posture
Runtime-agnostic Python library for CCM (Continuous Control Monitoring) data collection. The entire contract: credentials in, DataFrame out. Runs unchanged in Docker, Airflow, Databricks — the library never knows or cares where it executes.
Installation
pip install posture
posture loads a .env file from the current directory (or a parent) automatically
on import — no code changes needed. Variables already set in the environment always
take precedence over .env values.
# .env
CROWDSTRIKE_CLIENT_ID=xxx
CROWDSTRIKE_CLIENT_SECRET=xxx
OKTA_DOMAIN=https://your-org.okta.com
OKTA_TOKEN=xxx
WORKSPACEONE_CLIENT_ID=xxx
WORKSPACEONE_CLIENT_SECRET=xxx
WORKSPACEONE_API_SERVER=asXXX.awmdm.com
WORKSPACEONE_TOKEN_URL=https://na.uemauth.workspaceone.com/connect/token # optional, see below
UPGUARD_API_KEY=xxx
UPGUARD_BASE_URL=https://au.cyber-risk.upguard.com/api/public # optional, see below
JAMF_URL=https://your-org.jamfcloud.com
JAMF_CLIENT_ID=xxx
JAMF_CLIENT_SECRET=xxx
INTUNE_TENANT_ID=xxx
INTUNE_CLIENT_ID=xxx
INTUNE_CLIENT_SECRET=xxx
MDE_TENANT_ID=xxx
MDE_CLIENT_ID=xxx
MDE_CLIENT_SECRET=xxx
Usage
from posture import CCM
ccm = CCM("crowdstrike") # creds from CROWDSTRIKE_* env vars
ccm = CCM("crowdstrike", {"client_id": "xxx"}) # partial override, rest from env
df = ccm.collect("hosts") # always a complete pandas DataFrame
ccm.flush_cache() # the only cache invalidation
collect() always returns a complete pandas.DataFrame for the requested resource, or
raises — there is no such thing as a partial snapshot in this library.
Example: export Crowdstrike hosts to local JSON
import json
from pathlib import Path
from posture import CCM
# CROWDSTRIKE_CLIENT_ID / CROWDSTRIKE_CLIENT_SECRET must be set in the environment
ccm = CCM("crowdstrike")
df = ccm.collect("hosts")
output_dir = Path("output")
output_dir.mkdir(exist_ok=True)
output_path = output_dir / "hosts.json"
output_path.write_text(df.to_json(orient="records", date_format="iso", indent=2))
print(f"Wrote {len(df)} hosts to {output_path}")
Supported sources
| Source | Resources |
|---|---|
crowdstrike |
hosts, vulnerabilities, vulnerability_remediations, zero_trust_assessment, zero_trust_assessment_os_signals, zero_trust_assessment_sensor_signals |
okta |
users, devices, device_users |
workspaceone |
computers |
upguard |
vendors, domains, breached_identities, organisation, vendor_risks |
jamf |
computers_inventory, computers_inventory_detail, mobile_devices, policies, categories, buildings, departments |
intune |
managed_devices, users, device_configurations, managed_device_detail, device_configuration_detail, device_compliance_policies, attack_simulations, attack_simulation_users |
mde |
machines, vulnerabilities, device_av_info, machine_vulnerabilities |
Crowdstrike configuration
| Constructor key | Env var |
|---|---|
client_id |
CROWDSTRIKE_CLIENT_ID |
client_secret |
CROWDSTRIKE_CLIENT_SECRET |
Okta configuration
| Constructor key | Env var |
|---|---|
domain |
OKTA_DOMAIN |
token |
OKTA_TOKEN |
Workspace ONE configuration
| Constructor key | Env var |
|---|---|
client_id |
WORKSPACEONE_CLIENT_ID |
client_secret |
WORKSPACEONE_CLIENT_SECRET |
api_server |
WORKSPACEONE_API_SERVER |
token_url |
WORKSPACEONE_TOKEN_URL (optional — defaults to the APAC realm; set explicitly if your tenant is NA or EMEA, since there's no reliable way to derive the realm from api_server) |
UpGuard configuration
| Constructor key | Env var |
|---|---|
api_key |
UPGUARD_API_KEY |
base_url |
UPGUARD_BASE_URL (optional — defaults to the AU tenant) |
vendor_risks fans a single (unpaginated — UpGuard's /risks/vendors has no
pagination) request out per vendor across a thread pool (1–60s per vendor and
there can be hundreds of vendors) — the only posture resource that does
concurrent per-parent network calls rather than sequential pagination. Tune
with collect("vendor_risks", max_workers=8), or pass min_severity to filter
server-side.
Jamf configuration
| Constructor key | Env var |
|---|---|
url |
JAMF_URL |
client_id |
JAMF_CLIENT_ID |
client_secret |
JAMF_CLIENT_SECRET |
Only the fields the accelerator explicitly renamed are ported for computers_inventory,
computers_inventory_detail, and mobile_devices — the reference implementation
passes the rest of each response through via generic flattening, which posture's
allowlist-only manifest doesn't support. computers_inventory_detail fetches one
computer at a time by id (from computers_inventory), same pattern as Okta's
device_users.
Intune and MDE configuration
Both authenticate via Azure AD client-credentials against the tenant's OAuth2 endpoint (shared internal helper, not vendor SDKs).
| Constructor key | Env var |
|---|---|
tenant_id |
INTUNE_TENANT_ID / MDE_TENANT_ID |
client_id |
INTUNE_CLIENT_ID / MDE_CLIENT_ID |
client_secret |
INTUNE_CLIENT_SECRET / MDE_CLIENT_SECRET |
Neither supports incremental sync (the reference implementations do via $filter
checkpoints) — every collect() is a full snapshot, per posture's locked snapshot
semantics. intune's device_configurations / device_configuration_detail only
carry the fields the accelerator explicitly named as aliases, not the full raw Graph
payload it also flattens generically. mde's machine_vulnerabilities fans a request
out per machine across a thread pool (up to max_workers, default 25) — the same
pattern as UpGuard's vendor_risks. intune's attack_simulation_users fetches the
targeted-user report for each attack_simulations id (one paginated call per
simulation, click/report/training events kept as JSON blobs rather than exploded
into further tables).
Development
pip install -e ".[dev]"
pytest
ruff check src tests
black src tests
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file posture-0.0.3.tar.gz.
File metadata
- Download URL: posture-0.0.3.tar.gz
- Upload date:
- Size: 39.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2d66a7cb924615a344b6ec6c3e3ac1c4ef81695aa8f855e52de2dc9c7f296cff
|
|
| MD5 |
d0d11ea8d25c3f40d9d2cfd6f6524d26
|
|
| BLAKE2b-256 |
1f98e069570302d339a8e4ecbdce2458742af7028a0aba9b27d64b48e9d01569
|
File details
Details for the file posture-0.0.3-py3-none-any.whl.
File metadata
- Download URL: posture-0.0.3-py3-none-any.whl
- Upload date:
- Size: 35.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
17bfb431c2648da4aeee493d699472cde51d8f0002b30ef7ae93bb2c7186381f
|
|
| MD5 |
6364d1d8a94b7f40fcee5ad9e249bd1b
|
|
| BLAKE2b-256 |
1ea92220f00a649015bc48c61cff67a1a09055f69f913474a7cf17f889420e3a
|