Compare commits
4 Commits
v1.5.0-bet
...
v1.5.0-bet
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
fd990b698f | ||
|
|
d1bbd8838f | ||
|
|
feeeeedcf1 | ||
|
|
ceefb7a5dc |
@@ -10,7 +10,7 @@
|
||||
"criticalSprayAccountCount": 10,
|
||||
"correlationWarningCveThreshold": 1,
|
||||
"correlationCriticalCveThreshold": 1,
|
||||
"ransomwareBetaEnabled": false,
|
||||
"ransomwareBetaEnabled": true,
|
||||
"ransomwareBetaAlertingEnabled": false,
|
||||
"ransomwareLookbackMinutes": 15,
|
||||
"ransomwareWarningSignalCount": 2,
|
||||
|
||||
@@ -19,12 +19,13 @@ Die Stable-Aufgabe verwendet keinen Kanalwert oder den Wert `stable`.
|
||||
|
||||
## Passive Ransomware-Beta
|
||||
|
||||
Die Beta ist nach der Installation weiterhin deaktiviert. Auf einem
|
||||
Pilotgeraet wird in `C:\Program Files\OCSentinel\config\ocsentinel-settings.json`
|
||||
der Wert `ransomwareBetaEnabled` auf `true` gesetzt. Die Auswertung bleibt
|
||||
passiv, solange `ransomwareBetaAlertingEnabled` auf `false` steht: Hinweise,
|
||||
Warnungen und kritische Beta-Signale erscheinen im JSON-Report und Dashboard,
|
||||
veraendern aber keine NinjaOne-Alarmfelder.
|
||||
Die Ransomware-Beta ist im Beta-Kanal standardmaessig aktiviert. Die Auswertung
|
||||
bleibt passiv, solange `ransomwareBetaAlertingEnabled` auf `false` steht:
|
||||
Hinweise, Warnungen und kritische Beta-Signale erscheinen im JSON-Report und
|
||||
Dashboard, veraendern aber keine NinjaOne-Alarmfelder. Fuer eine lokale
|
||||
Ausnahme kann `ransomwareBetaEnabled` in
|
||||
`C:\Program Files\OCSentinel\config\ocsentinel-settings.json` auf `false`
|
||||
gesetzt werden.
|
||||
|
||||
Der optionale Datei-Churn-Sensor wird nur mit
|
||||
`ransomwareFileChurnEnabled: true` aktiviert. Er wertet ausschliesslich bereits
|
||||
|
||||
@@ -76,7 +76,6 @@ write access:
|
||||
| `ocsentinelqueuedreports` | Integer | Reports waiting for delivery |
|
||||
| `ocsentinellastuploadutc` | Date/Time | Last successful upload time |
|
||||
| `ocsentinellasterror` | Text | Last upload error, if any |
|
||||
| `ocsentinelclientversion` | Text | Installed client version |
|
||||
|
||||
## NinjaOne Tasks
|
||||
|
||||
|
||||
@@ -149,7 +149,6 @@ function Publish-NinjaCustomFields {
|
||||
[pscustomobject]@{ Name = "ocsentinelqueuedreports"; Type = "Integer"; Value = $queuedReports }
|
||||
[pscustomobject]@{ Name = "ocsentinellastuploadutc"; Type = "DateTime"; Value = $lastUploadUtc }
|
||||
[pscustomobject]@{ Name = "ocsentinellasterror"; Type = "Text"; Value = $lastUploadError }
|
||||
[pscustomobject]@{ Name = "ocsentinelclientversion"; Type = "Text"; Value = [string]$Report.ClientVersion }
|
||||
)
|
||||
|
||||
$updated = 0
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
{
|
||||
"channel": "beta",
|
||||
"version": "1.5.0-beta.1",
|
||||
"publishedAtUtc": "2026-07-29T23:07:54.7923320Z",
|
||||
"artifactUrl": "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.5.0-beta.1/OCSentinelClient-win-x64.zip",
|
||||
"sha256": "a712ee820dee2f6786a8297d892b3ae8844548ddc7030dcbe01435fbc89d924a",
|
||||
"version": "1.5.0-beta.3",
|
||||
"publishedAtUtc": "2026-07-31T23:31:45.7354313Z",
|
||||
"artifactUrl": "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v1.5.0-beta.3/OCSentinelClient-win-x64.zip",
|
||||
"sha256": "5a189c796635a4dc6a2df2e9d6122695532a4c30455fbf0808322a7a0030933d",
|
||||
"minUpdaterVersion": "1.0.0"
|
||||
}
|
||||
|
||||
@@ -112,6 +112,30 @@ function Get-OCSentinelArtifact {
|
||||
}
|
||||
}
|
||||
|
||||
function Enable-OCSentinelBetaDefaults {
|
||||
param([Parameter(Mandatory)][string]$SettingsPath)
|
||||
|
||||
if (-not (Test-Path -LiteralPath $SettingsPath)) {
|
||||
return
|
||||
}
|
||||
|
||||
$settings = Get-Content -LiteralPath $SettingsPath -Raw | ConvertFrom-Json
|
||||
if ($null -ne $settings.PSObject.Properties["ransomwareBetaDefaultApplied"]) {
|
||||
return
|
||||
}
|
||||
|
||||
if ($null -eq $settings.PSObject.Properties["ransomwareBetaEnabled"]) {
|
||||
$settings | Add-Member -NotePropertyName "ransomwareBetaEnabled" -NotePropertyValue $true
|
||||
}
|
||||
else {
|
||||
$settings.ransomwareBetaEnabled = $true
|
||||
}
|
||||
|
||||
$settings | Add-Member -NotePropertyName "ransomwareBetaDefaultApplied" -NotePropertyValue "1.5.0-beta.4"
|
||||
$settings | ConvertTo-Json -Depth 10 | Set-Content -LiteralPath $SettingsPath -Encoding UTF8
|
||||
Write-Host "Enabled passive ransomware beta defaults."
