Public/Get-RiskSenseHost.ps1

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
function Get-RiskSenseHost {
    <#
    .SYNOPSIS
        List hosts.
    .DESCRIPTION
        List hosts in RiskSense client.
        Authority: User, Group Manager, Manager
    .EXAMPLE
        Get-RiskSenseHost -ClientID 1 -Token 'secrettoken'
    #>


    [CmdletBinding()]
    param(
        # ClientID
        [int]$ClientID,
        
        # RiskSense API Key
        [Parameter(Mandatory)]
        $Token
    )

    begin {
        $headers = Get-AuthHeader $Token
        $body = '{
            "filters": [
            ],
            "projection": "basic",
            "sort": [
              {
                "field": "id",
                "direction": "ASC"
              }
            ],
            "page": $page,
            "size": 250
          }'

    }
    
    process {
        $page = 0
        do {
            $irmBody = $body.Replace('$page', $page)
            $result = Invoke-RestMethod -Uri "$uri/client/$ClientID/host/search" -Method Post -Body $irmBody -Headers $headers
            foreach ($rsHost in $result._embedded.hosts) {
                try {
                    $lastFoundOn = (Get-Date $rsHost.lastFoundOn)
                } catch {
                    $lastFoundOn = $rsHost.lastFoundOn
                }

                [PSCustomObject] @{
                    ID = $rsHost.id
                    ClientID = $rsHost.ClientID
                    RS3 = $rsHost.rs3 
                    Criticality = $rsHost.criticality 
                    TagIDs = $rsHost.tagIds 
                    NetworkId = $rsHost.networkIds 
                    FindingsDistribution = $rsHost.findingsDistribution 
                    DiscoveredOn = (Get-Date $rsHost.discoveredOn)
                    LastFoundOn = $lastFoundOn
                    LastScanTime = (Get-Date $rsHost.lastScanTime)
                    HostName = $rsHost.hostname 
                    IPAddress = $rsHost.ipAddress 
                    OperatingSystemScanner = $rsHost.operatingSystemScanner
                    External = [System.Convert]::ToBoolean($rsHost.external) 
                    ConfigurationManagementDB = $rsHost.configurationManagementDB
                }
            }
            $page++
        } while ($result._links.next.href)
    }

    end {}
}