From 16d88a6f1ed60e4447a72237fcedba3e573e5863 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Fri, 18 Sep 2026 21:46:28 +0900 Subject: [PATCH 1/4] Enable full domain NTLM auditing only on domain controllers --- .github/workflows/test-domain-ntlm.yml | 19 +++++ WELA.ps1 | 95 ++++++++++++++++++++- tests/DomainNtlm.Tests.ps1 | 111 +++++++++++++++++++++++++ website/docs/commands/usage.md | 19 +++++ 4 files changed, 242 insertions(+), 2 deletions(-) create mode 100644 .github/workflows/test-domain-ntlm.yml create mode 100644 tests/DomainNtlm.Tests.ps1 diff --git a/.github/workflows/test-domain-ntlm.yml b/.github/workflows/test-domain-ntlm.yml new file mode 100644 index 00000000..aaa0b1ff --- /dev/null +++ b/.github/workflows/test-domain-ntlm.yml @@ -0,0 +1,19 @@ +name: Domain NTLM regressions +on: + push: + branches: ['**'] + pull_request: + workflow_dispatch: +permissions: + contents: read +jobs: + test: + runs-on: windows-latest + strategy: + matrix: + shell: [powershell, pwsh] + steps: + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + - name: Test domain NTLM policy without changing host settings + shell: ${{ matrix.shell }} + run: ./tests/DomainNtlm.Tests.ps1 diff --git a/WELA.ps1 b/WELA.ps1 index a5e00cd6..9244b2c7 100644 --- a/WELA.ps1 +++ b/WELA.ps1 @@ -451,6 +451,12 @@ function AuditLogSetting { } } + $domainNtlm = Get-WelaDomainNtlmState + $auditResult += [WELA]::new( + "NTLM Authentication", "Domain NTLM auditing", $domainNtlm.Description, @(), + "Not configured", "Enable all (7) on domain controllers only", "", + "AuditNTLMInDomain; applicability is determined from Win32_OperatingSystem.ProductType." + ) $auditResult | ForEach-Object { $_.CountByLevel() } $auditResult | ForEach-Object { @@ -978,6 +984,90 @@ function UpdateRules { } } +function Get-WelaDomainNtlmState { + # ProductType distinguishes an actual DC from a member server with AD DS tools installed. + $state = [pscustomobject]@{ + Applicable = $false + Readable = $false + Value = $null + Description = 'Unknown (computer role could not be determined)' + } + try { + $os = Get-CimInstance -ClassName Win32_OperatingSystem -Property ProductType -ErrorAction Stop + switch ($os.ProductType) { + 1 { $state.Description = 'Not applicable (Windows client)'; return $state } + 2 { $state.Applicable = $true } + 3 { $state.Description = 'Not applicable (member or standalone server, including non-DC AD CS)'; return $state } + default { return $state } + } + } catch { + $state.Description = "Unknown (computer role query failed: $($_.Exception.Message))" + return $state + } + try { + $path = 'HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters' + $state.Description = 'Not configured' + if (Test-Path -LiteralPath $path -ErrorAction Stop) { + $properties = Get-ItemProperty -LiteralPath $path -ErrorAction Stop + $property = $properties.PSObject.Properties['AuditNTLMInDomain'] + if ($null -ne $property) { + $state.Value = $property.Value + $state.Description = switch ($state.Value) { + 0 { 'Disabled (0)' } + 7 { 'Enable all (7)' } + default { "Value $($state.Value) (not interpreted as Enable all)" } + } + } + } + $state.Readable = $true + } catch { + $state.Description = "Unknown (domain NTLM registry read failed: $($_.Exception.Message))" + } + return $state +} + +function Set-WelaDomainNtlmAudit { + [CmdletBinding(SupportsShouldProcess = $true)] + param ([switch]$Auto) + $state = Get-WelaDomainNtlmState + Write-Host "Domain NTLM auditing: $($state.Description)" + if (-not $state.Applicable) { + Write-Host '[SKIPPED] Domain NTLM policy is only changed on a confirmed domain controller.' -ForegroundColor Yellow + return + } + if (-not $state.Readable) { + throw 