $generatedAtUtc }
[pscustomobject]@{ Name = "ocsentineluploadstatus"; Type = "Text"; Value = $uploadStatus }
[pscustomobject]@{ Name = "ocsentinelqueuedreports"; Type = "Integer"; Value = $queuedReports }
[pscustomobject]@{ Name = "ocsentinellastuploadutc"; Type = "DateTime"; Value = $lastUploadUtc }
[pscustomobject]@{ Name = "ocsentinellasterror"; Type = "Text"; Value = $lastUploadError }
[pscustomobject]@{ Name = "ocsentinelclientversion"; Type = "Text"; Value = [string]$Report.ClientVersion }
)
$updated = 0
foreach ($entry in $fieldValues.GetEnumerator()) {
foreach ($entry in $fieldValues) {
try {
if (Set-NinjaCustomFieldValue -Name $entry.Key -Value $entry.Value) {
if (Set-NinjaCustomFieldValue -Name $entry.Name -Value $entry.Value -Type $entry.Type) {
$updated++
}
}
catch {
Write-Warning "Failed to set Ninja custom field '$($entry.Key)': $($_.Exception.Message)"
Write-Warning "Failed to set Ninja custom field '$($entry.Name)': $($_.Exception.Message)"
}
}
@@ -178,6 +205,8 @@ $events = [int]$report.TotalEvents
$uniqueIps = [int]$report.UniqueIpCount
$criticalCves = [int]$report.VulnerabilityCorrelation.CriticalCount
$totalCves = [int]$report.VulnerabilityCorrelation.TotalCount
$uploadStatus = [string]$report.Runtime.UploadStatus
$queuedReports = [int]$report.Runtime.QueuedReportCount
$monitorTriggered = $false
$monitorReason = ""
@@ -213,11 +242,13 @@ Write-Host "Events: $events"
Write-Host "Unique IPs: $uniqueIps"
Write-Host "Critical/High CVEs: $criticalCves"
Write-Host "Total CVEs: $totalCves"
Write-Host "Upload status: $uploadStatus"
Write-Host "Queued reports: $queuedReports"
Write-Host "Report: $outputFullPath"
Write-Host "Runner exit code: $runnerExitCode"
if ($monitorTriggered) {
if ($monitorTriggered -and -not $SuppressTriggerExit) {
exit 1
}
exit 0
exit $runnerExitCode

View File

@@ -0,0 +1,116 @@
[CmdletBinding()]
param(
[ValidateSet("daily", "burst")]
[string]$Kind = "daily",
[ValidateRange(15, 480)]
[int]$BurstDurationMinutes = 120
)
$ErrorActionPreference = "Stop"
$scriptDir = Split-Path -Parent $MyInvocation.MyCommand.Path
$monitorScript = Join-Path $scriptDir "run-ocsentinel-monitor.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
$mutexName = "Global\OfficeComSentinelScan"
function Get-NinjaBurstEnabled {
if (Get-Command -Name "Get-NinjaProperty" -ErrorAction SilentlyContinue) {
return [bool](Get-NinjaProperty -Name "ocsentinelburst" -Type "Checkbox")
}
if (Get-Command -Name "Ninja-Property-Get" -ErrorAction SilentlyContinue) {
$value = Ninja-Property-Get -Name "ocsentinelburst"
return [string]$value -match "^(1|true|yes)$"
}
Write-Warning "Ninja custom-field reader is unavailable; burst scan skipped."
return $false
}
function Get-NinjaValue {
param([Parameter(Mandatory)][string]$Name, [Parameter(Mandatory)][string]$Type)
try {
if (Get-Command -Name "Get-NinjaProperty" -ErrorAction SilentlyContinue) {
return Get-NinjaProperty -Name $Name -Type $Type
}
if (Get-Command -Name "Ninja-Property-Get" -ErrorAction SilentlyContinue) {
return Ninja-Property-Get -Name $Name
}
}
catch {
Write-Warning "Could not read Ninja field '$Name': $($_.Exception.Message)"
}
return $null
}
function Set-NinjaValue {
param([Parameter(Mandatory)][string]$Name, [AllowEmptyString()][string]$Value, [Parameter(Mandatory)][string]$Type)
try {
if (Get-Command -Name "Set-NinjaProperty" -ErrorAction SilentlyContinue) {
Set-NinjaProperty -Name $Name -Value $Value -Type $Type -Force | Out-Null
return $true
}
if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) {
Ninja-Property-Set -Name $Name -Value $Value | Out-Null
return $true
}
}
catch {
Write-Warning "Could not update Ninja field '$Name': $($_.Exception.Message)"
}
return $false
}
if ($Kind -eq "burst") {
if (-not (Get-NinjaBurstEnabled)) {
Set-NinjaValue -Name "ocsentinelburststatus" -Value "idle" -Type "Text" | Out-Null
Write-Host "OfficeCom Sentinel burst check: disabled."
exit 0
}
$now = [DateTimeOffset]::UtcNow
$untilValue = Get-NinjaValue -Name "ocsentinelburstuntilutc" -Type "DateTime"
$until = $null
if (-not [string]::IsNullOrWhiteSpace([string]$untilValue)) {
try { $until = [DateTimeOffset]$untilValue } catch { Write-Warning "Burst end time is invalid and will be restarted." }
}
if ($null -eq $until) {
$until = $now.AddMinutes($BurstDurationMinutes)
Set-NinjaValue -Name "ocsentinelburstuntilutc" -Value $until.ToString("o") -Type "DateTime" | Out-Null
Write-Host "OfficeCom Sentinel burst window started until $($until.ToString('u'))."
}
elseif ($until -le $now) {
Set-NinjaValue -Name "ocsentinelburst" -Value "false" -Type "Checkbox" | Out-Null
Set-NinjaValue -Name "ocsentinelburststatus" -Value "completed" -Type "Text" | Out-Null
Write-Host "OfficeCom Sentinel burst window completed and was disabled."
exit 0
}
Set-NinjaValue -Name "ocsentinelburststatus" -Value "active until $($until.ToUniversalTime().ToString('o'))" -Type "Text" | Out-Null
}
$createdNew = $false
$mutex = [Threading.Mutex]::new($false, $mutexName, [ref]$createdNew)
try {
if (-not $mutex.WaitOne(0)) {
Write-Host "OfficeCom Sentinel scan skipped: another scan is already running."
exit 0
}
Write-Host "OfficeCom Sentinel scheduled $Kind scan started."
$monitorArgs = @("-NoProfile", "-ExecutionPolicy", "Bypass", "-File", $monitorScript, "-Mode", "status", "-UploadMode", "required", "-SecretPath", $secretPath, "-SuppressTriggerExit")
if ($Kind -eq "burst") {
$monitorArgs += @("-LookbackDays", "1", "-TopCount", "25")
}
& powershell.exe @monitorArgs
exit $LASTEXITCODE
}
finally {
if ($null -ne $mutex) {
try { $mutex.ReleaseMutex() } catch { }
$mutex.Dispose()
}
}

