mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-09-30 03:27:15 +02:00
Stack named registry recovery on reviewed logging integration
This commit is contained in:
@@ -58,6 +58,11 @@ tests/SelectedSaclFixtureProtection.cs text eol=lf
|
||||
/scripts/WmiNamespaceAuditing.ps1 text eol=lf
|
||||
/scripts/WefArrival.ps1 text eol=lf
|
||||
/tests/WmiProbe*.ps1 text eol=lf
|
||||
# Actual archive-reader evidence binds implementation and native-token source bytes.
|
||||
/scripts/EvtxRecovery.ps1 text eol=lf
|
||||
/scripts/NativeValidation.ps1 text eol=lf
|
||||
/tests/EvtxRecovery*.ps1 text eol=lf
|
||||
/tests/fixtures/EvtxReader*.ps1 text eol=lf
|
||||
|
||||
# Named registry recovery binds implementation bytes across checkouts.
|
||||
/scripts/NamedRegistryRecovery* text eol=lf
|
||||
@@ -101,6 +106,16 @@ tests/NativeProviderConfigure.Windows.Tests.ps1 text eol=lf
|
||||
/tests/WecCollectorObservation* text eol=lf
|
||||
/tests/WecSubscriptionInventory* text eol=lf
|
||||
|
||||
/tests/TokenRightAttribution*.ps1 text eol=lf
|
||||
/tests/TokenRightAttribution*.cs text eol=lf
|
||||
# Disposable public OneSettings fixture source identity.
|
||||
/tests/OneSettingsConfigure*.ps1 text eol=lf
|
||||
# Scoped NTLM source and native evidence retain stable bytes.
|
||||
/scripts/NtlmAudit.ps1 text eol=lf
|
||||
/tests/NtlmAudit* text eol=lf
|
||||
# Native query receipts bind the same source bytes on every supported engine.
|
||||
/scripts/WefQuery* text eol=lf
|
||||
/tests/WefQuery* text eol=lf
|
||||
# Public filesystem-SACL disposable lifecycle evidence.
|
||||
tests/FileSaclProfileFixture.cs text eol=lf
|
||||
tests/FileSaclLifecycle.Windows.Tests.ps1 text eol=lf
|
||||
|
||||
Reference in New Issue
Block a user