103 lines
3.1 KiB
Markdown
103 lines
3.1 KiB
Markdown
# AttackTracer Ninja CLI
|
|
|
|
## Purpose
|
|
|
|
`AttackTracerNinjaCli` is the first headless replacement for the legacy `AttackTracer` WinForms tool.
|
|
|
|
It keeps the useful detection behavior, but drops the old UI and external WCF dependencies.
|
|
|
|
## Current inputs
|
|
|
|
- Windows Security Event Log `4625`
|
|
- Windows Application Event Log `18456`
|
|
- Windows Application Event Log `1035`
|
|
- IIS FTP logs under:
|
|
- `C:\inetpub\logs\LogFiles`
|
|
- `D:\inetpub\logs\LogFiles`
|
|
- FileZilla Server logs under:
|
|
- `C:\Program Files (x86)\FileZilla Server\Logs`
|
|
- `D:\Program Files (x86)\FileZilla Server\Logs`
|
|
|
|
## Current outputs
|
|
|
|
- human-readable console summary
|
|
- JSON report for later collection by `ninja1`
|
|
- optional `ATTACKTRACER_*` key/value lines for RMM parsing
|
|
- optional correlation with exported NinjaOne CVE data for the local device
|
|
|
|
## Usage
|
|
|
|
```powershell
|
|
dotnet run --project .\src\AttackTracerNinjaCli -- --output .\reports\attacktracer-summary.json
|
|
```
|
|
|
|
Or through the wrapper script:
|
|
|
|
```powershell
|
|
.\scripts\run-attacktracer-ninja.ps1 -LookbackDays 7 -TopCount 10 -FailOnThreshold
|
|
```
|
|
|
|
With vulnerability correlation:
|
|
|
|
```powershell
|
|
.\scripts\run-attacktracer-ninja.ps1 -LookbackDays 7 -TopCount 10 -VulnerabilityCsvPath .\samples\ninja-vulnerability-export.example.csv
|
|
```
|
|
|
|
Useful flags:
|
|
|
|
- `--json-only`
|
|
- `--lookback-days 7`
|
|
- `--top 20`
|
|
- `--config .\config\attacktracer-settings.example.json`
|
|
- `--ninja-output`
|
|
- `--fail-on-attacks`
|
|
- `--fail-on-threshold`
|
|
- `--vulnerability-csv .\path\to\ninja-export.csv`
|
|
|
|
## Configuration
|
|
|
|
A sample config is available at [config/attacktracer-settings.example.json](C:\Users\Besitzer\Documents\AttackTracerNinjaVersion\config\attacktracer-settings.example.json).
|
|
|
|
It currently supports:
|
|
|
|
- warning and critical thresholds
|
|
- correlation thresholds for local CVE findings
|
|
- FTP root overrides
|
|
- FileZilla root overrides
|
|
- source IP exclusions
|
|
|
|
## CVE correlation
|
|
|
|
You can correlate AttackTracer findings with exported vulnerability data for the current host.
|
|
|
|
Expected minimum CSV columns:
|
|
|
|
- a device-name column such as `device`, `hostname`, or `computername`
|
|
- a CVE column such as `cve` or `cve_id`
|
|
|
|
Optional columns:
|
|
|
|
- `severity`
|
|
- `cvss`
|
|
- `remediation`
|
|
|
|
A sample file is available at [samples/ninja-vulnerability-export.example.csv](C:\Users\Besitzer\Documents\AttackTracerNinjaVersion\samples\ninja-vulnerability-export.example.csv).
|
|
|
|
## Next integration step
|
|
|
|
The intended `ninja1` path is:
|
|
|
|
1. run the installed monitor wrapper from a NinjaOne script or scheduled task
|
|
2. let the monitor wrapper write endpoint-level NinjaOne custom fields when `Ninja-Property-Set` or `ninjarmm-cli` is available
|
|
3. collect the JSON artifact if you want deeper troubleshooting data
|
|
4. use the custom fields and/or `ATTACKTRACER_*` console lines for alerting
|
|
|
|
For organization-level reporting, you can mirror each device JSON report to a shared folder and render a local HTML summary using [docs/ninjaone-org-report-playbook.md](C:\Users\Besitzer\Documents\AttackTracerNinjaVersion\docs\ninjaone-org-report-playbook.md).
|
|
|
|
## Deliberate omissions for v1
|
|
|
|
- no geolocation
|
|
- no email sending
|
|
- no WinForms UI
|
|
- no dependency on legacy HTTP services
|