View File

@@ -39,6 +39,40 @@ function Resolve-PathLike {
return [System.IO.Path]::GetFullPath((Join-Path $BasePath $PathValue))
}
function Restore-NinjaContextFromClientConfiguration {
param([Parameter(Mandatory)][string]$Path)
if (-not (Test-Path -LiteralPath $Path)) {
return
}
try {
$clientConfiguration = Get-Content -LiteralPath $Path -Raw | ConvertFrom-Json
$mappings = @(
@{ EnvironmentName = "NINJA_ORGANIZATION_ID"; PropertyName = "ninjaOrganizationId" },
@{ EnvironmentName = "NINJA_ORGANIZATION_NAME"; PropertyName = "ninjaOrganizationName" },
@{ EnvironmentName = "NINJA_AGENT_MACHINE_ID"; PropertyName = "ninjaMachineId" },
@{ EnvironmentName = "NINJA_AGENT_NODE_ID"; PropertyName = "ninjaNodeId" },
@{ EnvironmentName = "NINJA_LOCATION_ID"; PropertyName = "ninjaLocationId" },
@{ EnvironmentName = "NINJA_LOCATION_NAME"; PropertyName = "ninjaLocationName" }
)
foreach ($mapping in $mappings) {
if (-not [string]::IsNullOrWhiteSpace([Environment]::GetEnvironmentVariable($mapping.EnvironmentName, "Process"))) {
continue
}
$value = [string]$clientConfiguration.($mapping.PropertyName)
if (-not [string]::IsNullOrWhiteSpace($value)) {
[Environment]::SetEnvironmentVariable($mapping.EnvironmentName, $value, "Process")
}
}
}
catch {
Write-Warning "Could not restore stored NinjaOne context: $($_.Exception.Message)"
}
}
if (-not (Test-Path $appExe)) {
throw "Application executable not found: $appExe"
}
@@ -54,6 +88,8 @@ else {
$secretFullPath = if ([string]::IsNullOrWhiteSpace($SecretPath)) { "" } else { Resolve-PathLike -PathValue $SecretPath -BasePath $scriptDir }
$canUpload = (Test-Path $clientConfigFullPath) -and (-not [string]::IsNullOrWhiteSpace($secretFullPath)) -and (Test-Path $secretFullPath)
Restore-NinjaContextFromClientConfiguration -Path $clientConfigFullPath
if ($UploadMode -eq "required" -and -not $canUpload) {
throw "UploadMode 'required' was set, but client config or protected secret is missing."
}

View File

@@ -5,6 +5,12 @@ $ErrorActionPreference = "Stop"
$installRoot = Join-Path ${env:ProgramFiles} "OCSentinel"
$uninstallKey = "HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\OCSentinel"
foreach ($taskName in @("OCSentinel Daily Scan", "OCSentinel Burst Check")) {
if (Get-ScheduledTask -TaskName $taskName -ErrorAction SilentlyContinue) {
Unregister-ScheduledTask -TaskName $taskName -Confirm:$false
}
}
if (Test-Path $uninstallKey) {
Remove-Item -Path $uninstallKey -Force -Recurse
}

View File

@@ -7,6 +7,72 @@ param(
$ErrorActionPreference = "Stop"
function Initialize-OCSentinelTls {
$protocols = [Net.SecurityProtocolType]::Tls12
if ([Enum]::GetNames([Net.SecurityProtocolType]) -contains "Tls13") {
$protocols = $protocols -bor [Net.SecurityProtocolType]::Tls13
}
[Net.ServicePointManager]::SecurityProtocol = $protocols
[Net.ServicePointManager]::Expect100Continue = $false
}
function Get-OCSentinelManifest {
param([Parameter(Mandatory)][string]$Uri)
$parameters = @{ Method = "Get"; Uri = $Uri; TimeoutSec = 60 }
if ((Get-Command Invoke-RestMethod).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
return Invoke-RestMethod @parameters
}
catch {
if ($attempt -eq 3) {
throw "Could not retrieve the OCSentinel release manifest after 3 attempts. Verify that the device can reach gitea.officecom.cloud with TLS 1.2 or newer. Last error: $($_.Exception.Message)"
}
Start-Sleep -Seconds (3 * $attempt)
}
}
}
function Get-OCSentinelArtifact {
param(
[Parameter(Mandatory)][string]$Uri,
[Parameter(Mandatory)][string]$DestinationPath
)
$parameters = @{ Uri = $Uri; OutFile = $DestinationPath; TimeoutSec = 300 }
if ((Get-Command Invoke-WebRequest).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
Remove-Item -LiteralPath $DestinationPath -Force -ErrorAction SilentlyContinue
Invoke-WebRequest @parameters
if (-not (Test-Path -LiteralPath $DestinationPath) -or (Get-Item -LiteralPath $DestinationPath).Length -eq 0) {
throw "The downloaded artifact is empty."
}
return
}
catch {
if ($attempt -eq 3) {
throw "Could not download the OCSentinel package after 3 attempts. Last error: $($_.Exception.Message)"
}
Write-Warning "Package download attempt $attempt failed. Retrying."
Start-Sleep -Seconds (5 * $attempt)
}
}
}
Initialize-OCSentinelTls
$installRoot = Join-Path ${env:ProgramFiles} "OCSentinel"
$appExe = Join-Path $installRoot "app\OCSentinelCli.exe"
$installScript = Join-Path $installRoot "scripts\install-ocsentinel.ps1"
@@ -66,7 +132,7 @@ if ([string]::IsNullOrWhiteSpace($ManifestUrl)) {
$resolvedManifestUrl = Resolve-ManifestUrl -ManifestUrl $ManifestUrl -Channel $Channel
Write-Host "Checking update manifest: $resolvedManifestUrl"
$manifest = Invoke-RestMethod -Method Get -Uri $resolvedManifestUrl -TimeoutSec 60
$manifest = Get-OCSentinelManifest -Uri $resolvedManifestUrl
if (-not $manifest.version -or -not $manifest.artifactUrl -or -not $manifest.sha256) {
throw "Update manifest is missing required fields: version, artifactUrl, sha256."
}
@@ -89,7 +155,7 @@ $extractRoot = Join-Path $downloadRoot "payload"
New-Item -ItemType Directory -Force -Path $downloadRoot, $extractRoot | Out-Null
Write-Host "Downloading artifact: $($manifest.artifactUrl)"
Invoke-WebRequest -Uri ([string]$manifest.artifactUrl) -OutFile $zipPath -TimeoutSec 300
Get-OCSentinelArtifact -Uri ([string]$manifest.artifactUrl) -DestinationPath $zipPath
$actualHash = Get-Sha256Hex -Path $zipPath
$expectedHash = ([string]$manifest.sha256).ToLowerInvariant()

View File

@@ -1,8 +1,8 @@
{
"channel": "stable",
"version": "1.2.6",
"publishedAtUtc": "2026-07-25T00:00:00Z",
"artifactUrl": "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.2.6/OCSentinelClient-win-x64.zip",
"sha256": "d6256f3e376701bff18d9dfd8d5825498e85fb6d94c15227828a50678693d097",
"version": "1.3.7",
"publishedAtUtc": "2026-07-27T09:14:02.6006737Z",
"artifactUrl": "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.3.7/OCSentinelClient-win-x64.zip",
"sha256": "8afdb5e8874e06c56047c32bed58f8593fd30928ddc004b39f4abae83d1d29e9",
"minUpdaterVersion": "1.0.0"
}

