38 lines
1.3 KiB
Markdown
38 lines
1.3 KiB
Markdown
# OfficeCom Sentinel Architecture
|
|
|
|
## Goal
|
|
|
|
OfficeCom Sentinel is a Windows endpoint client that:
|
|
|
|
- runs on every monitored device
|
|
- reads local attack telemetry and optional local vulnerability exports
|
|
- writes NinjaOne device custom fields locally
|
|
- uploads signed JSON reports to n8n
|
|
- receives updates through NinjaOne tasks from Gitea-hosted releases
|
|
|
|
## Current Model
|
|
|
|
The repository now keeps only the client-side architecture:
|
|
|
|
- endpoint scan and correlation
|
|
- local NinjaOne field publishing
|
|
- optional n8n upload
|
|
- packaged ZIP release flow for NinjaOne deployment
|
|
|
|
The client must not depend on a PostgreSQL IP or hostname. PostgreSQL stays a server-side concern behind the ingest or n8n layer.
|
|
|
|
## PostgreSQL Handling
|
|
|
|
- PostgreSQL is not contacted directly by endpoint clients.
|
|
- The PostgreSQL host or IP should be tracked in the repository only as internal deployment metadata.
|
|
- Review that internal target on every release before publishing.
|
|
- Keep the actual production value in a private operational copy if it should not be visible in the public repository.
|
|
|
|
## Removed Model
|
|
|
|
The following older pieces are intentionally no longer part of the repo:
|
|
|
|
- share-based organization aggregation
|
|
- dedicated server-side collector package
|
|
- server-side NinjaOne organization field updater
|