cloudpassage/check_for_cve
Search CloudPassage Halo API for specific CVEs
Discovered public repositories for cloudpassage in the GitHub catalog.
Search CloudPassage Halo API for specific CVEs
This program uses the Halo API to check for the presence of CVE-2014-0160
This program enables VMWare users to install/uninstall the CloudPassage Halo daemon across their VMWare infrastructure.
Cloudpassage Halo policy for detecting Bitcoin miners CPUMiner and CUDAMiner
The program makes Halo API calls to retrieve event and scan data from the Halo Grid and coverts it into XML format
Convert between AWS Security Groups and Halo Firewall Policies
This script places a GET call to the Halo API, sending the API response to stdout.
Quarantines potentially compromised cloud servers
Ruby console with a CloudPassage api session going
Directory modification tool for CloudPassage Halo policies
This library contains support routines used by Ruby programs accessing the CloudPassage Halo API.
These scripts regularly update the /etc/hosts file on each Halo-protected server with both the name and IP address of every other server, so that syslog entries will specify server name as well as IP address.
These ruby and Python scripts include examples of calling the CloudPassage API for basic purposes such as authentication, submitting a GET request to retrieve information, and submitting a PUT request to write information back to Halo.
This script downloads (in JSON format) all defined file integrity policies and firewall policies in one or more Halo accounts. Running this script allows you to archive a copy of all of your current policies.
Chef cookbook for installing the CloudPassage Halo agent
Checks AWS regions and Rackspace for servers that do not have CloudPassage Halo installed.
Looks at all Halo-secured systems in a single portal account and reports on all server-local accounts whose passwords have not been changed in over M days (where M is specified on the command line).
Provides an html-formatted page showing the IP addresses from which Halo Portal users have logged in. Reviewing this report allows you to quickly identify logins from suspcious networks unexpected countries, or at unusual times of day.
This tool provides one report per Halo group showing where the machines are the same, and where they differ. One of these things is not like the other...
This Ruby script adds or removes IP addresses from an IP zone that is used in a Halo firewall policy.
A script to easily send the cryptographic checksum of a suspected compromised file to Virus Total for comparison with other reported cases of known malware.
A plugin that lets you import CloudPassage Halo events into Splunk, Sumo Logic, and other SIEM/log processors
A plugin that lets you import CloudPassage Halo events into Splunk (and other SIEM/log processors)
Tools and other useful tidbits!