feat: Tenable-style patch_status - pending_updates, last_patch, reboot_pending across full stack
This commit is contained in:
202
agent/client/posture_unix.go
Normal file
202
agent/client/posture_unix.go
Normal file
@@ -0,0 +1,202 @@
|
||||
//go:build !windows
|
||||
|
||||
package client
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"os/exec"
|
||||
"os/user"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
)
|
||||
|
||||
func collectPosture() *PostureReport {
|
||||
r := &PostureReport{AgentServiceOK: boolPtr(true)}
|
||||
|
||||
// ── Firewall ───────────────────────────────────────────────────────────────
|
||||
fwActive := probeUnixFirewall()
|
||||
r.FirewallDomain = &fwActive
|
||||
r.FirewallPrivate = &fwActive
|
||||
// Public profile has no direct Linux equivalent; leave nil.
|
||||
|
||||
// ── AV / security daemons ─────────────────────────────────────────────────
|
||||
avProducts := probeUnixAV()
|
||||
r.AVProducts = avProducts
|
||||
avOK := fwActive || len(avProducts) > 0
|
||||
r.DefenderEnabled = &avOK
|
||||
|
||||
// ── SSH ───────────────────────────────────────────────────────────────────
|
||||
ssh := probeSSH()
|
||||
r.SSHListening = &ssh
|
||||
|
||||
// ── Patch age ─────────────────────────────────────────────────────────────
|
||||
days, dateStr := probeUnixPatchAge()
|
||||
if days >= 0 {
|
||||
r.LastPatchDays = &days
|
||||
recent := days <= 30
|
||||
r.PatchRecent = &recent
|
||||
if dateStr != "" {
|
||||
r.LastPatch = &dateStr
|
||||
}
|
||||
}
|
||||
|
||||
// ── Pending updates ───────────────────────────────────────────────────────
|
||||
pending := probeUnixPendingUpdates()
|
||||
r.PendingUpdates = &pending
|
||||
|
||||
// ── Reboot pending ────────────────────────────────────────────────────────
|
||||
rp := probeUnixRebootPending()
|
||||
r.RebootPending = &rp
|
||||
|
||||
// ── Elevation ─────────────────────────────────────────────────────────────
|
||||
elevated := probeUnixElevated()
|
||||
r.AgentElevated = &elevated
|
||||
|
||||
r.PostureScore = computePostureScore(r)
|
||||
return r
|
||||
}
|
||||
|
||||
// probeUnixFirewall returns true if any host firewall appears active.
|
||||
func probeUnixFirewall() bool {
|
||||
if out, _ := exec.Command("ufw", "status").CombinedOutput(); strings.Contains(strings.ToLower(string(out)), "status: active") {
|
||||
return true
|
||||
}
|
||||
if out, _ := exec.Command("systemctl", "is-active", "firewalld").CombinedOutput(); strings.TrimSpace(string(out)) == "active" {
|
||||
return true
|
||||
}
|
||||
if out, err := exec.Command("/bin/sh", "-c", "iptables -L -n 2>/dev/null | wc -l").CombinedOutput(); err == nil {
|
||||
if n, err := strconv.Atoi(strings.TrimSpace(string(out))); err == nil && n > 8 {
|
||||
return true
|
||||
}
|
||||
}
|
||||
if out, _ := exec.Command("/bin/sh", "-c", "nft list ruleset 2>/dev/null | wc -l").CombinedOutput(); true {
|
||||
if n, err := strconv.Atoi(strings.TrimSpace(string(out))); err == nil && n > 3 {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// probeUnixAV returns names of active security daemons.
|
||||
func probeUnixAV() []string {
|
||||
type entry struct{ svc, label string }
|
||||
candidates := []entry{
|
||||
{"clamav-daemon", "ClamAV"}, {"clamd", "ClamAV"},
|
||||
{"fail2ban", "Fail2Ban"}, {"rkhunter", "RKHunter"},
|
||||
{"chkrootkit", "Chkrootkit"}, {"auditd", "auditd"},
|
||||
}
|
||||
seen := map[string]bool{}
|
||||
var found []string
|
||||
for _, c := range candidates {
|
||||
out, _ := exec.Command("systemctl", "is-active", c.svc).CombinedOutput()
|
||||
if strings.TrimSpace(string(out)) == "active" && !seen[c.label] {
|
||||
seen[c.label] = true
|
||||
found = append(found, c.label)
|
||||
}
|
||||
}
|
||||
return found
|
||||
}
|
||||
|
||||
// probeUnixPatchAge returns (days since last update, ISO date string).
|
||||
// Returns (-1, "") when unknown.