View File

@@ -8,7 +8,109 @@ param(
$ErrorActionPreference = "Stop"
$ProgressPreference = "SilentlyContinue"
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
function Initialize-OCSentinelTls {
$protocols = [Net.SecurityProtocolType]::Tls12
if ([Enum]::GetNames([Net.SecurityProtocolType]) -contains "Tls13") {
$protocols = $protocols -bor [Net.SecurityProtocolType]::Tls13
}
[Net.ServicePointManager]::SecurityProtocol = $protocols
[Net.ServicePointManager]::Expect100Continue = $false
}
function Get-OCSentinelManifest {
param([Parameter(Mandatory)][string]$Uri)
$parameters = @{ Method = "Get"; Uri = $Uri; TimeoutSec = 60 }
if ((Get-Command Invoke-RestMethod).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
return Invoke-RestMethod @parameters
}
catch {
if ($attempt -eq 3) {
throw "Could not retrieve the OCSentinel release manifest after 3 attempts. Verify that the device can reach gitea.officecom.cloud with TLS 1.2 or newer. Last error: $($_.Exception.Message)"
}
Start-Sleep -Seconds (3 * $attempt)
}
}
}
function Invoke-OCSentinelUpdater {
param(
[Parameter(Mandatory)][string]$UpdaterPath,
[Parameter(Mandatory)][string]$ManifestUri
)
# Existing clients can still contain an older updater without TLS setup.
# Start it in a prepared child process so it can download the current package.
$escapedUpdaterPath = $UpdaterPath.Replace("'", "''")
$escapedManifestUri = $ManifestUri.Replace("'", "''")
$command = @"
`$protocols = [Net.SecurityProtocolType]::Tls12
if ([Enum]::GetNames([Net.SecurityProtocolType]) -contains 'Tls13') {
`$protocols = `$protocols -bor [Net.SecurityProtocolType]::Tls13
}
[Net.ServicePointManager]::SecurityProtocol = `$protocols
[Net.ServicePointManager]::Expect100Continue = `$false
& '$escapedUpdaterPath' -ManifestUrl '$escapedManifestUri'
exit `$LASTEXITCODE
"@
for ($attempt = 1; $attempt -le 3; $attempt++) {
& powershell.exe -NoProfile -ExecutionPolicy Bypass -Command $command | ForEach-Object { Write-Host $_ }
$exitCode = $LASTEXITCODE
if ($exitCode -eq 0) {
return
}
if ($attempt -lt 3) {
Write-Warning "OCSentinel update attempt $attempt failed. Retrying."
Start-Sleep -Seconds (5 * $attempt)
}
}
throw "OCSentinel updater exited with code $exitCode after 3 attempts."
}
function Get-OCSentinelArtifact {
param(
[Parameter(Mandatory)][string]$Uri,
[Parameter(Mandatory)][string]$DestinationPath
)
$parameters = @{ Uri = $Uri; OutFile = $DestinationPath; TimeoutSec = 300 }
if ((Get-Command Invoke-WebRequest).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
Remove-Item -LiteralPath $DestinationPath -Force -ErrorAction SilentlyContinue
Invoke-WebRequest @parameters
if (-not (Test-Path -LiteralPath $DestinationPath) -or (Get-Item -LiteralPath $DestinationPath).Length -eq 0) {
throw "The downloaded artifact is empty."
}
return
}
catch {
if ($attempt -eq 3) {
throw "Could not download the OCSentinel package after 3 attempts. Last error: $($_.Exception.Message)"
}
Write-Warning "Package download attempt $attempt failed. Retrying."
Start-Sleep -Seconds (5 * $attempt)
}
}
}
Initialize-OCSentinelTls
$installRoot = Join-Path $env:ProgramFiles "OCSentinel"
$updaterPath = Join-Path $installRoot "scripts\update-ocsentinel.ps1"
@@ -18,6 +120,20 @@ $clientConfigPath = Join-Path $installRoot "config\ocsentinel-client.json"
$secretScriptPath = Join-Path $installRoot "scripts\protect-ocsentinel-secret.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
# NinjaOne script variables are exposed as process environment variables.
if ([string]::IsNullOrWhiteSpace($WebhookUrl)) {
$WebhookUrl = $env:WebhookUrl
}
if ([string]::IsNullOrWhiteSpace($SecretValue)) {
$SecretValue = $env:SecretValue
}
$runInitialScan = $RunInitialStatusScan.IsPresent
if (-not $runInitialScan -and -not [string]::IsNullOrWhiteSpace($env:RunInitialStatusScan)) {
$runInitialScan = $env:RunInitialStatusScan -match '^(1|true|yes|on)$'
}
function Assert-ArtifactSignature {
param([Parameter(Mandatory)][string]$ExecutablePath)
@@ -33,14 +149,11 @@ function Assert-ArtifactSignature {
if (Test-Path -LiteralPath $updaterPath) {
Write-Host "Existing OCSentinel installation found. Checking for updates."
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $updaterPath -ManifestUrl $ManifestUrl
if ($LASTEXITCODE -ne 0) {
throw "OCSentinel updater exited with code $LASTEXITCODE"
}
Invoke-OCSentinelUpdater -UpdaterPath $updaterPath -ManifestUri $ManifestUrl
}
else {
Write-Host "Reading OCSentinel release manifest: $ManifestUrl"
$manifest = Invoke-RestMethod -Method Get -Uri $ManifestUrl -TimeoutSec 60
$manifest = Get-OCSentinelManifest -Uri $ManifestUrl
if ([string]::IsNullOrWhiteSpace($manifest.version) -or [string]::IsNullOrWhiteSpace($manifest.artifactUrl) -or [string]::IsNullOrWhiteSpace($manifest.sha256)) {
throw "Release manifest is missing version, artifactUrl, or sha256."
}
@@ -52,7 +165,7 @@ else {
try {
New-Item -ItemType Directory -Force -Path $extractRoot | Out-Null
Write-Host "Downloading OCSentinel $($manifest.version)"
Invoke-WebRequest -Uri ([string]$manifest.artifactUrl) -OutFile $zipPath -TimeoutSec 300
Get-OCSentinelArtifact -Uri ([string]$manifest.artifactUrl) -DestinationPath $zipPath
$actualHash = (Get-FileHash -LiteralPath $zipPath -Algorithm SHA256).Hash.ToLowerInvariant()
$expectedHash = ([string]$manifest.sha256).ToLowerInvariant()
@@ -93,8 +206,22 @@ if (-not [string]::IsNullOrWhiteSpace($WebhookUrl)) {
$clientConfig = Get-Content -LiteralPath $clientConfigPath -Raw | ConvertFrom-Json
$clientConfig.n8nWebhookUrl = $WebhookUrl
$clientConfig.environment = "production"
$ninjaContext = @(
@{ EnvironmentName = "NINJA_ORGANIZATION_ID"; PropertyName = "ninjaOrganizationId" },
@{ EnvironmentName = "NINJA_ORGANIZATION_NAME"; PropertyName = "ninjaOrganizationName" },
@{ EnvironmentName = "NINJA_AGENT_MACHINE_ID"; PropertyName = "ninjaMachineId" },
@{ EnvironmentName = "NINJA_AGENT_NODE_ID"; PropertyName = "ninjaNodeId" },
@{ EnvironmentName = "NINJA_LOCATION_ID"; PropertyName = "ninjaLocationId" },
@{ EnvironmentName = "NINJA_LOCATION_NAME"; PropertyName = "ninjaLocationName" }
)
foreach ($entry in $ninjaContext) {
$value = [Environment]::GetEnvironmentVariable($entry.EnvironmentName, "Process")
if (-not [string]::IsNullOrWhiteSpace($value)) {
$clientConfig | Add-Member -NotePropertyName $entry.PropertyName -NotePropertyValue $value.Trim() -Force
}
}
$clientConfig | ConvertTo-Json -Depth 10 | Set-Content -LiteralPath $clientConfigPath -Encoding UTF8
Write-Host "Configured OCSentinel upload endpoint."
Write-Host "Configured OCSentinel upload endpoint and NinjaOne context."
}
if (-not [string]::IsNullOrWhiteSpace($SecretValue)) {
@@ -108,7 +235,7 @@ if (-not [string]::IsNullOrWhiteSpace($SecretValue)) {
}
}
if ($RunInitialStatusScan) {
if ($runInitialScan) {
if (-not (Test-Path -LiteralPath $monitorPath)) {
throw "OCSentinel was installed, but the monitor script is missing."
}

