Talks PSRP over WinRM via pypsrp, one runspace pool per connection. Each getter sends one PowerShell script that projects cmdlet results onto flat fields and ends in ConvertTo-Json, so the Python side parses JSON, not text. Covers facts, interfaces, IP addresses, ARP, routes and services, plus service start/stop/restart/enable/disable. Service names are validated and quoted as PowerShell verbatim strings, typographic quotes included. Fixtures are synthetic: they pin down the JSON the scripts are designed to emit. tools/harvest.py records the real output from a host. Refs christianmanivong/netork#300
76 lines
2.8 KiB
Markdown
76 lines
2.8 KiB
Markdown
# napalm-windows
|
|
|
|
NAPALM driver for Windows Server 2016+ and Windows 10/11, part of the netOrk
|
|
driver family built on [`napalm-device-types`](https://git.netork.io/christianmanivong/napalm-device-types).
|
|
|
|
Driver name: `windows` · Role: `OSDriver` · Transport: PowerShell Remoting
|
|
(PSRP) over WinRM via [`pypsrp`](https://github.com/jborean93/pypsrp).
|
|
|
|
## How it works
|
|
|
|
Every getter sends one PowerShell script. The script projects the cmdlet
|
|
results onto flat, primitive fields and ends in `ConvertTo-Json`, so the
|
|
Python side parses JSON, never text. All device I/O goes through a single
|
|
seam (`PsrpTransport.run(script) -> str`), which is what the tests replace.
|
|
|
|
One runspace pool stays open per connection, so a poll pays the WinRM
|
|
handshake once.
|
|
|
|
## Supported
|
|
|
|
| Method | Source |
|
|
|---|---|
|
|
| `get_facts` | `Win32_ComputerSystem`, `Win32_OperatingSystem`, `Win32_BIOS`, registry (`DisplayVersion`, `UBR`) |
|
|
| `get_interfaces` | `Get-NetAdapter` |
|
|
| `get_interfaces_ip` | `Get-NetIPAddress` (loopback dropped, IPv6 zone index stripped) |
|
|
| `get_arp_table` | `Get-NetNeighbor -AddressFamily IPv4` (broadcast, multicast, unreachable dropped) |
|
|
| `get_route_to` | `Get-NetRoute` (multicast, broadcast, loopback dropped) |
|
|
| `get_services` / `manage_service` | `Win32_Service`, `Start-/Stop-/Restart-Service`, `Set-Service -StartupType` |
|
|
|
|
`running_kernel` carries the full build including the update revision
|
|
(`10.0.20348.2340`): Windows ships fixes as UBR bumps, which is what CVE
|
|
matching has to compare against.
|
|
|
|
Not yet: packages, Windows Update, scheduled tasks, health metrics, Hyper-V.
|
|
See netork#300 for the plan.
|
|
|
|
## Preparing a host
|
|
|
|
WinRM is on by default on Windows Server; on Windows 10/11 run
|
|
`Enable-PSRemoting` once. Then either
|
|
|
|
* **HTTPS (5986, default)** — needs a certificate-backed HTTPS listener, or
|
|
* **HTTP (5985)** — set the device port to 5985. Traffic is still encrypted at
|
|
message level (NTLM/Kerberos), credentials never travel in the clear.
|
|
|
|
A **local** administrator account additionally needs
|
|
`LocalAccountTokenFilterPolicy = 1` under
|
|
`HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System`; without it
|
|
remote UAC strips the admin token. Domain accounts are not affected.
|
|
|
|
## optional_args
|
|
|
|
| Key | Default | Meaning |
|
|
|---|---|---|
|
|
| `port` | `5986` | WinRM port |
|
|
| `winrm_ssl` | `port != 5985` | force HTTPS on or off |
|
|
| `winrm_auth` | `negotiate` | pypsrp auth protocol (`negotiate`, `ntlm`, `kerberos`, `credssp`, `basic`) |
|
|
| `ssl_verify` | `True` | validate the WinRM certificate |
|
|
|
|
## Tests and fixtures
|
|
|
|
```bash
|
|
pip install -e ".[dev]"
|
|
pytest
|
|
```
|
|
|
|
`tests/fixtures/synthetic/` holds the JSON the scripts are *designed* to emit.
|
|
To record the real thing from a host:
|
|
|
|
```bash
|
|
python tools/harvest.py <host> <user> <label> [--port 5985] [--insecure]
|
|
```
|
|
|
|
Output lands in `tools/harvest-out/` (gitignored); scrub it before copying
|
|
anything into `tests/`.
|