VakarisZ
beafc0bf9e
Merge pull request #1493 from guardicore/credential_duplication_fix
...
Duplicate credentials in system info telem
2021-09-28 13:49:21 +03:00
VakarisZ
d240427ce2
Remove mimikatz field from sensitive fields in telemetries since telemetries no longer contain such key
2021-09-28 13:09:06 +03:00
VakarisZ
27e2969e79
Remove the unnecessary "mimikatz" info from telemetry data since the exact same data is stored under "credentials" key
2021-09-28 13:03:10 +03:00
VakarisZ
e40c83c2ff
Merge pull request #1485 from guardicore/telemetry_encryption
...
Telemetry encryption in database
2021-09-28 12:18:12 +03:00
VakarisZ
8b9ddb0c4b
Removed unnecessary vulture ignores from whitelist
2021-09-28 11:04:42 +03:00
VakarisZ
d79892427b
Moved credential encryption in mongo CHANGELOG.md entry from Fixes to Security
2021-09-28 11:04:42 +03:00
VakarisZ
a24eb841c1
Extract DAL interface for report model into a separate report_dal.py file
2021-09-28 11:04:42 +03:00
VakarisZ
1160ac6af0
Refactor dictionary and sensitive mongo field encryption by moving it to server_utils/encryption
2021-09-28 11:04:42 +03:00
Mike Salvatore
67262e19d1
Merge pull request #1492 from guardicore/1484/faq-network-limitations
...
docs: Add faq for limiting monkey propagation
2021-09-27 14:30:57 -04:00
MarketingYeti
4b0bed8267
Docs: Edits to monkey propagation FAQ section
2021-09-27 14:29:10 -04:00
Mike Salvatore
c16cff7b32
Docs: Wrap lines in monkey propagation section of FAQ
2021-09-27 12:43:46 -04:00
Mike Salvatore
cd937802d7
Docs: Edits to monkey propagation FAQ section
2021-09-27 12:42:46 -04:00
Ilija Lazoroski
faef27a7d1
docs: Add faq for limiting monkey propagation
2021-09-27 16:58:25 +02:00
VakarisZ
8b9973238e
Add CHANGELOG.md entry about fixed plaintext credentials in mongodb
2021-09-27 16:59:11 +03:00
VakarisZ
46f263be5f
Separate the telemetry document from telemetry_dal, also extracted external interface into __init__.py files
2021-09-27 16:56:45 +03:00
VakarisZ
51f6fbe356
Adjust island conftest.py to also rename the encryptor to datastore_encryptor
2021-09-27 16:29:41 +03:00
Shreya Malviya
96c525d656
docs: Add upward right arrow icon to external links
...
Taken from
https://www.jayeless.net/2021/08/hugo-mark-external-links.html
2021-09-27 07:51:15 -04:00
VakarisZ
87809c46c1
Fix breaking PBA file upload unit tests on windows.
...
The tests broke because `get` endpoint opened up the file handle which was not closed anywhere. The delete endpoint couldn't delete the file, since a process was using it.
2021-09-27 07:47:51 -04:00
VakarisZ
ace60052da
Alter usages of telemetry collection in report to store/fetch system info telemetry using the Telemetry model
...
This is required to automatically encrypt/decrypt the telemetries and it's a good practice to have a DAL for telemetries
2021-09-24 13:31:26 +03:00
VakarisZ
e6ad125be9
Change the telemetry model to have a method for fetching the telemetries based on queries.
...
Telemetry code mainly uses queries and mongoengine has no good way of field encryption, that's why this method prefers to handle queries rather than Telemetry models
2021-09-24 13:31:26 +03:00
VakarisZ
3781095f25
Change the mock database name to "db", because all of the codebase is using this database.
...
This change enables us to write unit tests without the need to patch the the database name in all of the mongo queries that look like "mongo.db.collection"
2021-09-24 13:31:26 +03:00
VakarisZ
1ab0fe7b13
Add Telemetry model
2021-09-24 13:31:26 +03:00
VakarisZ
989d0ffd84
Add unit tests for telemetry model
2021-09-24 13:31:26 +03:00
VakarisZ
b2db5e77c4
Change test_string_list_encryptor.py to re-use fixture "uses_encryptor" rather than implementing the same fixture locally
2021-09-24 13:31:23 +03:00
VakarisZ
854ce4e1e1
Refactor DocumentEncryptor class into a series of methods.
...
DocumentEncryptor class serves no purpose because it holds no state, sensitive_fields can be passed as a parameter to methods
2021-09-24 13:30:28 +03:00
VakarisZ
f3865d022b
Change mongomock_fixtures.py to drop the whole database instead of specified collections.
...
