Add to ClamAV integration to the File Event Monitor
Some checks are pending
CodeQL / Analyze (csharp) (push) Waiting to run
CodeQL / Analyze (javascript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run

This commit is contained in:
Namhyeon Go 2024-09-14 22:33:58 +09:00
parent 93ea20cf25
commit f7b1461cc5
3 changed files with 62 additions and 1 deletions

View File

@ -1,9 +1,13 @@
// FileEventMonitor.cs
// Namhyeon Go <abuse@catswords.net>
// https://github.com/gnh1201/welsonjs
using ClamAV.Net.Client;
using ClamAV.Net.Client.Results;
using System;
using System.Diagnostics.Eventing.Reader;
using System.Runtime.CompilerServices;
using System.ServiceProcess;
using System.Threading.Tasks;
namespace WelsonJS.Service
{
@ -62,10 +66,22 @@ namespace WelsonJS.Service
Details,
User
}
private string clamAvConenctionString;
private IClamAvClient clamAvClient;
public FileEventMonitor(ServiceBase parent, string workingDirectory)
{
this.parent = (ServiceMain)parent;
try
{
clamAvConenctionString = this.parent.GetSettingsFileHandler().Read("CLAMAV_HOST", "Service");
}
catch (Exception)
{
clamAvConenctionString = "tcp://127.0.0.1:3310";
}
Task.Run(ConnectToClamAv);
}
public void Start()
@ -86,7 +102,7 @@ namespace WelsonJS.Service
}
catch (Exception ex)
{
parent.Log($"Failed to connect the Windows EventLog Service: {ex.Message}");
parent.Log($"Could not reach to the Sysmon service: {ex.Message}");
}
}
@ -131,6 +147,15 @@ namespace WelsonJS.Service
fileName
}));
if (clamAvClient != null)
{
parent.Log($"> Starting the ClamAV scan: {fileName}");
Task.Run(async () =>
{
await ScanWithClamAv(fileName);
});
}
break;
}
@ -191,5 +216,37 @@ namespace WelsonJS.Service
parent.Log("The event instance was null.");
}
}
private async Task ConnectToClamAv()
{
try {
// Create a client
clamAvClient = ClamAvClient.Create(new Uri(clamAvConenctionString));
// Send PING command to ClamAV
await clamAvClient.PingAsync().ConfigureAwait(false);
// Get ClamAV engine and virus database version
VersionResult result = await clamAvClient.GetVersionAsync().ConfigureAwait(false);
parent.Log($"ClamAV version - {result.ProgramVersion} , virus database version {result.VirusDbVersion}");
}
catch (Exception ex)
{
parent.Log($"Could not reach to ClamAV service: {clamAvConenctionString}, {ex.Message}");
clamAvClient = null;
}
}
private async Task ScanWithClamAv(string remotePath)
{
ScanResult res = await clamAvClient.ScanRemotePathAsync(remotePath).ConfigureAwait(false);
parent.Log($"> Scan result: Infected={res.Infected}, VirusName={res.VirusName}");
parent.Log(parent.DispatchServiceEvent("avScanResult", new string[] {
res.Infected.ToString(),
res.VirusName
}));
}
}
}

View File

@ -97,6 +97,9 @@
<StartupObject />
</PropertyGroup>
<ItemGroup>
<Reference Include="ClamAV.Net, Version=0.1.166.0, Culture=neutral, processorArchitecture=MSIL">
<HintPath>..\packages\ClamAV.Net.0.1.166\lib\netstandard2.0\ClamAV.Net.dll</HintPath>
</Reference>
<Reference Include="Google.Protobuf, Version=3.28.0.0, Culture=neutral, PublicKeyToken=a7d26565bac4d604, processorArchitecture=MSIL">
<HintPath>..\packages\Google.Protobuf.3.28.0\lib\net45\Google.Protobuf.dll</HintPath>
</Reference>

View File

@ -1,5 +1,6 @@
<?xml version="1.0" encoding="utf-8"?>
<packages>
<package id="ClamAV.Net" version="0.1.166" targetFramework="net48" />
<package id="Google.Protobuf" version="3.28.0" targetFramework="net48" />
<package id="Grpc" version="2.46.6" targetFramework="net48" />
<package id="Grpc.Core" version="2.46.6" targetFramework="net48" />