-
Notifications
You must be signed in to change notification settings - Fork 259
feat: add config-critical-systems cmd #1582
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
help |
when config/critical_systems.txt not exists |
when config/critical_systems.txt exists |
csv-timelineafter config-critical-systems execution |
|
@fukusuket Looking good! Thanks so much! |
|
@YamatoSecurity |
|
@fukusuket Sorry, small issue. Can you require either the |
YamatoSecurity
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Humm.. It seems like it does not save the file now.
DomainController found (3):
01566s-win16-ir.threebeesco.com
DC-Server-1.labcorp.local
rootdc1.offsec.lan
Would you like to add them to the config/critical_systems.txt file? (Y/n):
FileServer found (10):
01566s-win16-ir.threebeesco.com
FS03.offsec.lan
IEWIN7
PC01.example.corp
WIN-77LTAPHIQ1R.example.corp
fs01.offsec.lan
fs02.offsec.lan
fs03vuln.offsec.lan
rootdc1.offsec.lan
srvdefender01.offsec.lan
Would you like to add them to the config/critical_systems.txt file? (Y/n):
千里の道も一歩から - Senri No Michi Mo Ippo Kara - A journey of a thousand miles begins with a single step.
hayabusa % cat config/critical_systems.txt
hayabusa %
Also, can you change DomainController found to Domain Controllers found and FileServer found to File Servers found?
|
I thought it might be because i was running |
|
One more thing, it looks a little weird after the |
|
Can you add the message |
|
@YamatoSecurity |
|
@fukusuket The UI is looking great now! Running against some test data, I found some false positives using the EID 5140 event so I think we should just determine it based on EID 5145. Could you remove the checking of EID 5140? |
|
@YamatoSecurity |
YamatoSecurity
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@fukusuket LGTM! Everything looks perfect! Thanks so much!!
What Changed
config-critical-systemscommand #1570Evidence
Integration-Test
https://github.com/Yamato-Security/hayabusa/actions/runs/13343546597
I would appreciate it if you could check it out when you have time🙏