From dbabb8eada9423676815dbac0cb0f4faf1dbb186 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:37:09 +0900 Subject: [PATCH 1/5] docs: document native issue coverage --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ docs/applocker-readiness.md | 4 ++++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 5 files changed, 12 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index ebf3cb2e..63471d27 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381) + - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) - 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4a273d1b..511730e3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381) + - Document the versioned offline Intune audit export and assignment limitations. (Related #1) - Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) diff --git a/docs/applocker-readiness.md b/docs/applocker-readiness.md index c5f3737b..ed3709ac 100644 --- a/docs/applocker-readiness.md +++ b/docs/applocker-readiness.md @@ -1,5 +1,9 @@ # Native AppLocker readiness +### Issue 381 coverage + +AppLocker readiness observes the effective policy, AppIDSvc, and native channels before any optional import. Only an operator-supplied audit-only policy may be imported; existing enforcement policies are preserved, and policy state is kept separate from event generation and Sigma eligibility. + `applocker-readiness` reports local and GP effective policy XML, each of the five rule collections, enforcement modes, rule counts, Application Identity (`AppIDSvc`) state/start mode and relevant AppLocker channel observations. A host with enabled channels but no rules reports `MissingGpPolicy`. Stopped/disabled services, missing channels, unavailable cmdlets and read errors remain explicit. `NotConfigured` with rules is treated as potential enforcement, never as disabled. ```powershell diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index d050f6c2..4bf86f73 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381) + - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) - 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 3e39476a..27f44b96 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381) + - Document the versioned offline Intune audit export and assignment limitations. (Related #1) - Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) From f5f565097cabb697dd661347a430d3b6b6dafa9c Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:37:13 +0900 Subject: [PATCH 2/5] docs: document native issue coverage --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ docs/native-token-right-attribution.md | 4 ++++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 5 files changed, 12 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index ebf3cb2e..1ad029ae 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ Security 4703 帰属証跡と、条件付きマッピングの範囲を文書化しました。 (#380) + - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) - 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4a273d1b..d76d2229 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document native Security 4703 attribution evidence and conditional mapping boundaries. (Related #380) + - Document the versioned offline Intune audit export and assignment limitations. (Related #1) - Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) diff --git a/docs/native-token-right-attribution.md b/docs/native-token-right-attribution.md index df3a5093..9f885803 100644 --- a/docs/native-token-right-attribution.md +++ b/docs/native-token-right-attribution.md @@ -1,5 +1,9 @@ # Native Security 4703 audit attribution +### Issue 380 coverage + +Token-right attribution pins the canonical Security 4703 GUID and retains the competing historical mappings as conditional candidates. Native event XML, audit masks, token context, and cleanup evidence are required before attribution; a catalog match alone does not claim universal Windows coverage. + The disposable `Native Security 4703 audit attribution` workflow tests the two historical audit-subcategory candidates for event 4703 on standalone Windows Server 2022/2025 under Windows PowerShell 5.1 and PowerShell 7. It does not add a production probe, change WELA policy recommendations, remove historical mapping candidates or grant Sigma readiness. Microsoft's [Token Right Adjusted guidance](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/audit-token-right-adjusted) and [advanced audit-policy reference](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/advanced-audit-policy-configuration) associate 4703 with token adjustment. The older [4703 event reference](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4703) names Authorization Policy Change. [WELA's mapping review](audit-catalog-mappings.md) retains both historical candidates as conditional. Native evidence below is specific to the recorded Windows build/UBR, provider manifest, engine and fixed operation. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index d050f6c2..0c08b146 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ Security 4703 帰属証跡と、条件付きマッピングの範囲を文書化しました。 (#380) + - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) - 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 3e39476a..61eb0d02 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document native Security 4703 attribution evidence and conditional mapping boundaries. (Related #380) + - Document the versioned offline Intune audit export and assignment limitations. (Related #1) - Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) From 6609025d65853908156bd2262a5144e6d829a952 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:37:17 +0900 Subject: [PATCH 3/5] docs: document native issue coverage --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ docs/eventlog-settings.md | 4 ++++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 5 files changed, 12 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index ebf3cb2e..03864696 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379) + - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) - 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4a273d1b..b6306b7d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379) + - Document the versioned offline Intune audit export and assignment limitations. (Related #1) - Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) diff --git a/docs/eventlog-settings.md b/docs/eventlog-settings.md index 2b5dc129..a61a263d 100644 --- a/docs/eventlog-settings.md +++ b/docs/eventlog-settings.md @@ -1,5 +1,9 @@ # Event-log sizes and retention modes +### Issue 379 coverage + +Event-log sizing and retention changes are explicit per-channel controls with typed before/after evidence, mode preservation, and guarded recovery. Buffer size does not establish a retention duration, archive capacity, forwarding health, or absence of event loss. + `audit-filesize` and ordinary `configure` now use the same `config/eventlog_profiles.json` definitions. `-Profile` continues to select **advanced audit policy only**. Use the separate `-LogProfile` option with diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index d050f6c2..724b2bb1 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379) + - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) - 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 3e39476a..1a0611e2 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379) + - Document the versioned offline Intune audit export and assignment limitations. (Related #1) - Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) From 896cc5a249076ec4c58bb0637ee16a209f092f22 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 08:57:52 +0900 Subject: [PATCH 4/5] docs: restore token changelog entry --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 4 files changed, 8 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index 63471d27..c6c9f2a9 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ Security 4703 帰属証跡と、条件付きマッピングの範囲を文書化しました。 (#380) + - ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381) - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) diff --git a/CHANGELOG.md b/CHANGELOG.md index 511730e3..29c6d2cd 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document native Security 4703 attribution evidence and conditional mapping boundaries. (Related #380) + - Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381) - Document the versioned offline Intune audit export and assignment limitations. (Related #1) diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 4bf86f73..5dce36cc 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ Security 4703 帰属証跡と、条件付きマッピングの範囲を文書化しました。 (#380) + - ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381) - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 27f44b96..25d1139c 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document native Security 4703 attribution evidence and conditional mapping boundaries. (Related #380) + - Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381) - Document the versioned offline Intune audit export and assignment limitations. (Related #1) From 5527649c3c4ab4f746cb971b63b09b3e41a7d2cc Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 08:58:15 +0900 Subject: [PATCH 5/5] docs: restore eventlog changelog entry --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 4 files changed, 8 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index c6c9f2a9..3405c624 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379) + - ネイティブ Security 4703 帰属証跡と、条件付きマッピングの範囲を文書化しました。 (#380) - ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381) diff --git a/CHANGELOG.md b/CHANGELOG.md index 29c6d2cd..79c701fa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379) + - Document native Security 4703 attribution evidence and conditional mapping boundaries. (Related #380) - Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381) diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 5dce36cc..997f9e97 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379) + - ネイティブ Security 4703 帰属証跡と、条件付きマッピングの範囲を文書化しました。 (#380) - ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 25d1139c..00f6799e 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379) + - Document native Security 4703 attribution evidence and conditional mapping boundaries. (Related #380) - Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381)