Files
oc-sentinel/docs/attacktracer-ninja-v2-deployment.md
OfficeCom Codex 85e394f647
Some checks failed
OfficeCom Sentinel Client / build-client (push) Has been cancelled
Adopt OCSentinel script layout and add Gitea workflow
2026-07-17 00:50:26 +02:00

2.8 KiB

OfficeCom Sentinel Deployment

Goal

Deploy and update the endpoint client through NinjaOne while hosting release artifacts in Gitea.

Release assets

Each Gitea release should publish:

  • OCSentinelClient-win-x64.zip
  • OCSentinelClient-win-x64.zip.sha256
  • version.json

Build these locally with:

powershell -ExecutionPolicy Bypass -File .\build\build-client-package.ps1
powershell -ExecutionPolicy Bypass -File .\build\build-release-manifest.ps1 `
  -ArtifactUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v2.0.0/OCSentinelClient-win-x64.zip"

See example manifest:

Endpoint package contents

The installed package should include:

  • app\OCSentinelCli.exe
  • scripts\run-ocsentinel.ps1
  • scripts\run-ocsentinel-monitor.ps1
  • scripts\update-ocsentinel.ps1
  • scripts\protect-ocsentinel-secret.ps1
  • config\ocsentinel-settings.json
  • config\ocsentinel-client.json

Initial install through NinjaOne

Recommended NinjaOne task:

& "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" `
  -ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v2.0.0/version.json" `
  -Force

If the client is not installed yet, you can also first distribute a bootstrap ZIP or setup package, then switch to the updater-only model.

Routine update task

Recommended scheduled task command:

& "C:\Program Files\OCSentinel\scripts\update-ocsentinel.ps1" `
  -ManifestUrl "https://gitea.officecom.cloud/officecom/oc-sentinel/releases/download/v2.0.0/version.json"

Behavior

The updater:

  1. downloads the manifest
  2. compares installed and available version
  3. downloads the ZIP only when newer
  4. validates SHA-256
  5. validates Authenticode signature when present
  6. runs the package installer

Secret bootstrap

After installation, provision the upload secret once:

& "C:\Program Files\OCSentinel\scripts\protect-ocsentinel-secret.ps1" `
  -SecretValue "<shared-ingest-secret>"

This writes a DPAPI-protected file under:

  • C:\ProgramData\OCSentinel\secrets\ocsentinel-upload-secret.dat

Runtime task

Recommended runtime task:

& "C:\Program Files\OCSentinel\scripts\run-ocsentinel-monitor.ps1" `
  -Mode status `
  -OutputPath "..\reports\ocsentinel-summary.json"

Upload is enabled automatically when:

  • config\ocsentinel-client.json exists
  • the protected secret file exists

Otherwise the client falls back to local scan behavior.

Migration guidance

During migration you can keep old share-based logic disabled by default and only enable the new n8n upload path as secrets and webhook config become available.