Files
personal_development/Crowdstrike/ExposureReports.py
T
2025-08-04 12:58:29 -04:00

70 lines
2.3 KiB
Python

import requests
import json
import csv
from datetime import datetime, timedelta
# Replace with your CrowdStrike API credentials
CLIENT_ID = 'YOUR_CLIENT_ID'
CLIENT_SECRET = 'YOUR_CLIENT_SECRET'
# Base URL for the CrowdStrike Falcon API
BASE_URL = 'https://api.crowdstrike.com'
# Function to obtain an OAuth2 access token
def get_access_token():
url = f"{BASE_URL}/oauth2/token"
headers = {'Content-Type': 'application/x-www-form-urlencoded'}
data = {
'client_id': CLIENT_ID,
'client_secret': CLIENT_SECRET,
'grant_type': 'client_credentials'
}
response = requests.post(url, headers=headers, data=data)
response.raise_for_status()
return response.json()['access_token']
# Function to fetch exposure management reports (V2 API)
def get_exposure_management_reports(access_token):
url = f"{BASE_URL}/spotlight/queries/reports/v2"
headers = {
'Authorization': f'Bearer {access_token}',
'Accept': 'application/json'
}
# Calculate the timestamp for 24 hours ago
now = datetime.utcnow()
twenty_four_hours_ago = now - timedelta(hours=24)
timestamp_filter = twenty_four_hours_ago.strftime('%Y-%m-%dT%H:%M:%SZ')
# Filter for reports generated in the last 24 hours
params = {
'filter': f'created_on:>{timestamp_filter}'
}
response = requests.get(url, headers=headers, params=params)
response.raise_for_status()
return response.json()['resources']
# Function to export a report as CSV (V2 API)
def export_report_to_csv(report_id, access_token):
url = f"{BASE_URL}/spotlight/entities/reports-executions/v1/{report_id}/download"
headers = {'Authorization': f'Bearer {access_token}'}
response = requests.get(url, headers=headers)
response.raise_for_status()
# Assuming the report content is in CSV format
with open(f'{report_id}.csv', 'wb') as f:
f.write(response.content)
# Main script execution
if __name__ == '__main__':
access_token = get_access_token()
reports = get_exposure_management_reports(access_token)
if reports:
most_recent_report_id = reports[0]['id']
export_report_to_csv(most_recent_report_id, access_token)
print(f"Exported report {most_recent_report_id} to CSV")
else:
print("No exposure management reports found in the last 24 hours")