|
||||
}
|
||||
|
||||
Initialize-OCSentinelTls
|
||||
|
||||
if ($ReleaseChannel -eq "stable" -and -not [string]::IsNullOrWhiteSpace($env:ReleaseChannel)) {
|
||||
@@ -133,6 +157,7 @@ $updaterPath = Join-Path $installRoot "scripts\update-ocsentinel.ps1"
|
||||
$monitorPath = Join-Path $installRoot "scripts\run-ocsentinel-monitor.ps1"
|
||||
$appPath = Join-Path $installRoot "app\OCSentinelCli.exe"
|
||||
$clientConfigPath = Join-Path $installRoot "config\ocsentinel-client.json"
|
||||
$settingsPath = Join-Path $installRoot "config\ocsentinel-settings.json"
|
||||
$secretScriptPath = Join-Path $installRoot "scripts\protect-ocsentinel-secret.ps1"
|
||||
$secretPath = "C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat"
|
||||
|
||||
@@ -214,6 +239,10 @@ if (-not (Test-Path -LiteralPath $appPath)) {
|
||||
throw "OCSentinel installation completed, but the client executable was not found."
|
||||
}
|
||||
|
||||
if ($ReleaseChannel -eq "beta") {
|
||||
Enable-OCSentinelBetaDefaults -SettingsPath $settingsPath
|
||||
}
|
||||
|
||||
if (-not [string]::IsNullOrWhiteSpace($WebhookUrl)) {
|
||||
if (-not (Test-Path -LiteralPath $clientConfigPath)) {
|
||||
throw "OCSentinel client configuration was not found: $clientConfigPath"
|
||||
|
||||
@@ -149,7 +149,6 @@ function Publish-NinjaCustomFields {
|
||||
[pscustomobject]@{ Name = "ocsentinelqueuedreports"; Type = "Integer"; Value = $queuedReports }
|
||||
[pscustomobject]@{ Name = "ocsentinellastuploadutc"; Type = "DateTime"; Value = $lastUploadUtc }
|
||||
[pscustomobject]@{ Name = "ocsentinellasterror"; Type = "Text"; Value = $lastUploadError }
|
||||
[pscustomobject]@{ Name = "ocsentinelclientversion"; Type = "Text"; Value = [string]$Report.ClientVersion }
|
||||
)
|
||||
|
||||
$updated = 0
|
||||
|
||||
@@ -26,7 +26,7 @@ internal sealed record ScannerConfiguration
|
||||
|
||||
public int CorrelationCriticalCveThreshold { get; init; } = 1;
|
||||
|
||||
public bool RansomwareBetaEnabled { get; init; }
|
||||
public bool RansomwareBetaEnabled { get; init; } = true;
|
||||
|
||||
public bool RansomwareBetaAlertingEnabled { get; init; }
|
||||
|
||||
|
||||
@@ -9,10 +9,10 @@
|
||||
<RootNamespace>OCSentinelCli</RootNamespace>
|
||||
<Product>OfficeCom Sentinel</Product>
|
||||
<Company>OfficeCom</Company>
|
||||
<Version>1.5.0-beta.2</Version>
|
||||
<Version>1.5.0-beta.4</Version>
|
||||
<AssemblyVersion>1.5.0.0</AssemblyVersion>
|
||||
<FileVersion>1.5.0.0</FileVersion>
|
||||
<InformationalVersion>1.5.0-beta.2</InformationalVersion>
|
||||
<InformationalVersion>1.5.0-beta.4</InformationalVersion>
|
||||
</PropertyGroup>
|
||||
|
||||
<ItemGroup>
|
||||
|
||||
@@ -6,6 +6,13 @@ namespace OCSentinelCli.Tests;
|
||||
[SupportedOSPlatform("windows")]
|
||||
public sealed class RansomwareBetaTests
|
||||
{
|
||||
[Fact]
|
||||
public void RansomwareBetaIsEnabledByDefault()
|
||||
{
|
||||
Assert.True(new ScannerConfiguration().RansomwareBetaEnabled);
|
||||
Assert.False(new ScannerConfiguration().RansomwareBetaAlertingEnabled);
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void FileChurnBelowBothThresholdsDoesNotCreateSignal()
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user