sync
This commit is contained in:
@@ -0,0 +1,70 @@
|
||||
import requests
|
||||
import json
|
||||
import csv
|
||||
from datetime import datetime, timedelta
|
||||
|
||||
# Replace with your CrowdStrike API credentials
|
||||
CLIENT_ID = 'YOUR_CLIENT_ID'
|
||||
CLIENT_SECRET = 'YOUR_CLIENT_SECRET'
|
||||
|
||||
# Base URL for the CrowdStrike Falcon API
|
||||
BASE_URL = 'https://api.crowdstrike.com'
|
||||
|
||||
# Function to obtain an OAuth2 access token
|
||||
def get_access_token():
|
||||
url = f"{BASE_URL}/oauth2/token"
|
||||
headers = {'Content-Type': 'application/x-www-form-urlencoded'}
|
||||
data = {
|
||||
'client_id': CLIENT_ID,
|
||||
'client_secret': CLIENT_SECRET,
|
||||
'grant_type': 'client_credentials'
|
||||
}
|
||||
response = requests.post(url, headers=headers, data=data)
|
||||
response.raise_for_status()
|
||||
return response.json()['access_token']
|
||||
|
||||
# Function to fetch exposure management reports (V2 API)
|
||||
def get_exposure_management_reports(access_token):
|
||||
url = f"{BASE_URL}/spotlight/queries/reports/v2"
|
||||
headers = {
|
||||
'Authorization': f'Bearer {access_token}',
|
||||
'Accept': 'application/json'
|
||||
}
|
||||
|
||||
# Calculate the timestamp for 24 hours ago
|
||||
now = datetime.utcnow()
|
||||
twenty_four_hours_ago = now - timedelta(hours=24)
|
||||
timestamp_filter = twenty_four_hours_ago.strftime('%Y-%m-%dT%H:%M:%SZ')
|
||||
|
||||
# Filter for reports generated in the last 24 hours
|
||||
params = {
|
||||
'filter': f'created_on:>{timestamp_filter}'
|
||||
}
|
||||
|
||||
response = requests.get(url, headers=headers, params=params)
|
||||
response.raise_for_status()
|
||||
return response.json()['resources']
|
||||
|
||||
# Function to export a report as CSV (V2 API)
|
||||
def export_report_to_csv(report_id, access_token):
|
||||
url = f"{BASE_URL}/spotlight/entities/reports-executions/v1/{report_id}/download"
|
||||
headers = {'Authorization': f'Bearer {access_token}'}
|
||||
|
||||
response = requests.get(url, headers=headers)
|
||||
response.raise_for_status()
|
||||
|
||||
# Assuming the report content is in CSV format
|
||||
with open(f'{report_id}.csv', 'wb') as f:
|
||||
f.write(response.content)
|
||||
|
||||
# Main script execution
|
||||
if __name__ == '__main__':
|
||||
access_token = get_access_token()
|
||||
reports = get_exposure_management_reports(access_token)
|
||||
|
||||
if reports:
|
||||
most_recent_report_id = reports[0]['id']
|
||||
export_report_to_csv(most_recent_report_id, access_token)
|
||||
print(f"Exported report {most_recent_report_id} to CSV")
|
||||
else:
|
||||
print("No exposure management reports found in the last 24 hours")
|
||||
Reference in New Issue
Block a user