70 lines
2.3 KiB
Python
70 lines
2.3 KiB
Python
import requests
|
|
import json
|
|
import csv
|
|
from datetime import datetime, timedelta
|
|
|
|
# Replace with your CrowdStrike API credentials
|
|
CLIENT_ID = 'YOUR_CLIENT_ID'
|
|
CLIENT_SECRET = 'YOUR_CLIENT_SECRET'
|
|
|
|
# Base URL for the CrowdStrike Falcon API
|
|
BASE_URL = 'https://api.crowdstrike.com'
|
|
|
|
# Function to obtain an OAuth2 access token
|
|
def get_access_token():
|
|
url = f"{BASE_URL}/oauth2/token"
|
|
headers = {'Content-Type': 'application/x-www-form-urlencoded'}
|
|
data = {
|
|
'client_id': CLIENT_ID,
|
|
'client_secret': CLIENT_SECRET,
|
|
'grant_type': 'client_credentials'
|
|
}
|
|
response = requests.post(url, headers=headers, data=data)
|
|
response.raise_for_status()
|
|
return response.json()['access_token']
|
|
|
|
# Function to fetch exposure management reports (V2 API)
|
|
def get_exposure_management_reports(access_token):
|
|
url = f"{BASE_URL}/spotlight/queries/reports/v2"
|
|
headers = {
|
|
'Authorization': f'Bearer {access_token}',
|
|
'Accept': 'application/json'
|
|
}
|
|
|
|
# Calculate the timestamp for 24 hours ago
|
|
now = datetime.utcnow()
|
|
twenty_four_hours_ago = now - timedelta(hours=24)
|
|
timestamp_filter = twenty_four_hours_ago.strftime('%Y-%m-%dT%H:%M:%SZ')
|
|
|
|
# Filter for reports generated in the last 24 hours
|
|
params = {
|
|
'filter': f'created_on:>{timestamp_filter}'
|
|
}
|
|
|
|
response = requests.get(url, headers=headers, params=params)
|
|
response.raise_for_status()
|
|
return response.json()['resources']
|
|
|
|
# Function to export a report as CSV (V2 API)
|
|
def export_report_to_csv(report_id, access_token):
|
|
url = f"{BASE_URL}/spotlight/entities/reports-executions/v1/{report_id}/download"
|
|
headers = {'Authorization': f'Bearer {access_token}'}
|
|
|
|
response = requests.get(url, headers=headers)
|
|
response.raise_for_status()
|
|
|
|
# Assuming the report content is in CSV format
|
|
with open(f'{report_id}.csv', 'wb') as f:
|
|
f.write(response.content)
|
|
|
|
# Main script execution
|
|
if __name__ == '__main__':
|
|
access_token = get_access_token()
|
|
reports = get_exposure_management_reports(access_token)
|
|
|
|
if reports:
|
|
most_recent_report_id = reports[0]['id']
|
|
export_report_to_csv(most_recent_report_id, access_token)
|
|
print(f"Exported report {most_recent_report_id} to CSV")
|
|
else:
|
|
print("No exposure management reports found in the last 24 hours") |