-
Notifications
You must be signed in to change notification settings - Fork 0
/
hosts.go
110 lines (98 loc) · 3.13 KB
/
hosts.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
package core
/*
Sliver Implant Framework
Copyright (C) 2021 Bishop Fox
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
import (
"errors"
consts "github.com/starkzarn/glod/client/constants"
"github.com/starkzarn/glod/server/db"
"github.com/starkzarn/glod/server/db/models"
"github.com/starkzarn/glod/server/log"
"github.com/gofrs/uuid"
"gorm.io/gorm"
)
var (
coreLog = log.NamedLogger("core", "hosts")
)
// StartEventAutomation - Starts an event automation goroutine
func StartEventAutomation() {
go func() {
for event := range EventBroker.Subscribe() {
switch event.EventType {
case consts.BeaconRegisteredEvent:
if event.Beacon != nil {
hostsBeaconCallback(event.Beacon)
}
case consts.SessionOpenedEvent:
if event.Session != nil {
hostsSessionCallback(event.Session)
}
}
}
}()
}
// Triggered on new session events, checks to see if the host is in
// the database and adds it if not.
func hostsSessionCallback(session *Session) {
coreLog.Debugf("Hosts session callback for %v", session.UUID)
dbSession := db.Session()
host, err := db.HostByHostUUID(session.UUID)
coreLog.Debugf("Hosts query result: %v %v", host, err)
if err != nil && !errors.Is(err, gorm.ErrRecordNotFound) {
coreLog.Error(err)
return
}
if errors.Is(err, gorm.ErrRecordNotFound) {
coreLog.Infof("Session %v is from a new host", session.ID)
err := dbSession.Create(&models.Host{
HostUUID: uuid.FromStringOrNil(session.UUID),
Hostname: session.Hostname,
OSVersion: session.OS,
Locale: session.Locale,
IOCs: []models.IOC{},
ExtensionData: []models.ExtensionData{},
}).Error
if err != nil {
coreLog.Error(err)
return
}
}
}
// Triggered on new beacon events, checks to see if the host is in
// the database and adds it if not.
func hostsBeaconCallback(beacon *models.Beacon) {
coreLog.Debugf("Hosts beacon callback for %v", beacon.UUID)
dbSession := db.Session()
host, err := db.HostByHostUUID(beacon.UUID.String())
coreLog.Debugf("Hosts query result: %v %v", host, err)
if err != nil && !errors.Is(err, gorm.ErrRecordNotFound) {
coreLog.Error(err)
return
}
if errors.Is(err, gorm.ErrRecordNotFound) {
coreLog.Infof("Beacon %v is from a new host", beacon.ID)
err := dbSession.Create(&models.Host{
HostUUID: uuid.FromStringOrNil(beacon.UUID.String()),
Hostname: beacon.Hostname,
OSVersion: beacon.OS,
Locale: beacon.Locale,
IOCs: []models.IOC{},
ExtensionData: []models.ExtensionData{},
}).Error
if err != nil {
coreLog.Error(err)
return
}
}
}