import requests import json import csv from datetime import datetime, timedelta # Replace with your CrowdStrike API credentials CLIENT_ID = 'YOUR_CLIENT_ID' CLIENT_SECRET = 'YOUR_CLIENT_SECRET' # Base URL for the CrowdStrike Falcon API BASE_URL = 'https://api.crowdstrike.com' # Function to obtain an OAuth2 access token def get_access_token(): url = f"{BASE_URL}/oauth2/token" headers = {'Content-Type': 'application/x-www-form-urlencoded'} data = { 'client_id': CLIENT_ID, 'client_secret': CLIENT_SECRET, 'grant_type': 'client_credentials' } response = requests.post(url, headers=headers, data=data) response.raise_for_status() return response.json()['access_token'] # Function to fetch exposure management reports (V2 API) def get_exposure_management_reports(access_token): url = f"{BASE_URL}/spotlight/queries/reports/v2" headers = { 'Authorization': f'Bearer {access_token}', 'Accept': 'application/json' } # Calculate the timestamp for 24 hours ago now = datetime.utcnow() twenty_four_hours_ago = now - timedelta(hours=24) timestamp_filter = twenty_four_hours_ago.strftime('%Y-%m-%dT%H:%M:%SZ') # Filter for reports generated in the last 24 hours params = { 'filter': f'created_on:>{timestamp_filter}' } response = requests.get(url, headers=headers, params=params) response.raise_for_status() return response.json()['resources'] # Function to export a report as CSV (V2 API) def export_report_to_csv(report_id, access_token): url = f"{BASE_URL}/spotlight/entities/reports-executions/v1/{report_id}/download" headers = {'Authorization': f'Bearer {access_token}'} response = requests.get(url, headers=headers) response.raise_for_status() # Assuming the report content is in CSV format with open(f'{report_id}.csv', 'wb') as f: f.write(response.content) # Main script execution if __name__ == '__main__': access_token = get_access_token() reports = get_exposure_management_reports(access_token) if reports: most_recent_report_id = reports[0]['id'] export_report_to_csv(most_recent_report_id, access_token) print(f"Exported report {most_recent_report_id} to CSV") else: print("No exposure management reports found in the last 24 hours")