'Domain NTLM policy was not changed because its current state could not be read.' + } + if ($state.Value -eq 7) { + Write-Host '[SKIPPED] Domain NTLM auditing is already Enable all (7).' -ForegroundColor Yellow + return + } + $path = 'HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters' + if (-not $PSCmdlet.ShouldProcess("$path\AuditNTLMInDomain", 'Set domain NTLM auditing to Enable all (7)')) { return } + if (-not $Auto) { + $response = Read-Host "Change domain NTLM auditing from '$($state.Description)' to 'Enable all (7)'? (Y/n)" + if ($response -ne '' -and $response -ne 'Y') { + Write-Host '[SKIPPED] Domain NTLM auditing.' -ForegroundColor Yellow + return + } + } + try { + if (-not (Test-Path -LiteralPath $path -ErrorAction Stop)) { + New-Item -Path $path -Force -ErrorAction Stop | Out-Null + } + Set-ItemProperty -LiteralPath $path -Name AuditNTLMInDomain -Value 7 -Type DWord -ErrorAction Stop + $after = Get-WelaDomainNtlmState + if (-not $after.Applicable -or -not $after.Readable -or $after.Value -ne 7) { + throw "Read-back did not confirm Enable all (7). Observed: $($after.Description)" + } + Write-Host '[OK] Domain NTLM auditing: Enable all (7), registry value verified.' -ForegroundColor Green + Write-Host 'Group Policy or MDM may reapply a different value; validate events on the domain controller.' + } catch { + throw "Domain NTLM configuration failed: $($_.Exception.Message)" + } +} + + function Set-RegistryConfig { # レジストリを変更するため -WhatIf / -Confirm に対応する [CmdletBinding(SupportsShouldProcess = $true, ConfirmImpact = 'Medium')] @@ -1294,11 +1384,12 @@ function ConfigureAuditSettings { Write-Host "" $regPaths = @( @{Path = "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0"; Name = "RestrictSendingNTLMTraffic"; Value = 2}, - @{Path = "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0"; Name = "AuditReceivingNTLMTraffic"; Value = 2}, - @{Path = "HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters"; Name = "AuditNTLMInDomain"; Value = 2} + @{Path = "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0"; Name = "AuditReceivingNTLMTraffic"; Value = 2} ) Set-RegistryConfig -RegPaths $regPaths -Auto:$Auto + Set-WelaDomainNtlmAudit -Auto:$Auto + # LDAP query logging (Directory Service EventID 1644) - domain controllers only. # "15 Field Engineering" = 5 makes expensive / inefficient LDAP searches log as 1644, which surfaces # BloodHound / SharpHound-style directory reconnaissance. Only applied where the NTDS role is present. diff --git a/tests/DomainNtlm.Tests.ps1 b/tests/DomainNtlm.Tests.ps1 new file mode 100644 index 00000000..fb57c41a --- /dev/null +++ b/tests/DomainNtlm.Tests.ps1 @@ -0,0 +1,111 @@ +# Safe unit regressions: load function definitions without dispatching WELA or changing host policy. +$ErrorActionPreference = 'Stop' +$tokens = $null +$parseErrors = $null +$ast = [System.Management.Automation.Language.Parser]::ParseFile((Join-Path $PSScriptRoot '../WELA.ps1'), [ref]$tokens, [ref]$parseErrors) +if ($parseErrors.Count) { throw ($parseErrors | Out-String) } +foreach ($functionName in @('Get-WelaDomainNtlmState', 'Set-WelaDomainNtlmAudit')) { + $definition = $ast.Find({ param($node) $node -is [System.Management.Automation.Language.FunctionDefinitionAst] -and $node.Name -eq $functionName }, $true) + if (-not $definition) { throw "Missing function $functionName" } + . ([scriptblock]::Create($definition.Extent.Text)) +} +function Assert-Equal($Actual, $Expected, [string]$Message) { + if ($Actual -cne $Expected) { throw "$Message. Expected '$Expected', got '$Actual'." } + $script:assertions++ +} +function Assert-Throws([scriptblock]$Action, [string]$Message) { + $threw = $false + try { & $Action } catch { $threw = $true } + Assert-Equal $threw $true $Message +} +function Reset-Policy($Value, $ProductType = 2) { + $script:value = $Value + $script:productType = $ProductType + $script:writes = 0 + $script:prompts = 0 + $script:reads = 0 + $script:keyExists = $true + $script:roleFails = $false + $script:readFails = $false + $script:writeFails = $false + $script:ignoreWrite = $false + $script:response = 'Y' +} +function Get-CimInstance { + param($ClassName, $Property, $ErrorAction) + if ($script:roleFails) { throw 'CIM unavailable' } + return [pscustomobject]@{ ProductType = $script:productType } +} +function Test-Path { param($LiteralPath, $ErrorAction) return $script:keyExists } +function Get-ItemProperty { + param($LiteralPath, $ErrorAction) + $script:reads++ + if ($script:readFails) { throw 'Access denied' } + if ($null -eq $script:value) { return [pscustomobject]@{} } + return [pscustomobject]@{ AuditNTLMInDomain = $script:value } +} +function New-Item { param($Path, [switch]$Force, $ErrorAction) $script:keyExists = $true } +function Set-ItemProperty { + param($LiteralPath, $Name, $Value, $Type, $ErrorAction) + if ($script:writeFails) { throw 'Access denied' } + if ($Name -ne 'AuditNTLMInDomain') { throw "Unexpected write: $Name" } + $script:writes++ + if (-not $script:ignoreWrite) { $script:value = $Value } +} +function Read-Host { param($Prompt) $script:prompts++; return $script:response } + +$script:assertions = 0 +foreach ($initial in @($null, 0, 2, 7)) { + Reset-Policy $initial + Set-WelaDomainNtlmAudit -Auto + Assert-Equal $script:value 7 "DC initial value '$initial' reaches Enable all" + $expectedWrites = if ($initial -eq 7) { 0 } else { 1 } + Assert-Equal $script:writes $expectedWrites 'Already configured DCs are idempotent' +} +Reset-Policy 2 +Assert-Equal ((Get-WelaDomainNtlmState).Description) 'Value 2 (not interpreted as Enable all)' 'Migration reports old value without inventing semantics' +foreach ($role in @(1, 3)) { + Reset-Policy 2 $role + Set-WelaDomainNtlmAudit -Auto + Assert-Equal $script:writes 0 "No domain policy writes on non-DC ProductType $role" + Assert-Equal $script:reads 0 'Non-DC domain registry is not read' + Assert-Equal ((Get-WelaDomainNtlmState).Description -like 'Not applicable*') $true 'Non-DC is reported as not applicable' + Assert-Equal $script:value 2 'Existing non-DC value is preserved' +} +foreach ($role in @($null, 0, 42)) { + Reset-Policy 2 $role + Set-WelaDomainNtlmAudit -Auto + Assert-Equal $script:writes 0 'Unknown role never receives domain policy' + Assert-Equal ((Get-WelaDomainNtlmState).Description -like 'Unknown*') $true 'Unknown role is not labeled non-DC' +} +Reset-Policy 2 +$script:roleFails = $true +Set-WelaDomainNtlmAudit -Auto +Assert-Equal $script:writes 0 'Failed role discovery never receives domain policy' +Assert-Equal ((Get-WelaDomainNtlmState).Description -like 'Unknown*query failed*') $true 'Role errors are visible' +Reset-Policy 2 +$script:readFails = $true +Assert-Throws { Set-WelaDomainNtlmAudit -Auto } 'Unreadable DC policy fails visibly' +Assert-Equal $script:writes 0 'Unreadable current value is preserved' +Reset-Policy $null +$script:keyExists = $false +Set-WelaDomainNtlmAudit -Auto +Assert-Equal $script:keyExists $true 'Missing DC policy key is created' +Assert-Equal $script:value 7 'Missing DC key receives Enable all' +Reset-Policy 2 +Set-WelaDomainNtlmAudit -WhatIf +Assert-Equal $script:writes 0 'WhatIf preserves policy' +Assert-Equal $script:prompts 0 'WhatIf does not prompt without Auto' +$script:response = 'n' +Set-WelaDomainNtlmAudit +Assert-Equal $script:writes 0 'Declining preserves policy' +$script:response = '' +Set-WelaDomainNtlmAudit +Assert-Equal $script:value 7 'Confirming applies policy' +Reset-Policy 2 +$script:writeFails = $true +Assert-Throws { Set-WelaDomainNtlmAudit -Auto } 'Write failure propagates' +Reset-Policy 2 +$script:ignoreWrite = $true +Assert-Throws { Set-WelaDomainNtlmAudit -Auto } 'Read-back mismatch propagates' +Write-Host "PASS: $script:assertions domain NTLM assertions (mocked; no host changes)." diff --git a/website/docs/commands/usage.md b/website/docs/commands/usage.md index 7843242e..5e273ab1 100644 --- a/website/docs/commands/usage.md +++ b/website/docs/commands/usage.md @@ -36,6 +36,25 @@ Check the Windows event log file size with Yamato Security's recommendations and ## configure The `configure` command sets the recommended Windows event log audit policy and file size. +Domain NTLM auditing (`AuditNTLMInDomain`) is set to `7` (**Enable all**) only on +confirmed domain controllers. Windows clients, member/standalone servers and +non-DC AD CS servers report **Not applicable** and retain any existing value. +An unavailable or unknown computer role is reported as **Unknown** and skipped. +Role detection uses `Win32_OperatingSystem.ProductType=2`, not the presence of +AD DS tools or a registry key. Before a change, WELA reports the previous numeric +value; legacy value `2` is not described as full auditing. Changes respect the +usual confirmation prompt or `-Auto` and are verified by a registry read-back. +`audit-settings` includes role applicability and the current value in its console +and CSV output. Incoming and outgoing NTLM controls are separate from this policy. + +The [Microsoft NTLM auditing guidance](https://learn.microsoft.com/en-us/defender-for-identity/deploy/configure-windows-event-collection#configure-ntlm-auditing) +describes the policy and event collection prerequisites. A registry read-back +does not prove that events were generated, and GPO or MDM may overwrite a local +change. Validate benign domain NTLM activity and expected Operational events on +an isolated DC before deployment. `tests/DomainNtlm.Tests.ps1` uses mocked OS and +registry access; the associated Windows workflow runs Windows PowerShell 5.1 and +PowerShell 7 without changing host policy. + #### `configure` command examples Apply Yamato Security's recommended settings (with confirmation prompt before changing settings): ``` From d51c37258f86a23cbe0750762e1f88fa87a52af0 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Fri, 18 Sep 2026 21:49:46 +0900 Subject: [PATCH 2/4] Use explicit PowerShell shells in regression workflow --- .github/workflows/test-domain-ntlm.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/test-domain-ntlm.yml b/.github/workflows/test-domain-ntlm.yml index aaa0b1ff..facc0e50 100644 --- a/.github/workflows/test-domain-ntlm.yml +++ b/.github/workflows/test-domain-ntlm.yml @@ -9,11 +9,11 @@ permissions: jobs: test: runs-on: windows-latest - strategy: - matrix: - shell: [powershell, pwsh] steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Test domain NTLM policy without changing host settings - shell: ${{ matrix.shell }} + - name: Test domain NTLM policy in Windows PowerShell 5.1 + shell: powershell + run: ./tests/DomainNtlm.Tests.ps1 + - name: Test domain NTLM policy in PowerShell 7 + shell: pwsh run: ./tests/DomainNtlm.Tests.ps1 From 571f9ff51f2679fd6c846c530ece4e3cb814371a Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Fri, 18 Sep 2026 22:53:31 +0900 Subject: [PATCH 3/4] Document domain NTLM audit correction in changelogs --- CHANGELOG-Japanese.md | 3 ++- CHANGELOG.md | 3 ++- website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 4 ++++ 4 files changed, 10 insertions(+), 2 deletions(-) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index d4b501a2..1f2bc0d2 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -10,6 +10,7 @@ **バグ修正:** +- `configure`で全てのホストに`AuditNTLMInDomain=2`を設定していた問題を修正し、ドメインコントローラと確認できたホストにのみ`7` (Enable all)を設定するようにした。