|
||||
func probeUnixPatchAge() (int, string) {
|
||||
stamps := []string{
|
||||
"/var/lib/apt/periodic/update-success-stamp",
|
||||
"/var/cache/apk/lastupdate",
|
||||
}
|
||||
for _, path := range stamps {
|
||||
if info, err := os.Stat(path); err == nil {
|
||||
d := int(time.Since(info.ModTime()).Hours() / 24)
|
||||
if d < 0 {
|
||||
d = 0
|
||||
}
|
||||
return d, info.ModTime().Format("2006-01-02")
|
||||
}
|
||||
}
|
||||
// YUM/DNF history
|
||||
if out, err := exec.Command("/bin/sh", "-c",
|
||||
`yum history info 2>/dev/null | grep "Begin time" | head -1 | awk '{print $3, $4}'`).CombinedOutput(); err == nil {
|
||||
line := strings.TrimSpace(string(out))
|
||||
if line != "" {
|
||||
if t, err := time.Parse("2006-01-02 15:04", line); err == nil {
|
||||
return int(time.Since(t).Hours() / 24), t.Format("2006-01-02")
|
||||
}
|
||||
}
|
||||
}
|
||||
// rpm last installed
|
||||
if out, err := exec.Command("/bin/sh", "-c", "rpm -qa --last 2>/dev/null | head -1").CombinedOutput(); err == nil {
|
||||
parts := strings.Fields(string(out))
|
||||
if len(parts) >= 5 {
|
||||
dateStr := strings.Join(parts[len(parts)-5:], " ")
|
||||
if t, err := time.Parse("Mon Jan 2 15:04:05 2006", dateStr); err == nil {
|
||||
return int(time.Since(t).Hours() / 24), t.Format("2006-01-02")
|
||||
}
|
||||
}
|
||||
}
|
||||
return -1, ""
|
||||
}
|
||||
|
||||
// probeUnixPendingUpdates returns the count of available package updates.
|
||||
// Returns -1 if the count cannot be determined.
|
||||
func probeUnixPendingUpdates() int {
|
||||
// APT
|
||||
if out, err := exec.Command("/bin/sh", "-c",
|
||||
"apt list --upgradable 2>/dev/null | grep -c upgradable").CombinedOutput(); err == nil {
|
||||
if n, err := strconv.Atoi(strings.TrimSpace(string(out))); err == nil {
|
||||
return n
|
||||
}
|
||||
}
|
||||
// APT check (outputs "pkg;security" lines)
|
||||
if out, err := exec.Command("/bin/sh", "-c",
|
||||
"/usr/lib/update-notifier/apt-check 2>&1 | cut -d';' -f1").CombinedOutput(); err == nil {
|
||||
if n, err := strconv.Atoi(strings.TrimSpace(string(out))); err == nil && n >= 0 {
|
||||
return n
|
||||
}
|
||||
}
|
||||
// YUM/DNF
|
||||
if out, err := exec.Command("/bin/sh", "-c",
|
||||
"yum check-update --quiet 2>/dev/null | grep -c '^[a-zA-Z]'").CombinedOutput(); err == nil {
|
||||
if n, err := strconv.Atoi(strings.TrimSpace(string(out))); err == nil {
|
||||
return n
|
||||
}
|
||||
}
|
||||
// apk (Alpine)
|
||||
if out, err := exec.Command("/bin/sh", "-c",
|
||||
"apk version -l '<' 2>/dev/null | wc -l").CombinedOutput(); err == nil {
|
||||
if n, err := strconv.Atoi(strings.TrimSpace(string(out))); err == nil {
|
||||
return n
|
||||
}
|
||||
}
|
||||
return -1
|
||||
}
|
||||
|
||||
// probeUnixRebootPending checks kernel and package signals for a required reboot.
|
||||
func probeUnixRebootPending() bool {
|
||||
// Debian/Ubuntu explicit flag
|
||||
if _, err := os.Stat("/var/run/reboot-required"); err == nil {
|
||||
return true
|
||||
}
|
||||
// Kernel update check: compare running vs installed
|
||||
if out, err := exec.Command("uname", "-r").CombinedOutput(); err == nil {
|
||||
running := strings.TrimSpace(string(out))
|
||||
// Check if a newer kernel package exists
|
||||
if out2, err := exec.Command("/bin/sh", "-c",
|
||||
fmt.Sprintf("ls /boot/vmlinuz-* 2>/dev/null | grep -v '%s' | wc -l", running)).CombinedOutput(); err == nil {
|
||||
if n, err := strconv.Atoi(strings.TrimSpace(string(out2))); err == nil && n > 0 {
|
||||
return true
|
||||
}
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// probeUnixElevated returns true when running as root (uid 0).
|
||||
func probeUnixElevated() bool {
|
||||
u, err := user.Current()
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
return u.Uid == "0"
|
||||
}
|
||||
Reference in New Issue
Block a user