OfficeCom Sentinel

OfficeCom Sentinel is the hardened endpoint client for Windows event correlation, NinjaOne field updates, CVE correlation, and optional n8n upload.

Main Paths

  • CLI source: src/AttackTracerNinjaCli
  • local runner: scripts/run-ocsentinel.ps1
  • Ninja monitor wrapper: scripts/run-ocsentinel-monitor.ps1
  • packaged installer runtime: installer/runtime-run-ocsentinel.ps1
  • package builder: build/build-client-package.ps1
  • update manifest builder: build/build-release-manifest.ps1

Build

powershell -ExecutionPolicy Bypass -File .\build\build-client-package.ps1

This creates:

  • artifacts/OCSentinelClient-win-x64.zip
  • artifacts/OCSentinelClient-win-x64.zip.sha256

Release Manifest

powershell -ExecutionPolicy Bypass -File .\build\build-release-manifest.ps1 `
  -ArtifactUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v2.0.0/OCSentinelClient-win-x64.zip"

This creates:

  • artifacts/version.json

Compatibility

Legacy attacktracer script names are still present as wrappers so existing NinjaOne jobs do not break immediately. New work should use the ocsentinel script names.

Description
OfficeCom Sentinel client and deployment assets.
Readme 918 KiB
2026-08-03 01:18:36 +02:00
Languages
C# 40.2%
PowerShell 31.7%
Python 14.3%
HTML 9.1%
JavaScript 2.7%
Other 2%