mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-07 23:14:45 +02:00
Accept native UInt16 CIM domain roles in registry probe preflight
This commit is contained in:
1 parent
7e1b076254
commit
32cfb460a2
2 files changed
+11
-1
No files matched your search
@@ -10,6 +10,12 @@ function Get-WelaRegistryValueProbeSources {
|
||||
foreach($name in @('WELA.ps1','scripts/RegistryValueProbe.ps1','scripts/RegistryValueProbeNative.cs','scripts/FileAccessProbe.ps1','scripts/WmiProbe.ps1','scripts/WmiProbeNative.cs','scripts/ChannelRead.ps1','scripts/ChannelReadNative.cs','scripts/WefArrival.ps1','scripts/Configuration.ps1','modules/AuditProfiles.psm1','scripts/CustomAuditProfiles.ps1','scripts/IpsecPrerequisites.ps1','config/audit_profiles.json')){$sources[$name]=(Get-FileHash -LiteralPath (Join-Path $PSScriptRoot ('../'+$name)) -Algorithm SHA256 -ErrorAction Stop).Hash.ToLowerInvariant()}
|
||||
[pscustomobject]$sources
|
||||
}
|
||||
function Assert-WelaRegistryValueProbeComputerRole {
|
||||
param($Computer)
|
||||
# Win32_ComputerSystem.DomainRole is a native CIM UInt16, before JSON normalization.
|
||||
$role=$Computer.DomainRole
|
||||
if((-not($role -is [uint16]) -and -not(Test-WelaFileProbeInteger $role)) -or $role -notin 0,1,2,3,4,5 -or $Computer.PartOfDomain -isnot [bool]){throw 'Native Windows role and join observations are incomplete.'}
|
||||
}
|
||||
function Get-WelaRegistryValueProbeState {
|
||||
if($env:OS -ne 'Windows_NT' -or -not [Environment]::Is64BitProcess){throw 'Native 64-bit Windows is required.'}
|
||||
Initialize-WelaRegistryValueProbe
|
||||
@@ -18,7 +24,7 @@ function Get-WelaRegistryValueProbeState {
|
||||
if($services.Count -ne 3 -or @($services|Where-Object Status -ne Running).Count){throw 'EventLog, Winmgmt and RpcSs must already be running.'}
|
||||
$reader=Get-WelaChannelReader;$null=Get-WelaFileProbeReaderKey $reader
|
||||
$computer=Get-CimInstance Win32_ComputerSystem -Property DomainRole,PartOfDomain -ErrorAction Stop
|
||||
if(-not(Test-WelaFileProbeInteger $computer.DomainRole) -or $computer.PartOfDomain -isnot [bool]){throw 'Native Windows role and join observations are incomplete.'}
|
||||
Assert-WelaRegistryValueProbeComputerRole $computer
|
||||
$hostState=Get-WelaChannelReadHost
|
||||
if($hostState.DomainRole -ne $computer.DomainRole -or $hostState.DomainJoined -ne $computer.PartOfDomain){throw 'Native Windows role or join state changed during observation.'}
|
||||
$target=[Wela.RegistryValueProbe.Target]::new($false)
|
||||
|
||||
@@ -16,6 +16,10 @@ function Xml {
|
||||
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"><System><Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}"/><EventID>4657</EventID><Version>0</Version><Level>0</Level><Task>12801</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime="2026-09-21T00:00:00.0001500Z"/><EventRecordID>11</EventRecordID><Channel>Security</Channel><Computer>FIXTURE</Computer></System><EventData><Data Name="SubjectUserSid">S-1-5-21-1-2-3-1001</Data><Data Name="SubjectUserName">Reader</Data><Data Name="SubjectDomainName">FIXTURE</Data><Data Name="SubjectLogonId">0x1234</Data><Data Name="ObjectName">\REGISTRY\USER\S-1-5-21-1-2-3-1001\Software\WELA\AuditProbe</Data><Data Name="ObjectValueName">$($script:operation.Native.Name)</Data><Data Name="HandleId">0x888</Data><Data Name="OperationType">%%1905</Data><Data Name="OldValueType">%%1873</Data><Data Name="OldValue">$($script:operation.Native.BeforeValue)</Data><Data Name="NewValueType">%%1873</Data><Data Name="NewValue">$($script:operation.Native.AfterValue)</Data><Data Name="ProcessId">0x4d2</Data><Data Name="ProcessName">C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe</Data></EventData></Event>
|
||||
"@
|
||||
}
|
||||
# The live CIM schema uses UInt16; JSON fixtures normalize numbers to Int32.
|
||||
foreach($role in @([uint16]2,[int]2)) {Assert-WelaRegistryValueProbeComputerRole ([pscustomobject]@{DomainRole=$role;PartOfDomain=$false});Assert $true 'Native UInt16 and normalized Int32 roles are accepted.'}
|
||||
foreach($role in @($null,$true,'2',2.5,6,-1)) {Reject {Assert-WelaRegistryValueProbeComputerRole ([pscustomobject]@{DomainRole=$role;PartOfDomain=$false})}}
|
||||
Reject {Assert-WelaRegistryValueProbeComputerRole ([pscustomobject]@{DomainRole=[uint16]2;PartOfDomain='false'})}
|
||||
Fixture;$null=Get-WelaRegistryValueProbeStateKey $script:state;Assert-WelaRegistryValueProbeOperation $script:operation $script:state;Assert $true 'Complete fixed-key operation with cleanup is accepted.'
|
||||
foreach($bad in @('path','mask','precedence','channel','role','group','inherit-only','failure','callback','right','descriptor','sources','token')){
|
||||
Fixture
|
||||
|
||||
Reference in new issue
Block a user