View File

@@ -0,0 +1,62 @@
[CmdletBinding()]
param(
[string]$WebhookUrl = "",
[string]$SecretValue = ""
)
$ErrorActionPreference = "Stop"
function Get-NinjaValue {
param([Parameter(Mandatory)][string]$Name)
$value = [Environment]::GetEnvironmentVariable($Name, "Process")
if ($null -eq $value) {
return ""
}
return $value.Trim()
}
if ([string]::IsNullOrWhiteSpace($WebhookUrl)) {
$WebhookUrl = Get-NinjaValue -Name "webhookurl"
}
if ([string]::IsNullOrWhiteSpace($SecretValue)) {
$SecretValue = Get-NinjaValue -Name "secretvalue"
}
if ([string]::IsNullOrWhiteSpace($WebhookUrl) -or [string]::IsNullOrWhiteSpace($SecretValue)) {
throw "WebhookUrl and SecretValue must be supplied as NinjaOne script variables."
}
$installRoot = Join-Path $env:ProgramFiles "OCSentinel"
$configPath = Join-Path $installRoot "config\ocsentinel-client.json"
$secretScript = Join-Path $installRoot "scripts\protect-ocsentinel-secret.ps1"
$monitorScript = Join-Path $installRoot "scripts\run-ocsentinel-monitor.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
foreach ($path in @($configPath, $secretScript, $monitorScript)) {
if (-not (Test-Path -LiteralPath $path)) {
throw "OCSentinel installation is incomplete. Missing: $path"
}
}
$config = Get-Content -LiteralPath $configPath -Raw | ConvertFrom-Json
$config.n8nWebhookUrl = $WebhookUrl
$config.environment = "production"
$config | ConvertTo-Json -Depth 10 | Set-Content -LiteralPath $configPath -Encoding UTF8
Write-Host "OCSentinel upload endpoint configured."
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $secretScript -SecretValue $SecretValue
if ($LASTEXITCODE -ne 0) {
throw "Writing the protected upload secret failed with code $LASTEXITCODE"
}
Write-Host "Running signed OCSentinel test scan and upload."
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $monitorScript `
-Mode status `
-ClientConfigPath $configPath `
-SecretPath $secretPath `
-UploadMode required
exit $LASTEXITCODE

View File

@@ -0,0 +1,106 @@
[CmdletBinding()]
param(
[string]$ManifestUrl = "https://gitea.officecom.cloud/officecom/oc-sentinel/raw/main/release/stable/version.json",
[string]$WebhookUrl = "",
[string]$SecretValue = ""
)
$ErrorActionPreference = "Stop"
$ProgressPreference = "SilentlyContinue"
function Initialize-OCSentinelTls {
$protocols = [Net.SecurityProtocolType]::Tls12
if ([Enum]::GetNames([Net.SecurityProtocolType]) -contains "Tls13") {
$protocols = $protocols -bor [Net.SecurityProtocolType]::Tls13
}
[Net.ServicePointManager]::SecurityProtocol = $protocols
[Net.ServicePointManager]::Expect100Continue = $false
}
function Get-OCSentinelManifest {
param([Parameter(Mandatory)][string]$Uri)
$parameters = @{ Method = "Get"; Uri = $Uri; TimeoutSec = 60 }
if ((Get-Command Invoke-RestMethod).Parameters.ContainsKey("UseBasicParsing")) {
$parameters.UseBasicParsing = $true
}
for ($attempt = 1; $attempt -le 3; $attempt++) {
try {
return Invoke-RestMethod @parameters
}
catch {
if ($attempt -eq 3) {
throw "Could not retrieve the OCSentinel release manifest after 3 attempts. Verify that the device can reach gitea.officecom.cloud with TLS 1.2 or newer. Last error: $($_.Exception.Message)"
}
Start-Sleep -Seconds (3 * $attempt)
}
}
}
Initialize-OCSentinelTls
function Get-NinjaValue {
param([Parameter(Mandatory)][string]$Name)
$value = [Environment]::GetEnvironmentVariable($Name, "Process")
if ($null -eq $value) {
return ""
}
return $value.Trim()
}
if ([string]::IsNullOrWhiteSpace($WebhookUrl)) { $WebhookUrl = Get-NinjaValue -Name "webhookurl" }
if ([string]::IsNullOrWhiteSpace($SecretValue)) { $SecretValue = Get-NinjaValue -Name "secretvalue" }
if ([string]::IsNullOrWhiteSpace($WebhookUrl) -or [string]::IsNullOrWhiteSpace($SecretValue)) {
throw "WebhookUrl and SecretValue must be set as NinjaOne script variables."
}
$manifest = Get-OCSentinelManifest -Uri $ManifestUrl
if ([string]::IsNullOrWhiteSpace($manifest.artifactUrl) -or [string]::IsNullOrWhiteSpace($manifest.sha256)) {
throw "The release manifest is incomplete."
}
$downloadRoot = Join-Path $env:ProgramData ("OCSentinel\\install-" + [Guid]::NewGuid().ToString("N"))
$zipPath = Join-Path $downloadRoot "OCSentinelClient.zip"
$extractPath = Join-Path $downloadRoot "payload"
try {
New-Item -ItemType Directory -Force -Path $extractPath | Out-Null
Write-Host "Downloading OCSentinel $($manifest.version)."
Invoke-WebRequest -Uri $manifest.artifactUrl -OutFile $zipPath -TimeoutSec 300
$actualHash = (Get-FileHash -LiteralPath $zipPath -Algorithm SHA256).Hash.ToLowerInvariant()
if ($actualHash -ne ([string]$manifest.sha256).ToLowerInvariant()) {
throw "Release package SHA-256 validation failed."
}
Expand-Archive -LiteralPath $zipPath -DestinationPath $extractPath -Force
$installer = Get-ChildItem -Path $extractPath -Recurse -Filter "install-ocsentinel.ps1" | Select-Object -First 1
if ($null -eq $installer) { throw "The release package does not contain the installer." }
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $installer.FullName
if ($LASTEXITCODE -ne 0) { throw "Installer failed with code $LASTEXITCODE" }
}
finally {
if (Test-Path -LiteralPath $downloadRoot) { Remove-Item -LiteralPath $downloadRoot -Recurse -Force }
}
$installRoot = Join-Path $env:ProgramFiles "OCSentinel"
$configPath = Join-Path $installRoot "config\ocsentinel-client.json"
$secretScript = Join-Path $installRoot "scripts\protect-ocsentinel-secret.ps1"
$monitorScript = Join-Path $installRoot "scripts\run-ocsentinel-monitor.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
$config = Get-Content -LiteralPath $configPath -Raw | ConvertFrom-Json
$config.n8nWebhookUrl = $WebhookUrl
$config.environment = "production"
$config | ConvertTo-Json -Depth 10 | Set-Content -LiteralPath $configPath -Encoding UTF8
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $secretScript -SecretValue $SecretValue
if ($LASTEXITCODE -ne 0) { throw "Writing the protected upload secret failed with code $LASTEXITCODE" }
Write-Host "Running initial signed scan and upload."
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $monitorScript -Mode status -ClientConfigPath $configPath -SecretPath $secretPath -UploadMode required
exit $LASTEXITCODE

