diff --git a/CHANGELOG.md b/CHANGELOG.md index ceecb503..fbabed36 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) + - Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435)) **Improvements:** diff --git a/docs/audit-catalog-mappings.md b/docs/audit-catalog-mappings.md index 8dbd19be..39c99445 100644 --- a/docs/audit-catalog-mappings.md +++ b/docs/audit-catalog-mappings.md @@ -17,3 +17,6 @@ The bundled CSV remains a historical candidate map, not a universally valid even Fixtures check malformed/duplicate identifiers, unknown events, ambiguous 4703/object mappings, and independent RPC/token state through all four legacy baseline renderers. Windows CI runs [`auditpol /list /subcategory:* /v`](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/auditpol-list) and native policy queries under Windows PowerShell 5.1/PowerShell 7. These checks validate identifiers/readback, not generated event XML. Build-specific client, member-server, DC and CA event/outcome validation remains separate acceptance work for issue #380. Native Windows functionality only; Sysmon is out of scope. A separate [native4703 attribution fixture](native-token-right-attribution.md) compares the two selected masks on disposable standalone Server2022/2025 hosts with actual fixed privilege-adjustment XML. It retains all other audit masks and records the build/UBR and provider schema. This bounded generation evidence leaves historical candidates conditional and does not grant detection readiness. +# Issue 385 coverage + +Historical controls carry product-type, build, edition, optional-feature, and removal metadata. The applicability command reports `Applicable`, `NotApplicable`, or `Unknown` from observed host context and never proposes reinstalling a removed feature. Clean-install default snapshots retain build, patch, role, architecture, and installed-role provenance so client, member-server, domain-controller, and CA references cannot be treated as interchangeable.