Skip to content

Ghostwriter v3.0.3

Choose a tag to compare

@chrismaddalena chrismaddalena released this 06 Aug 01:01
· 3807 commits to master since this release
3e896bf

Summary

This release includes changes from the unreleased v3.0.1 and v3.0.2 hotfix releases. Changes address some small issues reported by users, improvements to the GraphQL API to support mythic_sync v2 and other external projects, and quality of life improvements.

CHANGELOG

[3.0.3] - 5 August 2022

Added

  • Added the CSRF_TRUSTED_ORIGINS to the base configuration to make it easier to add trusted origins for accessing Ghostwriter via a web proxy
  • Oplog ID now appears at the top of the log entries view for easier identification
  • Committed Ghostwriter CLI binaries (v0.2.2) for Windows, macOS, and Linux
  • Added project notes to the serialized report data as a list under project.notes (Closes #210)

Fixed

  • Fixed "Stand by" message appearing for all users viewing a report when one user generates a report
  • Fixed domain expiration dates not sorting properly in the domain table when date format is changed
  • Fixed operation log entries not loading if null values were present from GraphQL submissions
  • Fixed complete field being required for reported findings but unavailable in the GraphQL schema (Fixes #226)
  • Fixed log entry tables not showing "No entries to display" row when no entries are available
  • Fixed an issue that could cause an error when making a new activity log with a name longer than 50 characters
  • Fixed minor issue that could prevent PowerPoint generation if multiple evidence images were stacked on top of each other inside a list
  • Removed duplicate toast message displayed after the successful creation of a new oplog
  • Fixed GraphQL configuration that could cause webhook authentication to fail
  • Fixed server error when trying to view entries for an oplog that does not exist

Changed

  • Set defaults on some fields to make it easier to insert new domains, objectives, and findings via GraphQL
    • New domains will now default to WHOIS enabled, healthy, and available
    • Objectives will now default to primary priority and position one (top of the list)
    • Reported findings will now insert into position one (top of the list for its severity category)
  • Log entry fields can now be null to make it easier to insert new entries via GraphQL
  • Improved log entry view to make it easier to view logs
  • Users with the manager role can now update and delete protected report templates
  • User accounts can now be filtered by role in the admin panel
  • Removed GraphQL operatorName field preset to allow this value to be set by the user
  • Groups are now hidden on the user profile unless a user is part of a group
  • Adjusted client and project dashboards for better display of information and controls
  • Display of client's timezone has been changed to display the client's current date and time with the abbreviated timezone name
  • API keys now start with an initial expiry date that is +1 day from the current date
  • Project descriptions are now truncated after 35 words to make lengthy descriptions more readable in some sections of the UI
  • Infrastructure notes under the project dashboard are now inside collapsible sections for easier reading
  • Upgraded Ghostwriter CLI binaries to v0.2.3