View File

@@ -9,6 +9,7 @@ param(
[string]$UploadMode = "auto",
[string]$VulnerabilityCsvPath = "",
[string]$MirrorRoot = "",
[switch]$SuppressTriggerExit,
[ValidateSet("status", "attack-only", "cve-critical", "attack-plus-cve")]
[string]$Mode = "status"
)
@@ -46,8 +47,13 @@ function Initialize-NinjaFieldWriter {
return
}
if (Get-Command -Name "Set-NinjaProperty" -ErrorAction SilentlyContinue) {
$script:NinjaFieldBackend = "powershell-modern"
return
}
if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) {
$script:NinjaFieldBackend = "powershell"
$script:NinjaFieldBackend = "powershell-legacy"
return
}
@@ -64,14 +70,20 @@ function Set-NinjaCustomFieldValue {
[Parameter(Mandatory)]
[string]$Name,
[AllowEmptyString()]
[string]$Value
[object]$Value,
[Parameter(Mandatory)]
[string]$Type
)
Initialize-NinjaFieldWriter
switch ($script:NinjaFieldBackend) {
"powershell" {
Ninja-Property-Set $Name $Value | Out-Null
"powershell-modern" {
Set-NinjaProperty -Name $Name -Value $Value -Type $Type -Force | Out-Null
return $true
}
"powershell-legacy" {
Ninja-Property-Set -Name $Name -Value $Value | Out-Null
return $true
}
"cli" {
@@ -112,28 +124,43 @@ function Publish-NinjaCustomFields {
}
}
$fieldValues = [ordered]@{
"ocsentinelstatus" = [string]$Report.AlertState
"ocsentinelreason" = $Reason
"ocsentinelbasestatus" = [string]$Report.BaseAlertState
"ocsentinelevents" = [string]([int]$Report.TotalEvents)
"ocsentineluniqueips" = [string]([int]$Report.UniqueIpCount)
"ocsentinelcvecritical" = [string]([int]$Report.VulnerabilityCorrelation.CriticalCount)
"ocsentinelcvetotal" = [string]([int]$Report.VulnerabilityCorrelation.TotalCount)
"ocsentinelmode" = $Mode
"ocsentineltriggered" = $Triggered.ToString().ToLowerInvariant()
"ocsentinellastscanutc" = $generatedAtUtc
$uploadStatus = [string]$Report.Runtime.UploadStatus
if ([string]::IsNullOrWhiteSpace($uploadStatus)) { $uploadStatus = "unknown" }
$queuedReports = [int]$Report.Runtime.QueuedReportCount
$lastUploadUtc = ""
if ($Report.Runtime.LastSuccessfulUploadUtc) {
try { $lastUploadUtc = ([DateTimeOffset]$Report.Runtime.LastSuccessfulUploadUtc).ToUniversalTime().ToString("o") } catch { $lastUploadUtc = [string]$Report.Runtime.LastSuccessfulUploadUtc }
}
$lastUploadError = [string]$Report.Runtime.LastUploadError
if ($lastUploadError.Length -gt 900) { $lastUploadError = $lastUploadError.Substring(0, 900) }
$fieldValues = @(
[pscustomobject]@{ Name = "ocsentinelstatus"; Type = "Text"; Value = [string]$Report.AlertState }
[pscustomobject]@{ Name = "ocsentinelreason"; Type = "Text"; Value = $Reason }
[pscustomobject]@{ Name = "ocsentinelbasestatus"; Type = "Text"; Value = [string]$Report.BaseAlertState }
[pscustomobject]@{ Name = "ocsentinelevents"; Type = "Integer"; Value = [int]$Report.TotalEvents }
[pscustomobject]@{ Name = "ocsentineluniqueips"; Type = "Integer"; Value = [int]$Report.UniqueIpCount }
[pscustomobject]@{ Name = "ocsentinelcvecritical"; Type = "Integer"; Value = [int]$Report.VulnerabilityCorrelation.CriticalCount }
[pscustomobject]@{ Name = "ocsentinelcvetotal"; Type = "Integer"; Value = [int]$Report.VulnerabilityCorrelation.TotalCount }
[pscustomobject]@{ Name = "ocsentinelmode"; Type = "Text"; Value = $Mode }
[pscustomobject]@{ Name = "ocsentineltriggered"; Type = "Checkbox"; Value = $Triggered }
[pscustomobject]@{ Name = "ocsentinellastscanutc"; Type = "DateTime"; Value = $generatedAtUtc }
[pscustomobject]@{ Name = "ocsentineluploadstatus"; Type = "Text"; Value = $uploadStatus }
[pscustomobject]@{ Name = "ocsentinelqueuedreports"; Type = "Integer"; Value = $queuedReports }
[pscustomobject]@{ Name = "ocsentinellastuploadutc"; Type = "DateTime"; Value = $lastUploadUtc }
[pscustomobject]@{ Name = "ocsentinellasterror"; Type = "Text"; Value = $lastUploadError }
[pscustomobject]@{ Name = "ocsentinelclientversion"; Type = "Text"; Value = [string]$Report.ClientVersion }
)
$updated = 0
foreach ($entry in $fieldValues.GetEnumerator()) {
foreach ($entry in $fieldValues) {
try {
if (Set-NinjaCustomFieldValue -Name $entry.Key -Value $entry.Value) {
if (Set-NinjaCustomFieldValue -Name $entry.Name -Value $entry.Value -Type $entry.Type) {
$updated++
}
}
catch {
Write-Warning "Failed to set Ninja custom field '$($entry.Key)': $($_.Exception.Message)"
Write-Warning "Failed to set Ninja custom field '$($entry.Name)': $($_.Exception.Message)"
}
}
@@ -178,6 +205,8 @@ $events = [int]$report.TotalEvents
$uniqueIps = [int]$report.UniqueIpCount
$criticalCves = [int]$report.VulnerabilityCorrelation.CriticalCount
$totalCves = [int]$report.VulnerabilityCorrelation.TotalCount
$uploadStatus = [string]$report.Runtime.UploadStatus
$queuedReports = [int]$report.Runtime.QueuedReportCount
$monitorTriggered = $false
$monitorReason = ""
@@ -213,11 +242,13 @@ Write-Host "Events: $events"
Write-Host "Unique IPs: $uniqueIps"
Write-Host "Critical/High CVEs: $criticalCves"
Write-Host "Total CVEs: $totalCves"
Write-Host "Upload status: $uploadStatus"
Write-Host "Queued reports: $queuedReports"
Write-Host "Report: $outputFullPath"
Write-Host "Runner exit code: $runnerExitCode"
if ($monitorTriggered) {
if ($monitorTriggered -and -not $SuppressTriggerExit) {
exit 1
}
exit 0
exit $runnerExitCode

