mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
Merge commit '008a8c80b9820318be8d9f833c6adf31c2dbf9a9' into feat/362-scoped-outgoing-ntlm
# Conflicts: # .github/workflows/release.yml # CHANGELOG-Japanese.md # CHANGELOG.md # website/docs/resources/changelog.ja.md # website/docs/resources/changelog.md
This commit is contained in:
commit
559a9d1b82
22 files changed
+608
-11
No files matched your search
@@ -53,12 +53,15 @@ function Get-WelaProviderPackSchema {
|
||||
if ([guid]$provider.Id -eq [guid]::Empty) { throw 'Provider GUID is unknown.' }
|
||||
if (@($logs[0].ProviderNames) -notcontains $Pack.provider -or @($provider.LogLinks.LogName) -notcontains $Pack.channel) { throw 'Provider/channel links disagree.' }
|
||||
$events = @()
|
||||
# EventMetadata.Id is Int64; WinRM includes unrelated IDs above Int32.MaxValue.
|
||||
# Compare before parsing selected templates, without narrowing the native ID.
|
||||
$expectedIds = @($Pack.events | ForEach-Object { [long]$_.id })
|
||||
foreach ($event in $provider.Events) {
|
||||
if (@($Pack.events.id) -contains [int]$event.Id -and $event.LogLink.LogName -eq $Pack.channel) {
|
||||
if ($expectedIds -contains [long]$event.Id -and $event.LogLink.LogName -eq $Pack.channel) {
|
||||
$fields = @(Get-WelaProviderTemplateFields -Template $event.Template)
|
||||
$sha = [Security.Cryptography.SHA256]::Create()
|
||||
try { $templateHash = ([BitConverter]::ToString($sha.ComputeHash([Text.Encoding]::UTF8.GetBytes([string]$event.Template)))).Replace('-','').ToLowerInvariant() } finally { $sha.Dispose() }
|
||||
$events += [pscustomobject]@{ Id=[int]$event.Id; Version=[int]$event.Version; Channel=[string]$event.LogLink.LogName; Fields=$fields; TemplateSha256=$templateHash }
|
||||
$events += [pscustomobject]@{ Id=[long]$event.Id; Version=[int]$event.Version; Channel=[string]$event.LogLink.LogName; Fields=$fields; TemplateSha256=$templateHash }
|
||||
}
|
||||
}
|
||||
[pscustomobject]@{ State='Observed'; Provider=[string]$provider.Name; ProviderGuid=[string]$provider.Id; ChannelType=[string]$logs[0].LogType; Events=$events; Diagnostic=$null }
|
||||
|
||||
@@ -30,13 +30,14 @@ function Get-WelaWefControlState {
|
||||
'SubscriptionManager' { return Get-WelaRegistryState -Path $Target.Path -Name $Target.Name }
|
||||
'ForwardedEvents' { return Get-WelaNativeChannel -Name 'ForwardedEvents' }
|
||||
'Subscription' {
|
||||
$ids = @((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('es')).Output | ForEach-Object { $_.ToString().Trim() } | Where-Object { $_ })
|
||||
$ids = @(Get-WelaWecSubscriptionIds)
|
||||
if ($ids -notcontains $Target.Id) { return [pscustomobject]@{ Exists=$false; Xml=$null; Key=$null; Definition=$null } }
|
||||
# Keep evidence as a plain string. Windows PowerShell 5.1's JSON
|
||||
# serializer expands ETS properties on strings (for example a test
|
||||
# reader's PSDrive/PSProvider graph), unlike modern PowerShell.
|
||||
$xml = [string]::Concat((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('gs',$Target.Id,'/f:xml')).Diagnostic)
|
||||
$xml = [string]::Concat((Read-WelaWecSubscriptionXml -Id $Target.Id))
|
||||
$model = ConvertFrom-WelaWefSubscription -Xml $xml -SourceSids $Target.SourceSids -Observed
|
||||
if($model.Id -cne $Target.Id){throw 'Native subscription identity differs from the selected ID.'}
|
||||
return [pscustomobject]@{ Exists=$true; Xml=$xml; Key=$model.Key; Definition=$model.Definition }
|
||||
}
|
||||
default { throw "Unsupported WEF control kind: $Kind" }
|
||||
|
||||
Reference in new issue
Block a user