mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 07:15:25 +02:00
Add a native local failed-logon audit probe (#444)
* Add native local nonexistent-account failed-logon probe * Match actual MSV1 local authentication event package * Refuse coerced identity and authentication receipt fields * Preserve explicit UTC DateTime receipts on older PowerShell7 * Reject unknown failed-logon probe options before dispatch
This commit is contained in:
1 parent
203fdfc942
commit
6d228fedef
14 files changed
+454
-1
No files matched your search
@@ -0,0 +1,14 @@
|
||||
param([Parameter(Mandatory)][ValidatePattern('^[a-f0-9]{32}$')][string]$Nonce)
|
||||
$ErrorActionPreference='Stop';[Console]::OutputEncoding=[Text.UTF8Encoding]::new($false)
|
||||
$script:ScriptRoot=Split-Path $PSScriptRoot -Parent
|
||||
. "$PSScriptRoot/WefArrival.ps1"
|
||||
. "$PSScriptRoot/ChannelRead.ps1"
|
||||
. "$PSScriptRoot/FailedLogonProbe.ps1"
|
||||
Initialize-WelaFailedLogonNative
|
||||
foreach($name in @('EventLog','Winmgmt','SamSs','RpcSs')){if((Get-Service -Name $name -ErrorAction Stop).Status -ne 'Running'){throw 'Required native services must already be running.'}}
|
||||
$hostState=Get-WelaChannelReadHost
|
||||
if($hostState.ProductType -notin @(1,3) -or $hostState.DomainRole -notin @(0,1,2,3)){throw 'A local SAM client or member/standalone server is required.'}
|
||||
$before=Get-WelaChannelReader
|
||||
$result=[Wela.FailedLogonProbe.Native]::Run($Nonce)
|
||||
$after=Get-WelaChannelReader
|
||||
[pscustomobject][ordered]@{Nonce=$Nonce;ProcessId=$PID;Executable=(Get-Process -Id $PID).Path;BeforeToken=$before;AfterToken=$after;Attempt=$result}|ConvertTo-Json -Depth 10 -Compress
|
||||
Reference in new issue
Block a user