View File

@@ -0,0 +1,116 @@
[CmdletBinding()]
param(
[ValidateSet("daily", "burst")]
[string]$Kind = "daily",
[ValidateRange(15, 480)]
[int]$BurstDurationMinutes = 120
)
$ErrorActionPreference = "Stop"
$scriptDir = Split-Path -Parent $MyInvocation.MyCommand.Path
$monitorScript = Join-Path $scriptDir "run-ocsentinel-monitor.ps1"
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
$mutexName = "Global\OfficeComSentinelScan"
function Get-NinjaBurstEnabled {
if (Get-Command -Name "Get-NinjaProperty" -ErrorAction SilentlyContinue) {
return [bool](Get-NinjaProperty -Name "ocsentinelburst" -Type "Checkbox")
}
if (Get-Command -Name "Ninja-Property-Get" -ErrorAction SilentlyContinue) {
$value = Ninja-Property-Get -Name "ocsentinelburst"
return [string]$value -match "^(1|true|yes)$"
}
Write-Warning "Ninja custom-field reader is unavailable; burst scan skipped."
return $false
}
function Get-NinjaValue {
param([Parameter(Mandatory)][string]$Name, [Parameter(Mandatory)][string]$Type)
try {
if (Get-Command -Name "Get-NinjaProperty" -ErrorAction SilentlyContinue) {
return Get-NinjaProperty -Name $Name -Type $Type
}
if (Get-Command -Name "Ninja-Property-Get" -ErrorAction SilentlyContinue) {
return Ninja-Property-Get -Name $Name
}
}
catch {
Write-Warning "Could not read Ninja field '$Name': $($_.Exception.Message)"
}
return $null
}
function Set-NinjaValue {
param([Parameter(Mandatory)][string]$Name, [AllowEmptyString()][string]$Value, [Parameter(Mandatory)][string]$Type)
try {
if (Get-Command -Name "Set-NinjaProperty" -ErrorAction SilentlyContinue) {
Set-NinjaProperty -Name $Name -Value $Value -Type $Type -Force | Out-Null
return $true
}
if (Get-Command -Name "Ninja-Property-Set" -ErrorAction SilentlyContinue) {
Ninja-Property-Set -Name $Name -Value $Value | Out-Null
return $true
}
}
catch {
Write-Warning "Could not update Ninja field '$Name': $($_.Exception.Message)"
}
return $false
}
if ($Kind -eq "burst") {
if (-not (Get-NinjaBurstEnabled)) {
Set-NinjaValue -Name "ocsentinelburststatus" -Value "idle" -Type "Text" | Out-Null
Write-Host "OfficeCom Sentinel burst check: disabled."
exit 0
}
$now = [DateTimeOffset]::UtcNow
$untilValue = Get-NinjaValue -Name "ocsentinelburstuntilutc" -Type "DateTime"
$until = $null
if (-not [string]::IsNullOrWhiteSpace([string]$untilValue)) {
try { $until = [DateTimeOffset]$untilValue } catch { Write-Warning "Burst end time is invalid and will be restarted." }
}
if ($null -eq $until) {
$until = $now.AddMinutes($BurstDurationMinutes)
Set-NinjaValue -Name "ocsentinelburstuntilutc" -Value $until.ToString("o") -Type "DateTime" | Out-Null
Write-Host "OfficeCom Sentinel burst window started until $($until.ToString('u'))."
}
elseif ($until -le $now) {
Set-NinjaValue -Name "ocsentinelburst" -Value "false" -Type "Checkbox" | Out-Null
Set-NinjaValue -Name "ocsentinelburststatus" -Value "completed" -Type "Text" | Out-Null
Write-Host "OfficeCom Sentinel burst window completed and was disabled."
exit 0
}
Set-NinjaValue -Name "ocsentinelburststatus" -Value "active until $($until.ToUniversalTime().ToString('o'))" -Type "Text" | Out-Null
}
$createdNew = $false
$mutex = [Threading.Mutex]::new($false, $mutexName, [ref]$createdNew)
try {
if (-not $mutex.WaitOne(0)) {
Write-Host "OfficeCom Sentinel scan skipped: another scan is already running."
exit 0
}
Write-Host "OfficeCom Sentinel scheduled $Kind scan started."
$monitorArgs = @("-NoProfile", "-ExecutionPolicy", "Bypass", "-File", $monitorScript, "-Mode", "status", "-UploadMode", "required", "-SecretPath", $secretPath, "-SuppressTriggerExit")
if ($Kind -eq "burst") {
$monitorArgs += @("-LookbackDays", "1", "-TopCount", "25")
}
& powershell.exe @monitorArgs
exit $LASTEXITCODE
}
finally {
if ($null -ne $mutex) {
try { $mutex.ReleaseMutex() } catch { }
$mutex.Dispose()
}
}

View File

@@ -40,6 +40,40 @@ function Resolve-PathLike {
return [System.IO.Path]::GetFullPath((Join-Path $BasePath $PathValue))
}
function Restore-NinjaContextFromClientConfiguration {
param([Parameter(Mandatory)][string]$Path)
if (-not (Test-Path -LiteralPath $Path)) {
return
}
try {
$clientConfiguration = Get-Content -LiteralPath $Path -Raw | ConvertFrom-Json
$mappings = @(
@{ EnvironmentName = "NINJA_ORGANIZATION_ID"; PropertyName = "ninjaOrganizationId" },
@{ EnvironmentName = "NINJA_ORGANIZATION_NAME"; PropertyName = "ninjaOrganizationName" },
@{ EnvironmentName = "NINJA_AGENT_MACHINE_ID"; PropertyName = "ninjaMachineId" },
@{ EnvironmentName = "NINJA_AGENT_NODE_ID"; PropertyName = "ninjaNodeId" },
@{ EnvironmentName = "NINJA_LOCATION_ID"; PropertyName = "ninjaLocationId" },
@{ EnvironmentName = "NINJA_LOCATION_NAME"; PropertyName = "ninjaLocationName" }
)
foreach ($mapping in $mappings) {
if (-not [string]::IsNullOrWhiteSpace([Environment]::GetEnvironmentVariable($mapping.EnvironmentName, "Process"))) {
continue
}
$value = [string]$clientConfiguration.($mapping.PropertyName)
if (-not [string]::IsNullOrWhiteSpace($value)) {
[Environment]::SetEnvironmentVariable($mapping.EnvironmentName, $value, "Process")
}
}
}
catch {
Write-Warning "Could not restore stored NinjaOne context: $($_.Exception.Message)"
}
}
$arguments = @(
$dllPath
)
@@ -53,6 +87,8 @@ else {
$secretFullPath = if ([string]::IsNullOrWhiteSpace($SecretPath)) { "" } else { Resolve-PathLike -PathValue $SecretPath -BasePath $repoRoot }
$canUpload = (Test-Path $clientConfigFullPath) -and (-not [string]::IsNullOrWhiteSpace($secretFullPath)) -and (Test-Path $secretFullPath)
Restore-NinjaContextFromClientConfiguration -Path $clientConfigFullPath
if ($UploadMode -eq "required" -and -not $canUpload) {
throw "UploadMode 'required' was set, but client config or protected secret is missing."
}

