CrowdStrike / psfalcon

PowerShell for CrowdStrike's OAuth2 APIs
The Unlicense
369 stars 70 forks source link

Create Correção Falcon #415

Closed tgyuy closed 2 months ago

tgyuy commented 4 months ago

1 - Baixa o PSFalcon no Github: https://github.com/CrowdStrike/psfalcon

Usa meu script aqui para distribuir (executa.ps1)

Import-Module -Name ./PSFalcon.psd1 -Force

Request-FalconToken -ClientId SUAAPI -ClientSecret SUASCRET -Cloud us-1

# Vai no grupo que vc quer acertar e altere pelo ID que tem na URL
$GroupId = "cf5b2566f5f0456097ef65f6c07db494"
$HostIds = Get-FalconHost -All -Filter "groups:'$GroupId'"

Invoke-FalconRTR -Command runscript -Arguments "-CloudFile='SCRIPT-NO-RESPONSE-SCRIPTS'" -Verbose -HostIds $HostIds -Timeout 90 | Export-Csv 'export-result.csv'

2 - Script para colocar no response scripts files na console do CrowdStrike

$ProgressPreference = 'SilentlyContinue'

# Caminho de rede para a pasta já descompactada
$networkPath = "\\fileserver\pasta"

# Caminho local para onde a pasta será copiada
$localPath = "pasta"

# Copiar a pasta do caminho de rede para a máquina local
Copy-Item -Path $networkPath -Destination $localPath -Recurse

# Navegar para o diretório copiado
cd $localPath

# Instalar o Elastic Agent
.\software-pra-instalar.exe install

Please review our Code of Conduct and our Contribution Guidelines before submitting a Pull Request.

REMOVE ALL PULL REQUEST HINTS BEFORE SUBMITTING

PULL REQUEST TITLE

Pull Request general description should go here.

Please fill out all values and then remove any help text before submitting your PR.

Check the values above that match your PR and remove the remaining.

Added features and functionality

Issues resolved

Other

bk-cs commented 2 months ago

Thank you for your contribution!

I'm not sure of your goal with this. As I only speak English, could you re-submit in English and provide a description of your suggestion and final outcome of the additional code?

tgyuy commented 2 months ago

Sorry for only replying now 5511971331516 this my whatsapp Em 3 de set. de 2024 19:11, bk-cs @.***> escreveu: Thank you for your contribution! I'm not sure of your goal with this. As I only speak English, could you re-submit in English and provide a description of your suggestion and final outcome of the additional code?

—Reply to this email directly, view it on GitHub, or unsubscribe.You are receiving this because you authored the thread.Message ID: @.***>