This makes it easier to add new database related tests, because we no longer need to modify the mongomock_fixtures.py to also drop a particular collection we are testing.
2021-09-24 13:30:27 +03:00
VakarisZ
f1c7cf4047
Generalize report_encryptor.py into document_encryptor.py and extract the sensitive fields to report_encryptor.py
2021-09-24 13:30:27 +03:00
Mike Salvatore
089158a976
Agent: Remove editable pyspnego degendency
...
pyspnego v0.2.0 has been released, so we no longer need to specify a git
commit hash in order to get the correct version.
2021-09-23 14:14:32 -04:00
Mike Salvatore
1996387cc5
Remove unnecessary # noqa: E402 from __init__.py files
2021-09-23 13:39:48 -04:00
Mike Salvatore
f0a2a43d51
Remove unnecessary # noqa: F401 from __init__.py files
2021-09-23 13:38:47 -04:00
Mike Salvatore
8b7cb9c0b1
Merge pull request #1481 from guardicore/1471/merge-encryptions
...
Refactor encryptors
2021-09-23 13:38:00 -04:00
Ilija Lazoroski
e2ede28967
Island: Rename get_encryptor and initialize_encryptor
...
Renamed to get_datastore_encryptor and
initialize_datastore_encryptor
2021-09-23 19:04:22 +02:00
Ilija Lazoroski
e0779347b2
Island: Add all imports from encryption to __init__
...
Now the imports are shorter by one directory.
Check the __init__ in encryption.
2021-09-23 19:00:13 +02:00
Ilija Lazoroski
071a4eb1a7
Island: Add IEncryptor to __init__
...
Dnt abbrev in PassworBasedEncryptor and KeyBasedEncryptor
Add comment for review and evaluate the padding function
2021-09-23 17:52:15 +02:00
Ilija Lazoroski
1b91616778
Island: Add explanation for KBE and PBE
...
KeyBasedEncryptor and PasswordBasedEncryptor
2021-09-23 12:44:05 +02:00
Ilija Lazoroski
a661dc4fe6
Island: Refactor encryptors
...
All encryptors are moved to server_utils/encryption.
They were renamed according to the class name.
Everywhere that we had use the encryptors I have updated the names.
Unit tests are also moved to UTs server_utils/encryption.
2021-09-22 22:48:13 +02:00
Ilija Lazoroski
803d1c910f
Island: Separate password and key encryption
2021-09-22 18:10:16 +02:00
Mike Salvatore
380d0ee74f
Merge pull request #1479 from guardicore/1476/upgrade-python-deps
...
Update Python dependencies
2021-09-22 08:30:13 -04:00
Mike Salvatore
67b23c42bf
Tests: Simplify test names in test_string_list_encryptor.py
2021-09-22 07:44:54 -04:00
Ilija Lazoroski
71d0cccdba
Island: Update boto3, botocore and awscli
...
botocore is dependency of boto3 which is
then dependency of awscli.
2021-09-22 11:26:47 +02:00
Ilija Lazoroski
57bce38661
Agent: Upgrade urllib3 to 1.26.5
...
It should work because all the deps are
there.
2021-09-22 11:23:07 +02:00
VakarisZ
ba4aabb67f
Merge pull request #1477 from guardicore/report_encryption
...
Report encryption
2021-09-22 11:48:22 +03:00
VakarisZ
88f3a2b9ca
Add unit tests for string list encryptor
2021-09-22 10:23:41 +03:00
VakarisZ
a1c0af4257
Improve readability and test empty list in test_report_model.py
2021-09-22 10:21:48 +03:00
Mike Salvatore
627a31c902
Island: Remove string_encryptor.py
2021-09-21 13:58:16 -04:00
Mike Salvatore
2ddd369afd
Island: Move encode/decode dot mongo functions to Report model
2021-09-21 13:58:14 -04:00
Mike Salvatore
f662369a07
Tests: Decouple test_report_model.py from StringListEncryptor
2021-09-21 12:51:55 -04:00
Mike Salvatore
13ba0b9091
Island: Rename FieldType to FieldEncryptor
...
* Switch FieldTypeABC from abstract class to interface, since there's no
intention of ever implementing FieldTypeABC's methods.
* Rename FieldTypeABC to IFieldEncryptor and rename StringList to
StringListEncryptor.
2021-09-21 12:30:35 -04:00
Mike Salvatore
96ac13c579
Merge pull request #1478 from guardicore/powershell-pth-on-windows
...
Powershell pth on windows
2021-09-21 08:14:45 -04:00
VakarisZ
5077d84269
Change report service to use report model.
...
Because report saving/fetching happens through model, model can encrypt/decrypt sensitive data
2021-09-21 10:45:39 +03:00