docs: close issue applicability

This commit is contained in:
Shirofune-Security
2026-09-22 18:20:23 +09:00
parent 76af0e92d8
commit 552592cbac
2 changed files with 5 additions and 0 deletions
+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385)
- Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435))
**Improvements:**
+3
View File
@@ -17,3 +17,6 @@ The bundled CSV remains a historical candidate map, not a universally valid even
Fixtures check malformed/duplicate identifiers, unknown events, ambiguous 4703/object mappings, and independent RPC/token state through all four legacy baseline renderers. Windows CI runs [`auditpol /list /subcategory:* /v`](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol-list) and native policy queries under Windows PowerShell 5.1/PowerShell 7. These checks validate identifiers/readback, not generated event XML. Build-specific client, member-server, DC and CA event/outcome validation remains separate acceptance work for issue #380. Native Windows functionality only; Sysmon is out of scope.
A separate [native4703 attribution fixture](native-token-right-attribution.md) compares the two selected masks on disposable standalone Server2022/2025 hosts with actual fixed privilege-adjustment XML. It retains all other audit masks and records the build/UBR and provider schema. This bounded generation evidence leaves historical candidates conditional and does not grant detection readiness.
# Issue 385 coverage
Historical controls carry product-type, build, edition, optional-feature, and removal metadata. The applicability command reports `Applicable`, `NotApplicable`, or `Unknown` from observed host context and never proposes reinstalling a removed feature. Clean-install default snapshots retain build, patch, role, architecture, and installed-role provenance so client, member-server, domain-controller, and CA references cannot be treated as interchangeable.