mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-09-30 03:27:15 +02:00
docs: close issue applicability
This commit is contained in:
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385)
|
||||
|
||||
- Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435))
|
||||
|
||||
**Improvements:**
|
||||
|
||||
@@ -17,3 +17,6 @@ The bundled CSV remains a historical candidate map, not a universally valid even
|
||||
Fixtures check malformed/duplicate identifiers, unknown events, ambiguous 4703/object mappings, and independent RPC/token state through all four legacy baseline renderers. Windows CI runs [`auditpol /list /subcategory:* /v`](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol-list) and native policy queries under Windows PowerShell 5.1/PowerShell 7. These checks validate identifiers/readback, not generated event XML. Build-specific client, member-server, DC and CA event/outcome validation remains separate acceptance work for issue #380. Native Windows functionality only; Sysmon is out of scope.
|
||||
|
||||
A separate [native4703 attribution fixture](native-token-right-attribution.md) compares the two selected masks on disposable standalone Server2022/2025 hosts with actual fixed privilege-adjustment XML. It retains all other audit masks and records the build/UBR and provider schema. This bounded generation evidence leaves historical candidates conditional and does not grant detection readiness.
|
||||
# Issue 385 coverage
|
||||
|
||||
Historical controls carry product-type, build, edition, optional-feature, and removal metadata. The applicability command reports `Applicable`, `NotApplicable`, or `Unknown` from observed host context and never proposes reinstalling a removed feature. Clean-install default snapshots retain build, patch, role, architecture, and installed-role provenance so client, member-server, domain-controller, and CA references cannot be treated as interchangeable.
|
||||
|
||||
Reference in New Issue
Block a user