Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGES
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
1.16.1
-----
- Show the server's error reason and missing scan file details when an offline endpoint scan upload fails

1.16.0
-----
- alerts-data-sources deactivate-batch: deactivate multiple alert data sources concurrently, either from a text file of connector IDs (`--config`) or every connector currently in `active`/`offline`/`update_failed` (`--all-active`)
Expand Down
2 changes: 1 addition & 1 deletion intezer_analyze_cli/__init__.py
Original file line number Diff line number Diff line change
@@ -1 +1 @@
__version__ = '1.16.0'
__version__ = '1.16.1'
10 changes: 10 additions & 0 deletions intezer_analyze_cli/commands.py
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
from email.utils import parsedate_to_datetime

import click
import requests
from intezer_sdk import api
from intezer_sdk import consts as sdk_consts
from intezer_sdk import errors as sdk_errors
Expand Down Expand Up @@ -310,6 +311,15 @@ def upload_offline_endpoint_scan(offline_scan_directory: str, force: bool = Fals
click.echo(f'Analyze error: {e}')
logger.exception('Failed to analyze offline scan')
raise
except requests.HTTPError as error:
click.echo(f'Upload failed: {error}')
logger.exception('Failed to upload offline scan')
raise
except FileNotFoundError as error:
click.echo(f'Missing scan file: {error.filename}. Make sure the path is the scan output directory '
'created by the scanner (scan_<computername>_<date>_<time>)')
logger.exception('Failed to upload offline scan, scan file is missing')
raise
return endpoint_analysis.analysis_id


Expand Down
36 changes: 36 additions & 0 deletions tests/unit/commands_test.py
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@
from unittest.mock import patch

import click.exceptions
import requests
import intezer_sdk.endpoint_analysis
import intezer_sdk.base_analysis
from intezer_sdk import errors as sdk_errors
Expand Down Expand Up @@ -128,6 +129,41 @@ def test_offline_scan_upload(self):
self.send_analyze_mock.assert_called_once()
self.assertTrue(os.path.isfile(analysis_id_file_path))

def test_offline_scan_upload_echoes_server_error_when_http_error_is_raised(self):
# Arrange
create_global_api()
self.send_analyze_mock.side_effect = requests.HTTPError(
'409 Client Error: CONFLICT for url: https://analyze.intezer.com/scans, '
'server returns Windows scanner version 1.0.1.20 is not supported'
)
with tempfile.TemporaryDirectory() as root:
offline_scan_directory = self._create_temporary_directory_hierarchy(root)

# Act
with patch('intezer_analyze_cli.commands.click.echo') as echo_mock:
with self.assertRaises(requests.HTTPError):
commands.upload_offline_endpoint_scan(offline_scan_directory)

# Assert
echoed_messages = ' '.join(str(echo_call.args[0]) for echo_call in echo_mock.call_args_list)
self.assertIn('Windows scanner version 1.0.1.20 is not supported', echoed_messages)

def test_offline_scan_upload_echoes_missing_file_when_scan_file_is_missing(self):
# Arrange
create_global_api()
self.send_analyze_mock.side_effect = FileNotFoundError(2, 'No such file or directory', 'scanner_info.json')
with tempfile.TemporaryDirectory() as root:
offline_scan_directory = self._create_temporary_directory_hierarchy(root)

# Act
with patch('intezer_analyze_cli.commands.click.echo') as echo_mock:
with self.assertRaises(FileNotFoundError):
commands.upload_offline_endpoint_scan(offline_scan_directory)

# Assert
echoed_messages = ' '.join(str(echo_call.args[0]) for echo_call in echo_mock.call_args_list)
self.assertIn('scanner_info.json', echoed_messages)

def test_offline_scan_do_not_upload_if_already_uploaded(self):
# Arrange
create_global_api()
Expand Down
Loading