mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
Merge remote-tracking branch 'origin/dev' into feat/10-scoring-closure
This commit is contained in:
commit
6ed7b4e3d4
6 files changed
+18
-4
No files matched your search
@@ -2,7 +2,9 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10)
|
||||
- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185)
|
||||
|
||||
- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387)
|
||||
|
||||
- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386)
|
||||
|
||||
|
||||
+3
-1
@@ -2,7 +2,9 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10)
|
||||
- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185)
|
||||
|
||||
- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387)
|
||||
|
||||
- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386)
|
||||
|
||||
|
||||
@@ -121,3 +121,6 @@ These are hosted standalone servers classified by the shared profile engine as
|
||||
MemberServer; no domain join or GPO refresh is simulated. Configuration and
|
||||
benign event/backend acceptance on Windows 11, domain-joined servers, DC and AD CS labs remain separate;
|
||||
no clean-install or detection-coverage claim is made.
|
||||
### Issue 185 coverage
|
||||
|
||||
Custom audit settings are loaded from a versioned JSON profile instead of requiring script edits. Exact, minimum, preserve, optional, and not-configured semantics are validated before configuration, with profile hashes guarding against drift.
|
||||
@@ -69,3 +69,6 @@ Only relative files inside the bundle directory are read. Traversal, UNC paths,
|
||||
Use separate Windows 11, member-server, DC and member-server CA snapshots. Record build/patch, domain membership, roles, corpus/mapping hashes and backend version. Capture before state, apply an approved source profile, generate a benign operation corresponding to one explicitly selected full rule, save native XML, then capture after state. Confirm field normalization and source identity at the collector/backend, execute the exact translated query, retain its match and independently review the normalization. SACL-dependent rules require additional reviewed adapters; a file/AD/WMI policy toggle alone never closes that gap. Measure event volume, loss/backlog and overhead separately and preserve those records; this importer does not infer EPS or storage capacity.
|
||||
|
||||
Hosted CI uses synthetic fixtures and read-only Windows observations. It supplies no clean-image before/after matrix, genuine backend-query/ingestion result or end-to-end detection claim. Issue #387 remains open for those acceptance tests and for additional rule/parser adapters.
|
||||
### Issue 387 coverage
|
||||
|
||||
Eligibility is reported as `Ready`, `Conditional`, `Blocked`, or `NotApplicable` from versioned native rule metadata and observed prerequisites. Channel enablement, SACLs, field availability, forwarding, and matching remain separate stages; native 4688 command-line limitations and Sysmon exclusions are explicit.
|
||||
@@ -5,7 +5,9 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10)
|
||||
- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185)
|
||||
|
||||
- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387)
|
||||
|
||||
- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386)
|
||||
|
||||
|
||||
@@ -5,7 +5,9 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10)
|
||||
- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185)
|
||||
|
||||
- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387)
|
||||
|
||||
- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386)
|
||||
|
||||
|
||||
Reference in new issue
Block a user