9.5.3. plugins/plugin_mcafee.pyΒΆ

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
from collections import OrderedDict

VERSION = "1.1.0"
"""Version of this set of plugin definitions."""

MINIMUM_THAT_VERSION = "1.1.0"
"""Minimum THAT version required to run these plugin definitions."""

NAME = "mcafee"
PRIORITY = 6
ANALYZE_DATA = OrderedDict()
GET_TANIUM_DATA = OrderedDict()

GET_INTERNET_DATA = [
]

# ask the question 'Get VirusScan Enterprise Version < 8.7 from all machines with Is Windows contains True'
# and store results in "mcafeeunsupported.csv"
GET_TANIUM_DATA["mcafeeunsupported.csv"] = {
    "filters": ["Is Windows, that contains:True"],
    "sensors": ["VirusScan Enterprise Version, that lt:8.7"],
}

# ask the question 'Get VirusScan Enterprise Version from all machines with Is Windows contains True'
# and store results in "mcafeeunsupported.csv"
GET_TANIUM_DATA["mcafeeversion.csv"] = {
    "filters": ["Is Windows, that contains:True"],
    "sensors": ["VirusScan Enterprise Version"],
}

# ask the question 'Get VirusScan Enterprise DAT Version from all machines where VirusScan Enterprise DAT Days Old > 2'
# and store results in "mcafeedat.csv"
GET_TANIUM_DATA["mcafeedat.csv"] = {
    "filters": ["VirusScan Enterprise DAT Days Old, that gt:2"],
    "sensors": ["VirusScan Enterprise DAT Version"],
}

# ask the question 'Get VirusScan Enterprise On-Access Scan State contains "Disabled" from all machines'
# and store results in "mcafeeonaccess.csv"
GET_TANIUM_DATA["mcafeeonaccess.csv"] = {
    "filters": [],
    "sensors": ["VirusScan Enterprise On-Access Scan State, that contains:Disabled"],
}

# ask the question 'Get Installed Applications contains "mcafee" from all machines'
# and store results in "mcafee.csv"
GET_TANIUM_DATA["mcafee.csv"] = {
    "filters": [],
    "sensors": ["Installed Applications, that contains:mcafee"],
}

# ask the question 'Get Online from all machines with Is Windows contains True'
# and store results in "mcafeetargets.csv"
GET_TANIUM_DATA["mcafeetargets.csv"] = {
    "filters": ["Is Windows, that contains:True"],
    "sensors": ["Online"],
}

ANALYZE_DATA["extra_clean_values"] = """
# set extra clean values to be used for df cleaning

result = ["N/A on Linux", "N/A on AIX", "N/A on Solaris"]
"""

ANALYZE_DATA["cleaned_mcafeeunsupported_df"] = """
# clean out noise from mcafeeunsupported.csv

csv = "mcafeeunsupported.csv"
df = self.load_csv_as_df(csv)
extra_clean_values = self.get_result("extra_clean_values")

result = self.clean_df(df, columns=["VirusScan Enterprise Version"], add_values=extra_clean_values)
"""

ANALYZE_DATA["cleaned_mcafeedat_df"] = """
# clean out noise from mcafeedat.csv

csv = "mcafeedat.csv"
df = self.load_csv_as_df(csv)

result = self.clean_df(df, columns=["VirusScan Enterprise DAT Version"])
"""

ANALYZE_DATA["cleaned_mcafeeversion_df"] = """
# clean out noise from mcafeeversion.csv

csv = "mcafeeversion.csv"
df = self.load_csv_as_df(csv)

result = self.clean_df(df, columns=["VirusScan Enterprise Version"])
"""

ANALYZE_DATA["cleaned_mcafee_df"] = """
# clean out noise from mcafee.csv

csv = "mcafee.csv"
df = self.load_csv_as_df(csv)

result = self.clean_df(df, columns=["Name"])
"""

ANALYZE_DATA["mcafee_scanned_total"] = """
# Total Number of Scanned Endpoints for McAfee Products

csv = "mcafeetargets.csv"
df = self.load_csv_as_df(csv)

result = df['Count'].sum()
"""

ANALYZE_DATA["mcafee_notinstalled_perc_total"] = """
# get total count of endpoints where McAfee is NOT Installed

df = self.get_result("cleaned_mcafeeversion_df")
df2 = self.get_result("mcafee_scanned_total")
col1 = 'VirusScan Enterprise Version'
col2 = 'Not Installed'
col3 = 'Count'

res1 = self.force_int(df.loc[df[col1] == col2, col3].sum(),0)
res2 = df2

result = self.force_int((res1 * 100)/res2,0)
"""

ANALYZE_DATA["unsupported_version_count"] = """
# Number of Unsupported McAfee Versions

df = self.get_result("cleaned_mcafeeunsupported_df")
col1 = 'VirusScan Enterprise Version'
col2 = 'Not Installed'

result = self.force_int(len(df.loc[df[col1] != col2]),0)
"""

ANALYZE_DATA["unsupported_total_installs_count"] = """
#number of installs across endpoints with unsupported versions

df = self.get_result("cleaned_mcafeeunsupported_df")
col1 = 'VirusScan Enterprise Version'
col2 = 'Not Installed'
col3 = 'Count'

result = self.force_int(df.loc[df[col1] != col2, col3].sum(),0)
"""

ANALYZE_DATA["outdated_mcafee_dat"] = """
# Outdated mcAfee Dat Versions

df = self.get_result("cleaned_mcafeedat_df")
col = 'VirusScan Enterprise DAT Version'

result = len(df[col])
"""

ANALYZE_DATA["outdated_mcafee_dat_total_installs"] = """
# Outdated mcAfee Dat Versions installs on endpoints

df = self.get_result("cleaned_mcafeedat_df")
col = 'Count'

result = df[col].sum()
"""

ANALYZE_DATA["mcafee_onaccess_disabled"] = """
#Total Number of Endpoints with OnAccess Disabled State

csv = "mcafeeonaccess.csv"
df = self.load_csv_as_df(csv)
col1 = 'VirusScan Enterprise On-Access Scan State'
col2 = 'Disabled'
col3 = 'Count'

result = self.force_int(df.loc[df[col1] == col2, col3].sum(),0)
"""

ANALYZE_DATA["mcafee_total_products"] = """
#Total Number McAfee Products detected

df = self.get_result("cleaned_mcafee_df")
col = 'Name'

result = len(df[col])
"""

ANALYZE_DATA["mcafee_total_install_count"] = """
#Total Number McAfee Products detected

df = self.get_result("cleaned_mcafee_df")
col = 'Count'

result = df[col].sum()
"""