91 lines
3.8 KiB
Python
91 lines
3.8 KiB
Python
import datetime
|
|
import requests
|
|
import json
|
|
import os
|
|
import time
|
|
|
|
def allowlistexechistories(url, outputjson: bool):
|
|
endpoint = url + '/v1/group'
|
|
print("[+] Grabbing All Policies")
|
|
payload = {}
|
|
headers = {
|
|
"X-APIKey": os.getenv('APIKEY')
|
|
}
|
|
response = requests.request("POST", endpoint, headers=headers, data=payload, verify=False)
|
|
parse_text = json.loads(response.text)
|
|
policiesnames = []
|
|
policyids = []
|
|
for index, list in enumerate(parse_text['response']['groups'], start=1):
|
|
print(f"{index}. {list['name']}")
|
|
policiesnames.append(list['name'])
|
|
policyids.append(list['groupid'])
|
|
choice = input("Select Policy Group: ")
|
|
choice = int(choice) - 1
|
|
checkpoint = '000000000000000000000000'
|
|
json_output = {'error': 'Success', 'response': {'exechistories': []}}
|
|
while True:
|
|
json_response_data = checkpoint_stomper(checkpoint, url, policiesnames[choice], headers)
|
|
if not json_response_data['response']['exechistories']:
|
|
break
|
|
for index, item in enumerate(json_response_data['response']['exechistories']):
|
|
if index == len(json_response_data['response']['exechistories']) -1:
|
|
checkpoint = item['checkpoint']
|
|
print(f"Date Greater than 30 Days, Stepping to new Checkpoint. {item['checkpoint']}")
|
|
else:
|
|
if (datetime.date.today() - datetime.timedelta(days=1) > datetime.datetime.strptime(item['datetime'].replace(' +0000 UTC', ''), '%Y-%m-%dT%H:%M:%SZ').date()):
|
|
pass
|
|
else:
|
|
#json_output['response']['exechistories'].append(json_response_data['response']['exechistories'][1])
|
|
for output in json_response_data['response']['exechistories']:
|
|
json_output['response']['exechistories'].append(output)
|
|
json_output = json.dumps(json_output)
|
|
if outputjson == True:
|
|
return json_output
|
|
#endpoint = url + '/v1/logging/exechistories'
|
|
#payload_dict = {
|
|
# "type":[1, 2, 6, 7],
|
|
# "checkpoint":"000000000000000000000000",
|
|
# "policy": [policiesnames[choice]]
|
|
#}
|
|
#payload = json.dumps(payload_dict)
|
|
#print(payload)
|
|
#response = requests.request("POST", endpoint, headers=headers, data=payload, verify=False)
|
|
#parse_text = json.loads(response.text)
|
|
#text_response = checkpoint_stomper(parse_text['response']['exechistories'], url, policiesnames[choice])
|
|
#
|
|
#if outputjson == False:
|
|
# return response
|
|
#
|
|
#parse_text = json.loads(response.text)
|
|
#
|
|
#for item in parse_text['response']['exechistories']:
|
|
# print(item['checkpoint'])
|
|
# print(item['datetime'])
|
|
# print(item['hostname'])
|
|
# print(item['filename'])
|
|
# checkpoint_stomper(item['checkpoint'], endpoint, headers, policiesnames[choice])
|
|
|
|
def checkpoint_stomper(checkpoint, url, policy, headers):
|
|
endpoint = url + '/v1/logging/exechistories'
|
|
payload_dict = {
|
|
"type":[1,2,6,7],
|
|
"checkpoint": checkpoint,
|
|
"policy": [policy]
|
|
}
|
|
payload = json.dumps(payload_dict)
|
|
response = requests.request("POST", endpoint, headers=headers, data=payload, verify=False)
|
|
parse_text = json.loads(response.text)
|
|
return parse_text
|
|
#for index, item in enumerate(parse_text):
|
|
# if index == len(parse_text) - 1:
|
|
# checkpoint = item['checkpoint']
|
|
# print(f"Time: {item['datetime']} Checkpoint: {item['checkpoint']}")
|
|
# response_fuzzer(checkpoint, url, policyname)
|
|
# else:
|
|
# if (datetime.date.today() - datetime.timedelta(days=30) > datetime.datetime.strptime(item['datetime'].replace( ' +0000 UTC', ''), '%Y-%m-%dT%H:%M:%SZ').date()):
|
|
# pass
|
|
# else:
|
|
# response_fuzzer(checkpoint, url, policyname)
|
|
|
|
|
|
print("Finished") |