|
| 1 | +// Copyright 2018 Saferwall. All rights reserved. |
| 2 | +// Use of this source code is governed by Apache v2 license |
| 3 | +// license that can be found in the LICENSE file. |
| 4 | + |
| 5 | +package cmd |
| 6 | + |
| 7 | +import ( |
| 8 | + "fmt" |
| 9 | + "log" |
| 10 | + "strings" |
| 11 | + "time" |
| 12 | + |
| 13 | + "github.com/charmbracelet/lipgloss" |
| 14 | + "github.com/saferwall/cli/internal/webapi" |
| 15 | + "github.com/spf13/cobra" |
| 16 | +) |
| 17 | + |
| 18 | +var ( |
| 19 | + searchPage int |
| 20 | + searchPerPage int |
| 21 | +) |
| 22 | + |
| 23 | +var searchCmd = &cobra.Command{ |
| 24 | + Use: "search <query>", |
| 25 | + Short: "Search for files on the Saferwall platform", |
| 26 | + Long: `Search files using a query expression. |
| 27 | +
|
| 28 | +Examples: |
| 29 | + saferwall-cli search 'type=pe and positives>=10' |
| 30 | + saferwall-cli search 'fs>2026 and tag=upx' --per-page 50 |
| 31 | + saferwall-cli search 'extension=sys and positives>=10' --page 2`, |
| 32 | + Args: cobra.ExactArgs(1), |
| 33 | + Run: func(cmd *cobra.Command, args []string) { |
| 34 | + webSvc := webapi.New(cfg.Credentials.URL) |
| 35 | + result, err := webSvc.SearchFiles(args[0], cfg.Credentials.APIKey, searchPage, searchPerPage) |
| 36 | + if err != nil { |
| 37 | + log.Fatalf("search failed: %v", err) |
| 38 | + } |
| 39 | + printSearchResults(result, searchPage, searchPerPage) |
| 40 | + }, |
| 41 | +} |
| 42 | + |
| 43 | +func init() { |
| 44 | + searchCmd.Flags().IntVarP(&searchPage, "page", "p", 1, "Page number") |
| 45 | + searchCmd.Flags().IntVarP(&searchPerPage, "per-page", "n", 20, "Results per page") |
| 46 | +} |
| 47 | + |
| 48 | +func printSearchResults(result *webapi.SearchResult, page, perPage int) { |
| 49 | + fmt.Println() |
| 50 | + |
| 51 | + if result.TotalCount == 0 { |
| 52 | + fmt.Println(" No results found.") |
| 53 | + fmt.Println() |
| 54 | + return |
| 55 | + } |
| 56 | + |
| 57 | + // Summary line. |
| 58 | + start := (page-1)*perPage + 1 |
| 59 | + end := start + len(result.Items) - 1 |
| 60 | + fmt.Printf(" %s\n\n", |
| 61 | + headerStyle.Render(fmt.Sprintf("Showing %d-%d of %d results", start, end, result.TotalCount)), |
| 62 | + ) |
| 63 | + |
| 64 | + // Column styles. |
| 65 | + nameCol := lipgloss.NewStyle().Width(24) |
| 66 | + typeCol := lipgloss.NewStyle().Width(16) |
| 67 | + sizeCol := lipgloss.NewStyle().Width(10) |
| 68 | + detCol := lipgloss.NewStyle().Width(12) |
| 69 | + dateCol := lipgloss.NewStyle().Width(12) |
| 70 | + clsCol := lipgloss.NewStyle().Width(12) |
| 71 | + |
| 72 | + // Header row. |
| 73 | + fmt.Printf(" %s %s %s %s %s %s %s %s\n", |
| 74 | + styleDim.Render(fmt.Sprintf("%-64s", "SHA256")), |
| 75 | + styleDim.Render(nameCol.Render("NAME")), |
| 76 | + styleDim.Render(typeCol.Render("TYPE/EXT")), |
| 77 | + styleDim.Render(sizeCol.Render("SIZE")), |
| 78 | + styleDim.Render(detCol.Render("DETECTIONS")), |
| 79 | + styleDim.Render(dateCol.Render("FIRST SEEN")), |
| 80 | + styleDim.Render(dateCol.Render("LAST SCANNED")), |
| 81 | + styleDim.Render(clsCol.Render("VERDICT")), |
| 82 | + ) |
| 83 | + fmt.Printf(" %s\n", styleDim.Render(strings.Repeat("─", 172))) |
| 84 | + |
| 85 | + for _, item := range result.Items { |
| 86 | + // Name: hide if it looks like a bare hash (the API echoes the ID as name). |
| 87 | + name := item.Name |
| 88 | + if name == "" || looksLikeHash(name) { |
| 89 | + name = "-" |
| 90 | + } |
| 91 | + if len(name) > 24 { |
| 92 | + name = name[:21] + "..." |
| 93 | + } |
| 94 | + |
| 95 | + // Type/extension column. |
| 96 | + typeStr := item.Format |
| 97 | + if item.Extension != "" { |
| 98 | + typeStr += "/" + item.Extension |
| 99 | + } |
| 100 | + if typeStr == "" { |
| 101 | + typeStr = "-" |
| 102 | + } |
| 103 | + if len(typeStr) > 16 { |
| 104 | + typeStr = typeStr[:13] + "..." |
| 105 | + } |
| 106 | + |
| 107 | + // AV detections from condensed multiav.hits/total. |
| 108 | + detStr := "-" |
| 109 | + if item.MultiAV.Total > 0 { |
| 110 | + raw := fmt.Sprintf("%d/%d", item.MultiAV.Hits, item.MultiAV.Total) |
| 111 | + if item.MultiAV.Hits > 0 { |
| 112 | + detStr = detectStyle.Render(raw) |
| 113 | + } else { |
| 114 | + detStr = cleanStyle.Render(raw) |
| 115 | + } |
| 116 | + } |
| 117 | + |
| 118 | + // Timestamps: date only. |
| 119 | + firstSeen := "-" |
| 120 | + if item.FirstSeen != 0 { |
| 121 | + firstSeen = time.Unix(item.FirstSeen, 0).UTC().Format("2006-01-02") |
| 122 | + } |
| 123 | + lastScanned := "-" |
| 124 | + if item.LastScanned != 0 { |
| 125 | + lastScanned = time.Unix(item.LastScanned, 0).UTC().Format("2006-01-02") |
| 126 | + } |
| 127 | + |
| 128 | + fmt.Printf(" %s %s %s %s %s %s %s %s\n", |
| 129 | + item.ID, |
| 130 | + nameCol.Render(name), |
| 131 | + typeCol.Render(typeStr), |
| 132 | + sizeCol.Render(formatSize(item.Size)), |
| 133 | + detCol.Render(detStr), |
| 134 | + dateCol.Render(firstSeen), |
| 135 | + dateCol.Render(lastScanned), |
| 136 | + clsCol.Render(renderClassification(item.Classification)), |
| 137 | + ) |
| 138 | + } |
| 139 | + |
| 140 | + fmt.Println() |
| 141 | + |
| 142 | + // Pagination hint. |
| 143 | + if result.PageCount > 1 { |
| 144 | + fmt.Printf(" %s\n\n", |
| 145 | + styleDim.Render(fmt.Sprintf("Page %d of %d — use --page to navigate", page, result.PageCount)), |
| 146 | + ) |
| 147 | + } |
| 148 | +} |
| 149 | + |
0 commit comments