View File

@@ -53,8 +53,9 @@ internal sealed class AttackScanner
.ToList();
int uniqueIpCount = attacks.Select(static attack => attack.SourceIp).Distinct(StringComparer.OrdinalIgnoreCase).Count();
string baseAlertState = GetAlertState(attacks.Count, uniqueIpCount, configuration);
string baseAlertReason = GetAlertReason(attacks.Count, uniqueIpCount, configuration, baseAlertState);
AlertAssessment baseAssessment = AssessAttackActivity(attacks, uniqueIpCount, configuration);
string baseAlertState = baseAssessment.State;
string baseAlertReason = baseAssessment.Reason;
VulnerabilityCorrelationSummary vulnerabilityCorrelation = string.IsNullOrWhiteSpace(options.VulnerabilityCsvPath)
? VulnerabilityCorrelationSummary.Empty()
: VulnerabilityCorrelation.LoadForMachine(Environment.MachineName, options.VulnerabilityCsvPath, errors);
@@ -469,28 +470,90 @@ internal sealed class AttackScanner
return IPAddress.TryParse(input, out _);
}
private static string GetAlertState(int totalEvents, int uniqueIpCount, ScannerConfiguration configuration)
private static AlertAssessment AssessAttackActivity(IReadOnlyList<AttackEvent> attacks, int uniqueIpCount, ScannerConfiguration configuration)
{
if (totalEvents >= configuration.CriticalEventThreshold || uniqueIpCount >= configuration.CriticalUniqueIpThreshold)
if (attacks.Count == 0)
{
return "critical";
return new AlertAssessment("ok", "No failed login activity observed.");
}
if (totalEvents >= configuration.WarningEventThreshold || uniqueIpCount >= configuration.WarningUniqueIpThreshold)
TimeSpan window = TimeSpan.FromMinutes(configuration.LoginBurstWindowMinutes);
int largestBurst = attacks
.GroupBy(attack => (attack.SourceIp, attack.Username, attack.Target))
.Select(group => GetPeakEventCount(group.OrderBy(attack => attack.Timestamp).ToList(), window))
.DefaultIfEmpty(0)
.Max();
int largestSpray = attacks
.GroupBy(attack => attack.SourceIp)
.Select(group => GetPeakDistinctAccountCount(group.OrderBy(attack => attack.Timestamp).ToList(), window))
.DefaultIfEmpty(0)
.Max();
if (largestBurst >= configuration.CriticalLoginBurstCount || largestSpray >= configuration.CriticalSprayAccountCount)
{
return "warning";
return new AlertAssessment("critical", $"High-confidence login attack pattern: burst={largestBurst}, sprayed accounts={largestSpray}, window={configuration.LoginBurstWindowMinutes}m.");
}
return "ok";
if (largestBurst >= configuration.WarningLoginBurstCount || largestSpray >= configuration.WarningSprayAccountCount)
{
return new AlertAssessment("warning", $"Suspicious login pattern: burst={largestBurst}, sprayed accounts={largestSpray}, window={configuration.LoginBurstWindowMinutes}m.");
}
private static string GetAlertReason(int totalEvents, int uniqueIpCount, ScannerConfiguration configuration, string alertState)
int criticalEventThreshold = Math.Max(configuration.CriticalEventThreshold, configuration.CriticalLoginBurstCount);
int criticalIpThreshold = Math.Max(configuration.CriticalUniqueIpThreshold, configuration.CriticalSprayAccountCount);
int warningEventThreshold = Math.Max(configuration.WarningEventThreshold, configuration.WarningLoginBurstCount * 2);
int warningIpThreshold = Math.Max(configuration.WarningUniqueIpThreshold, configuration.WarningSprayAccountCount);
if (attacks.Count >= criticalEventThreshold || uniqueIpCount >= criticalIpThreshold)
{
return alertState switch
return new AlertAssessment("critical", $"Critical volume threshold reached: events={attacks.Count}, unique IPs={uniqueIpCount}.");
}
if (attacks.Count >= warningEventThreshold || uniqueIpCount >= warningIpThreshold)
{
"critical" => $"Critical threshold reached. Events={totalEvents}/{configuration.CriticalEventThreshold}, UniqueIPs={uniqueIpCount}/{configuration.CriticalUniqueIpThreshold}.",
"warning" => $"Warning threshold reached. Events={totalEvents}/{configuration.WarningEventThreshold}, UniqueIPs={uniqueIpCount}/{configuration.WarningUniqueIpThreshold}.",
_ => "No thresholds exceeded."
};
return new AlertAssessment("warning", $"Elevated failed-login volume: events={attacks.Count}, unique IPs={uniqueIpCount}.");
}
return new AlertAssessment("ok", $"Low-volume login errors observed: events={attacks.Count}, unique IPs={uniqueIpCount}; no burst or password-spraying pattern detected.");
}
private static int GetPeakEventCount(IReadOnlyList<AttackEvent> events, TimeSpan window)
{
int start = 0;
int peak = 0;
for (int end = 0; end < events.Count; end++)
{
while (events[end].Timestamp - events[start].Timestamp > window)
{
start++;
}
peak = Math.Max(peak, end - start + 1);
}
return peak;
}
private static int GetPeakDistinctAccountCount(IReadOnlyList<AttackEvent> events, TimeSpan window)
{
var accounts = new Dictionary<string, int>(StringComparer.OrdinalIgnoreCase);
int start = 0;
int peak = 0;
for (int end = 0; end < events.Count; end++)
{
accounts[events[end].Username] = accounts.GetValueOrDefault(events[end].Username) + 1;
while (events[end].Timestamp - events[start].Timestamp > window)
{
string account = events[start].Username;
accounts[account]--;
if (accounts[account] == 0)
{
accounts.Remove(account);
}
start++;
}
peak = Math.Max(peak, accounts.Count);
}
return peak;
}
private sealed record AlertAssessment(string State, string Reason);
}

View File

@@ -1,4 +1,5 @@
using OCSentinelCli.Configuration;
using OCSentinelCli.Models;
using System.Text.Json;
using OCSentinelCli.Security;
using OCSentinelCli.Transport;
@@ -56,30 +57,52 @@ internal static class UploadCommand
string reportFullPath = Path.GetFullPath(reportPath);
string json = File.ReadAllText(reportFullPath);
string secret = ProtectedSecretStore.LoadSecret(resolvedSecretPath);
var client = new N8nUploadClient();
var queue = new UploadQueue(config.UploadQueueMaxReports);
UploadHealth health = queue.LoadHealth();
DateTimeOffset attemptTime = DateTimeOffset.UtcNow;
ScanResult? parsedReport = JsonSerializer.Deserialize<ScanResult>(json, JsonOptions.Default);
if (parsedReport is not null)
{
parsedReport = parsedReport with
{
Runtime = parsedReport.Runtime with
{
UploadAttempted = true
UploadAttempted = true,
UploadStatus = "attempting",
QueuedReportCount = health.QueuedReportCount,
LastSuccessfulUploadUtc = health.LastSuccessfulUploadUtc
}
};
json = JsonSerializer.Serialize(parsedReport, JsonOptions.Default);
File.WriteAllText(reportFullPath, json);
}
string secret = ProtectedSecretStore.LoadSecret(resolvedSecretPath);
var client = new N8nUploadClient();
var result = client.UploadJson(config.N8nWebhookUrl, Environment.MachineName, BuildMetadata.Version, json, secret, config.UploadTimeoutSeconds);
UploadResult? deferredFailure = queue.Drain(
client,
config.N8nWebhookUrl,
Environment.MachineName,
BuildMetadata.Version,
secret,
config.UploadTimeoutSeconds);
if (!result.Success)
if (deferredFailure is null)
{
Console.Error.WriteLine($"Upload failed ({result.StatusCode}): {result.Message}");
return 1;
}
var result = client.UploadJson(config.N8nWebhookUrl, Environment.MachineName, BuildMetadata.Version, json, secret, config.UploadTimeoutSeconds);
if (result.Success)
{
UploadHealth successHealth = new()
{
LastUploadAttemptUtc = attemptTime,
LastSuccessfulUploadUtc = DateTimeOffset.UtcNow,
LastUploadStatus = "ok",
LastUploadError = string.Empty,
QueuedReportCount = queue.GetQueueDepth()
};
queue.SaveHealth(successHealth);
WriteReportRuntime(reportFullPath, parsedReport, successHealth, true);
Console.WriteLine($"Upload succeeded ({result.StatusCode})");
Console.WriteLine($"Nonce: {result.Nonce}");
@@ -87,6 +110,50 @@ internal static class UploadCommand
return 0;
}
deferredFailure = result;
}
UploadResult failure = deferredFailure ?? throw new InvalidOperationException("Upload failed without a result.");
int queuedCount = queue.Enqueue(json);
UploadHealth queuedHealth = new()
{
LastUploadAttemptUtc = attemptTime,
LastSuccessfulUploadUtc = health.LastSuccessfulUploadUtc,
LastUploadStatus = "queued",
LastUploadError = failure.Message,
QueuedReportCount = queuedCount
};
queue.SaveHealth(queuedHealth);
WriteReportRuntime(reportFullPath, parsedReport, queuedHealth, true);
Console.WriteLine($"Upload deferred ({failure.StatusCode}): {failure.Message}");
Console.WriteLine($"Queued reports: {queuedCount}");
Console.WriteLine("The report will be retried automatically on the next scheduled run.");
return 0;
}
private static void WriteReportRuntime(string reportPath, ScanResult? report, UploadHealth health, bool attempted)
{
if (report is null)
{
return;
}
ScanResult updated = report with
{
Runtime = report.Runtime with
{
UploadAttempted = attempted,
UploadSucceeded = string.Equals(health.LastUploadStatus, "ok", StringComparison.Ordinal),
UploadStatus = health.LastUploadStatus,
QueuedReportCount = health.QueuedReportCount,
LastSuccessfulUploadUtc = health.LastSuccessfulUploadUtc,
LastUploadError = health.LastUploadError
}
};
File.WriteAllText(reportPath, JsonSerializer.Serialize(updated, JsonOptions.Default));
}
private static string ReadValue(string[] args, ref int index, string argName)
{
if (index + 1 >= args.Length)

