Merge commit '008a8c80b9820318be8d9f833c6adf31c2dbf9a9' into feat/362-scoped-outgoing-ntlm

# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
This commit is contained in:
Shirofune-Security committed 2026-09-22 11:42:30 +09:00
commit 559a9d1b82
22 files changed
+608 -11

No files matched your search

+5 -2
View File
@@ -53,12 +53,15 @@ function Get-WelaProviderPackSchema {
if ([guid]$provider.Id -eq [guid]::Empty) { throw 'Provider GUID is unknown.' }
if (@($logs[0].ProviderNames) -notcontains $Pack.provider -or @($provider.LogLinks.LogName) -notcontains $Pack.channel) { throw 'Provider/channel links disagree.' }
$events = @()
# EventMetadata.Id is Int64; WinRM includes unrelated IDs above Int32.MaxValue.
# Compare before parsing selected templates, without narrowing the native ID.
$expectedIds = @($Pack.events | ForEach-Object { [long]$_.id })
foreach ($event in $provider.Events) {
if (@($Pack.events.id) -contains [int]$event.Id -and $event.LogLink.LogName -eq $Pack.channel) {
if ($expectedIds -contains [long]$event.Id -and $event.LogLink.LogName -eq $Pack.channel) {
$fields = @(Get-WelaProviderTemplateFields -Template $event.Template)
$sha = [Security.Cryptography.SHA256]::Create()
try { $templateHash = ([BitConverter]::ToString($sha.ComputeHash([Text.Encoding]::UTF8.GetBytes([string]$event.Template)))).Replace('-','').ToLowerInvariant() } finally { $sha.Dispose() }
$events += [pscustomobject]@{ Id=[int]$event.Id; Version=[int]$event.Version; Channel=[string]$event.LogLink.LogName; Fields=$fields; TemplateSha256=$templateHash }
$events += [pscustomobject]@{ Id=[long]$event.Id; Version=[int]$event.Version; Channel=[string]$event.LogLink.LogName; Fields=$fields; TemplateSha256=$templateHash }
}
}
[pscustomobject]@{ State='Observed'; Provider=[string]$provider.Name; ProviderGuid=[string]$provider.Id; ChannelType=[string]$logs[0].LogType; Events=$events; Diagnostic=$null }
+3 -2
View File
@@ -30,13 +30,14 @@ function Get-WelaWefControlState {
'SubscriptionManager' { return Get-WelaRegistryState -Path $Target.Path -Name $Target.Name }
'ForwardedEvents' { return Get-WelaNativeChannel -Name 'ForwardedEvents' }
'Subscription' {
$ids = @((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('es')).Output | ForEach-Object { $_.ToString().Trim() } | Where-Object { $_ })
$ids = @(Get-WelaWecSubscriptionIds)
if ($ids -notcontains $Target.Id) { return [pscustomobject]@{ Exists=$false; Xml=$null; Key=$null; Definition=$null } }
# Keep evidence as a plain string. Windows PowerShell 5.1's JSON
# serializer expands ETS properties on strings (for example a test
# reader's PSDrive/PSProvider graph), unlike modern PowerShell.
$xml = [string]::Concat((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('gs',$Target.Id,'/f:xml')).Diagnostic)
$xml = [string]::Concat((Read-WelaWecSubscriptionXml -Id $Target.Id))
$model = ConvertFrom-WelaWefSubscription -Xml $xml -SourceSids $Target.SourceSids -Observed
if($model.Id -cne $Target.Id){throw 'Native subscription identity differs from the selected ID.'}
return [pscustomobject]@{ Exists=$true; Xml=$xml; Key=$model.Key; Definition=$model.Definition }
}
default { throw "Unsupported WEF control kind: $Kind" }