Iterate through all checkpoints and add the json responses to the return output for the hash functions script
This commit is contained in:
@@ -1 +1,2 @@
|
||||
.env
|
||||
*.html
|
||||
-62550
File diff suppressed because one or more lines are too long
+1
-1
@@ -1,4 +1,4 @@
|
||||
pandas==2.3.1
|
||||
pandas==2.3.2
|
||||
python-dotenv==1.1.1
|
||||
Requests==2.32.5
|
||||
urllib3==2.5.0
|
||||
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+57
-27
@@ -2,6 +2,7 @@ import datetime
|
||||
import requests
|
||||
import json
|
||||
import os
|
||||
import time
|
||||
|
||||
def allowlistexechistories(url, outputjson: bool):
|
||||
endpoint = url + '/v1/group'
|
||||
@@ -20,39 +21,68 @@ def allowlistexechistories(url, outputjson: bool):
|
||||
policyids.append(list['groupid'])
|
||||
choice = input("Select Policy Group: ")
|
||||
choice = int(choice) - 1
|
||||
checkpoint = '000000000000000000000000'
|
||||
json_output = {'error': 'Success', 'response': {'exechistories': []}}
|
||||
while True:
|
||||
json_response_data = checkpoint_stomper(checkpoint, url, policiesnames[choice], headers)
|
||||
if not json_response_data['response']['exechistories']:
|
||||
break
|
||||
for index, item in enumerate(json_response_data['response']['exechistories']):
|
||||
if index == len(json_response_data['response']['exechistories']) -1:
|
||||
checkpoint = item['checkpoint']
|
||||
print(f"Date Greater than 30 Days, Stepping to new Checkpoint. {item['checkpoint']}")
|
||||
else:
|
||||
if (datetime.date.today() - datetime.timedelta(days=1) > datetime.datetime.strptime(item['datetime'].replace(' +0000 UTC', ''), '%Y-%m-%dT%H:%M:%SZ').date()):
|
||||
pass
|
||||
else:
|
||||
json_output['response']['exechistories'].append(json_response_data['response']['exechistories'])
|
||||
if outputjson == True:
|
||||
return (json_output)
|
||||
#endpoint = url + '/v1/logging/exechistories'
|
||||
#payload_dict = {
|
||||
# "type":[1, 2, 6, 7],
|
||||
# "checkpoint":"000000000000000000000000",
|
||||
# "policy": [policiesnames[choice]]
|
||||
#}
|
||||
#payload = json.dumps(payload_dict)
|
||||
#print(payload)
|
||||
#response = requests.request("POST", endpoint, headers=headers, data=payload, verify=False)
|
||||
#parse_text = json.loads(response.text)
|
||||
#text_response = checkpoint_stomper(parse_text['response']['exechistories'], url, policiesnames[choice])
|
||||
#
|
||||
#if outputjson == False:
|
||||
# return response
|
||||
#
|
||||
#parse_text = json.loads(response.text)
|
||||
#
|
||||
#for item in parse_text['response']['exechistories']:
|
||||
# print(item['checkpoint'])
|
||||
# print(item['datetime'])
|
||||
# print(item['hostname'])
|
||||
# print(item['filename'])
|
||||
# checkpoint_stomper(item['checkpoint'], endpoint, headers, policiesnames[choice])
|
||||
|
||||
def checkpoint_stomper(checkpoint, url, policy, headers):
|
||||
endpoint = url + '/v1/logging/exechistories'
|
||||
payload_dict = {
|
||||
"type":[1, 2, 6, 7],
|
||||
"checkpoint":"68a153c23963989b484541b4",
|
||||
"policy": [policiesnames[choice]]
|
||||
}
|
||||
payload = json.dumps(payload_dict)
|
||||
print(payload)
|
||||
response = requests.request("POST", endpoint, headers=headers, data=payload, verify=False)
|
||||
|
||||
if outputjson == True:
|
||||
return response
|
||||
|
||||
parse_text = json.loads(response.text)
|
||||
|
||||
for item in parse_text['response']['exechistories']:
|
||||
print(item['checkpoint'])
|
||||
print(item['datetime'])
|
||||
print(item['hostname'])
|
||||
print(item['filename'])
|
||||
# checkpoint_stomper(item['checkpoint'], endpoint, headers, policiesnames[choice])
|
||||
|
||||
def checkpoint_stomper(checkpoint, endpoint, headers, policyname):
|
||||
print(checkpoint)
|
||||
payload_dict = {
|
||||
"type":[1,2,6,7],
|
||||
"checkpoint": checkpoint,
|
||||
"policy":[policyname]
|
||||
"policy": [policy]
|
||||
}
|
||||
payload = json.dumps(payload_dict)
|
||||
response = requests.request("POST", endpoint, headers=headers, data=payload, verify=False)
|
||||
parse_text = json.loads(response.text)
|
||||
# Send Whole JSON Response
|
||||
for item in parse_text['response']['exechistories']:
|
||||
print("test")
|
||||
return parse_text
|
||||
#for index, item in enumerate(parse_text):
|
||||
# if index == len(parse_text) - 1:
|
||||
# checkpoint = item['checkpoint']
|
||||
# print(f"Time: {item['datetime']} Checkpoint: {item['checkpoint']}")
|
||||
# response_fuzzer(checkpoint, url, policyname)
|
||||
# else:
|
||||
# if (datetime.date.today() - datetime.timedelta(days=30) > datetime.datetime.strptime(item['datetime'].replace( ' +0000 UTC', ''), '%Y-%m-%dT%H:%M:%SZ').date()):
|
||||
# pass
|
||||
# else:
|
||||
# response_fuzzer(checkpoint, url, policyname)
|
||||
|
||||
|
||||
print("Finished")
|
||||
@@ -8,7 +8,7 @@ def aggregateHashes(executions_json) -> pd.DataFrame:
|
||||
"""
|
||||
Takes the executions, aggregates all the data with sha256 as primary, then returns aggregated dataframe
|
||||
"""
|
||||
data = executions_json.json()
|
||||
data = executions_json
|
||||
df = pd.DataFrame(data["response"]["exechistories"])
|
||||
|
||||
if df.empty:
|
||||
|
||||
Reference in New Issue
Block a user