View File

@@ -4,13 +4,23 @@ namespace OCSentinelCli;
internal sealed record ScannerConfiguration
{
public int WarningEventThreshold { get; init; } = 1;
public int WarningEventThreshold { get; init; } = 10;
public int CriticalEventThreshold { get; init; } = 20;
public int CriticalEventThreshold { get; init; } = 30;
public int WarningUniqueIpThreshold { get; init; } = 1;
public int WarningUniqueIpThreshold { get; init; } = 5;
public int CriticalUniqueIpThreshold { get; init; } = 10;
public int CriticalUniqueIpThreshold { get; init; } = 12;
public int LoginBurstWindowMinutes { get; init; } = 15;
public int WarningLoginBurstCount { get; init; } = 5;
public int CriticalLoginBurstCount { get; init; } = 20;
public int WarningSprayAccountCount { get; init; } = 5;
public int CriticalSprayAccountCount { get; init; } = 10;
public int CorrelationWarningCveThreshold { get; init; } = 1;

View File

@@ -18,6 +18,8 @@ internal sealed record ClientConfiguration
public int UploadTimeoutSeconds { get; init; } = 30;
public int UploadQueueMaxReports { get; init; } = 100;
public bool EnableVulnerabilityCorrelation { get; init; } = true;
public string VulnerabilityCsvPath { get; init; } = string.Empty;

View File

@@ -8,6 +8,9 @@ internal static class JsonOptions
public static readonly JsonSerializerOptions Default = new()
{
WriteIndented = true,
// Client configuration is also written by PowerShell/NinjaOne scripts.
// Accept their conventional camelCase names (for example n8nWebhookUrl).
PropertyNameCaseInsensitive = true,
DefaultIgnoreCondition = JsonIgnoreCondition.WhenWritingNull
};
}

View File

@@ -136,6 +136,16 @@ internal sealed record ScanRuntimeMetadata
public DateTimeOffset FinishedAtUtc { get; init; }
public bool UploadAttempted { get; init; }
public bool UploadSucceeded { get; init; }
public string UploadStatus { get; init; } = "not-attempted";
public int QueuedReportCount { get; init; }
public DateTimeOffset? LastSuccessfulUploadUtc { get; init; }
public string LastUploadError { get; init; } = string.Empty;
}
internal sealed record VulnerabilityFinding

View File

@@ -9,10 +9,10 @@
<RootNamespace>OCSentinelCli</RootNamespace>
<Product>OfficeCom Sentinel</Product>
<Company>OfficeCom</Company>
<Version>1.2.7</Version>
<AssemblyVersion>1.2.3.0</AssemblyVersion>
<FileVersion>1.2.3.0</FileVersion>
<InformationalVersion>1.2.3</InformationalVersion>
<Version>1.4.0</Version>
<AssemblyVersion>1.4.0.0</AssemblyVersion>
<FileVersion>1.4.0.0</FileVersion>
<InformationalVersion>1.4.0</InformationalVersion>
</PropertyGroup>
<ItemGroup>

View File

@@ -38,6 +38,8 @@ internal sealed class N8nUploadClient
request.Headers.Add("X-ATN-Payload-SHA256", payloadHash);
request.Headers.Add("X-ATN-Signature", signature);
try
{
using HttpResponseMessage response = httpClient.Send(request);
string responseText = response.Content.ReadAsStringAsync().GetAwaiter().GetResult();
@@ -50,6 +52,18 @@ internal sealed class N8nUploadClient
PayloadSha256 = payloadHash
};
}
catch (Exception exception) when (exception is HttpRequestException or TaskCanceledException)
{
return new UploadResult
{
Success = false,
StatusCode = 0,
Message = exception.Message,
Nonce = nonce,
PayloadSha256 = payloadHash
};
}
}
private static string ComputeSha256(string value)
{

View File

@@ -0,0 +1,106 @@
using System.Text.Json;
using OCSentinelCli.Models;
namespace OCSentinelCli.Transport;
internal sealed record UploadHealth
{
public DateTimeOffset? LastUploadAttemptUtc { get; init; }
public DateTimeOffset? LastSuccessfulUploadUtc { get; init; }
public string LastUploadStatus { get; init; } = "not-attempted";
public string LastUploadError { get; init; } = string.Empty;
public int QueuedReportCount { get; init; }
}
internal sealed class UploadQueue
{
private readonly string queueDirectory;
private readonly string healthPath;
private readonly int maxReports;
public UploadQueue(int maxReports)
{
string root = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.CommonApplicationData), "OCSentinel");
queueDirectory = Path.Combine(root, "upload-queue");
healthPath = Path.Combine(root, "state", "upload-health.json");
this.maxReports = Math.Clamp(maxReports, 10, 500);
}
public UploadHealth LoadHealth()
{
try
{
if (!File.Exists(healthPath))
{
return new UploadHealth { QueuedReportCount = GetQueueDepth() };
}
UploadHealth? health = JsonSerializer.Deserialize<UploadHealth>(File.ReadAllText(healthPath), JsonOptions.Default);
return (health ?? new UploadHealth()) with { QueuedReportCount = GetQueueDepth() };
}
catch (Exception)
{
return new UploadHealth { QueuedReportCount = GetQueueDepth() };
}
}
public void SaveHealth(UploadHealth health)
{
Directory.CreateDirectory(Path.GetDirectoryName(healthPath)!);
WriteAtomically(healthPath, JsonSerializer.Serialize(health, JsonOptions.Default));
}
public UploadResult? Drain(N8nUploadClient client, string webhookUrl, string machineName, string clientVersion, string secret, int timeoutSeconds)
{
foreach (string path in GetQueuedPaths())
{
string payload = File.ReadAllText(path);
UploadResult result = client.UploadJson(webhookUrl, machineName, clientVersion, payload, secret, timeoutSeconds);
if (!result.Success)
{
return result;
}
File.Delete(path);
}
return null;
}
public int Enqueue(string payloadJson)
{
Directory.CreateDirectory(queueDirectory);
string fileName = $"{DateTimeOffset.UtcNow:yyyyMMddHHmmssfff}-{Guid.NewGuid():N}.json";
WriteAtomically(Path.Combine(queueDirectory, fileName), payloadJson);
foreach (string stalePath in GetQueuedPaths().Take(Math.Max(0, GetQueueDepth() - maxReports)))
{
File.Delete(stalePath);
}
return GetQueueDepth();
}
public int GetQueueDepth()
{
return Directory.Exists(queueDirectory) ? Directory.EnumerateFiles(queueDirectory, "*.json").Count() : 0;
}
private IEnumerable<string> GetQueuedPaths()
{
return Directory.Exists(queueDirectory)
? Directory.EnumerateFiles(queueDirectory, "*.json").OrderBy(static path => path, StringComparer.Ordinal)
: Enumerable.Empty<string>();
}
private static void WriteAtomically(string path, string content)
{
string temporaryPath = path + ".tmp";
File.WriteAllText(temporaryPath, content);
File.Move(temporaryPath, path, true);
}
}