From 32cfb460a2829a7fffc4b621f51051fa20105828 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Tue, 22 Sep 2026 15:32:00 +0900 Subject: [PATCH] Accept native UInt16 CIM domain roles in registry probe preflight --- scripts/RegistryValueProbe.ps1 | 8 +++++++- tests/RegistryValueProbe.Tests.ps1 | 4 ++++ 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/scripts/RegistryValueProbe.ps1 b/scripts/RegistryValueProbe.ps1 index e5ef3a4c..04d2f715 100644 --- a/scripts/RegistryValueProbe.ps1 +++ b/scripts/RegistryValueProbe.ps1 @@ -10,6 +10,12 @@ function Get-WelaRegistryValueProbeSources { foreach($name in @('WELA.ps1','scripts/RegistryValueProbe.ps1','scripts/RegistryValueProbeNative.cs','scripts/FileAccessProbe.ps1','scripts/WmiProbe.ps1','scripts/WmiProbeNative.cs','scripts/ChannelRead.ps1','scripts/ChannelReadNative.cs','scripts/WefArrival.ps1','scripts/Configuration.ps1','modules/AuditProfiles.psm1','scripts/CustomAuditProfiles.ps1','scripts/IpsecPrerequisites.ps1','config/audit_profiles.json')){$sources[$name]=(Get-FileHash -LiteralPath (Join-Path $PSScriptRoot ('../'+$name)) -Algorithm SHA256 -ErrorAction Stop).Hash.ToLowerInvariant()} [pscustomobject]$sources } +function Assert-WelaRegistryValueProbeComputerRole { + param($Computer) + # Win32_ComputerSystem.DomainRole is a native CIM UInt16, before JSON normalization. + $role=$Computer.DomainRole + if((-not($role -is [uint16]) -and -not(Test-WelaFileProbeInteger $role)) -or $role -notin 0,1,2,3,4,5 -or $Computer.PartOfDomain -isnot [bool]){throw 'Native Windows role and join observations are incomplete.'} +} function Get-WelaRegistryValueProbeState { if($env:OS -ne 'Windows_NT' -or -not [Environment]::Is64BitProcess){throw 'Native 64-bit Windows is required.'} Initialize-WelaRegistryValueProbe @@ -18,7 +24,7 @@ function Get-WelaRegistryValueProbeState { if($services.Count -ne 3 -or @($services|Where-Object Status -ne Running).Count){throw 'EventLog, Winmgmt and RpcSs must already be running.'} $reader=Get-WelaChannelReader;$null=Get-WelaFileProbeReaderKey $reader $computer=Get-CimInstance Win32_ComputerSystem -Property DomainRole,PartOfDomain -ErrorAction Stop - if(-not(Test-WelaFileProbeInteger $computer.DomainRole) -or $computer.PartOfDomain -isnot [bool]){throw 'Native Windows role and join observations are incomplete.'} + Assert-WelaRegistryValueProbeComputerRole $computer $hostState=Get-WelaChannelReadHost if($hostState.DomainRole -ne $computer.DomainRole -or $hostState.DomainJoined -ne $computer.PartOfDomain){throw 'Native Windows role or join state changed during observation.'} $target=[Wela.RegistryValueProbe.Target]::new($false) diff --git a/tests/RegistryValueProbe.Tests.ps1 b/tests/RegistryValueProbe.Tests.ps1 index f7692b67..e8798ae9 100644 --- a/tests/RegistryValueProbe.Tests.ps1 +++ b/tests/RegistryValueProbe.Tests.ps1 @@ -16,6 +16,10 @@ function Xml { 4657001280100x802000000000000011SecurityFIXTURES-1-5-21-1-2-3-1001ReaderFIXTURE0x1234\REGISTRY\USER\S-1-5-21-1-2-3-1001\Software\WELA\AuditProbe$($script:operation.Native.Name)0x888%%1905%%1873$($script:operation.Native.BeforeValue)%%1873$($script:operation.Native.AfterValue)0x4d2C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "@ } +# The live CIM schema uses UInt16; JSON fixtures normalize numbers to Int32. +foreach($role in @([uint16]2,[int]2)) {Assert-WelaRegistryValueProbeComputerRole ([pscustomobject]@{DomainRole=$role;PartOfDomain=$false});Assert $true 'Native UInt16 and normalized Int32 roles are accepted.'} +foreach($role in @($null,$true,'2',2.5,6,-1)) {Reject {Assert-WelaRegistryValueProbeComputerRole ([pscustomobject]@{DomainRole=$role;PartOfDomain=$false})}} +Reject {Assert-WelaRegistryValueProbeComputerRole ([pscustomobject]@{DomainRole=[uint16]2;PartOfDomain='false'})} Fixture;$null=Get-WelaRegistryValueProbeStateKey $script:state;Assert-WelaRegistryValueProbeOperation $script:operation $script:state;Assert $true 'Complete fixed-key operation with cleanup is accepted.' foreach($bad in @('path','mask','precedence','channel','role','group','inherit-only','failure','callback','right','descriptor','sources','token')){ Fixture