その他のホストや役割を判定できないホストでは、この設定を変更しない。ドメインNTLM監査設定を明示的に表示し、設定後の値の確認とレジストリエラーの報告にも対応した。 (#389) (@Shirofune-Security) - ルールのフィルタ条件が全て適用されず最後の条件のみが適用されていたため、ルール数が正確ではなかった。 (#358) (@fukusuket) - 依存するログが無効になっているルールも使用可能として報告されていた。 (#358) (@fukusuket) - 複数のカテゴリに属するルールが重複してカウントされ、CSVファイルにも重複して出力されていた。 (#358) (@fukusuket) @@ -53,4 +54,4 @@ - `audit-settings`: Windows Event Log audit policy settingsをチェックする - `audit-filesize`: Windows Event Logファイルサイズをチェックする -- `update-rules`: WELAのSigmaルール設定ファイルを更新する \ No newline at end of file +- `update-rules`: WELAのSigmaルール設定ファイルを更新する diff --git a/CHANGELOG.md b/CHANGELOG.md index 96f9ad77..6df0f36e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,6 +12,7 @@ **Bug Fixes:** +- Fixed domain NTLM auditing: `configure` now sets `AuditNTLMInDomain=7` (Enable all) only on confirmed domain controllers, instead of writing `2` on every host. This setting is left unchanged on other hosts and hosts whose role cannot be determined. Audit output reports the domain NTLM setting, and configuration verifies registry writes and reports failures. (#389) (@Shirofune-Security) - Rule filtering applied only the last criterion instead of all of them, so rule counts were inaccurate. (#358) (@fukusuket) - Rules were reported as usable even when the logs they depend on were disabled. (#358) (@fukusuket) - Rules that belong to multiple categories were counted and written to the CSV files multiple times. (#358) (@fukusuket) @@ -55,4 +56,4 @@ - `audit-settings`: Check Windows Event Log audit policy settings. - `audit-filesize`: Check Windows Event Log file size. -- `update-rules`: Update WELA's Sigma rules config files. \ No newline at end of file +- `update-rules`: Update WELA's Sigma rules config files. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 161dfb31..15df5727 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -8,10 +8,12 @@ **改善:** - ベースライン定義を`WELA.ps1`から`config/baselines.json`に外部化し、ベースラインの追加・変更をJSONの編集のみで行えるようにした。 (#358) (@fukusuket) +- `Microsoft-Windows-DFSN-Server/Admin`チャネルを`audit-settings`と`audit-filesize`の確認対象に追加した。 (#358) (@fukusuket) - MITRE ATT&CK Navigatorのヒートマップを ATT&CK v19 に対応させ、ATT&CK側でrevokedとなった技術IDを置換先に書き換えるようにした(例: v19で`T1685`に統合された`T1562`と`T1562.001`)。Navigatorはrevokedのエントリを黙って破棄するため、従来はその分のカバレッジがヒートマップから欠落していた。 (@fukusuket) **バグ修正:** +- `configure`で全てのホストに`AuditNTLMInDomain=2`を設定していた問題を修正し、ドメインコントローラと確認できたホストにのみ`7` (Enable all)を設定するようにした。その他のホストや役割を判定できないホストでは、この設定を変更しない。ドメインNTLM監査設定を明示的に表示し、設定後の値の確認とレジストリエラーの報告にも対応した。 (#389) (@Shirofune-Security) - ルールのフィルタ条件が全て適用されず最後の条件のみが適用されていたため、ルール数が正確ではなかった。 (#358) (@fukusuket) - 依存するログが無効になっているルールも使用可能として報告されていた。 (#358) (@fukusuket) - 複数のカテゴリに属するルールが重複してカウントされ、CSVファイルにも重複して出力されていた。 (#358) (@fukusuket) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index f6da9eca..747d2958 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -7,11 +7,15 @@ **Improvements:** +- Added a `configure-sacl` command that sets targeted audit SACLs on the autostart/persistence registry keys and sensitive files the detection rules watch, so File System (4663), Registry (4657) and Handle Manipulation (4656) auditing produce useful events without enabling global object auditing. It covers machine-wide objects plus per-user HKCU keys and profile AppData across all user profiles and the Default profile (so future users inherit the SACL). Targets live in `config/audit_sacl_targets.json`. (#361) (@YamatoSecurity) +- `configure` now also enables Detailed Tracking > Process Termination (4689), Object Access > Detailed File Share (5145), and (on domain controllers) LDAP query logging (Directory Service 1644 via NTDS `15 Field Engineering`), so a full detection baseline is applied without any manual `auditpol`/registry steps. (#361) (@YamatoSecurity) - Baseline definitions were moved out of `WELA.ps1` into a `config/baselines.json` config file, so adding or changing a baseline is now a JSON-only edit. (#358) (@fukusuket) +- The `Microsoft-Windows-DFSN-Server/Admin` channel is now checked by `audit-settings` and `audit-filesize`. (#358) (@fukusuket) - MITRE ATT&CK Navigator heatmaps are now generated for ATT&CK v19, and technique IDs that ATT&CK has revoked are rewritten to their replacements (for example `T1562` and `T1562.001`, which v19 folded into `T1685`). Navigator silently discards revoked entries, so that coverage used to disappear from the heatmap. (@fukusuket) **Bug Fixes:** +- Fixed domain NTLM auditing: `configure` now sets `AuditNTLMInDomain=7` (Enable all) only on confirmed domain controllers, instead of writing `2` on every host. This setting is left unchanged on other hosts and hosts whose role cannot be determined. Audit output reports the domain NTLM setting, and configuration verifies registry writes and reports failures. (#389) (@Shirofune-Security) - Rule filtering applied only the last criterion instead of all of them, so rule counts were inaccurate. (#358) (@fukusuket) - Rules were reported as usable even when the logs they depend on were disabled. (#358) (@fukusuket) - Rules that belong to multiple categories were counted and written to the CSV files multiple times. (#358) (@fukusuket) From bf69494bd9025bf4e922004711855eebac4970a4 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Fri, 18 Sep 2026 22:59:25 +0900 Subject: [PATCH 4/4] Report configuration-only audit states without rule coverage inference --- .github/workflows/test-domain-ntlm.yml | 6 +++ WELA.ps1 | 9 +++- tests/DomainNtlm.Tests.ps1 | 11 +++++ tests/DomainNtlmAuditOutput.Tests.ps1 | 65 ++++++++++++++++++++++++++ website/docs/commands/usage.md | 8 ++++ 5 files changed, 98 insertions(+), 1 deletion(-) create mode 100644 tests/DomainNtlmAuditOutput.Tests.ps1 diff --git a/.github/workflows/test-domain-ntlm.yml b/.github/workflows/test-domain-ntlm.yml index facc0e50..d94dfec0 100644 --- a/.github/workflows/test-domain-ntlm.yml +++ b/.github/workflows/test-domain-ntlm.yml @@ -17,3 +17,9 @@ jobs: - name: Test domain NTLM policy in PowerShell 7 shell: pwsh run: ./tests/DomainNtlm.Tests.ps1 + - name: Test domain NTLM audit output in Windows PowerShell 5.1 + shell: powershell + run: ./tests/DomainNtlmAuditOutput.Tests.ps1 + - name: Test domain NTLM audit output in PowerShell 7 + shell: pwsh + run: ./tests/DomainNtlmAuditOutput.Tests.ps1 diff --git a/WELA.ps1 b/WELA.ps1 index 9244b2c7..0dd71dff 100644 --- a/WELA.ps1 +++ b/WELA.ps1 @@ -485,7 +485,14 @@ function AuditLogSetting { $disabledCount = ($_.Group | Where-Object { $notEnabled -contains $_.CurrentSetting } | ForEach-Object { $_.Rules.Count } | Measure-Object -Sum).Sum $out = "" $color = "" - if (@($_.Group | Where-Object { $_.CurrentSetting -ne "Unknown" }).Count -eq 0) { + if (@($_.Group | Where-Object { $_.Rules.Count -gt 0 }).Count -eq 0) { + # Configuration-only rows have no rule coverage to aggregate. + # Preserve their observed state, including applicability and errors. + $out = ($_.Group | Select-Object -ExpandProperty CurrentSetting -Unique) -join '; ' + if (-not $out) { $out = 'Unknown' } + $color = 'DarkYellow' + } + elseif (@($_.Group | Where-Object { $_.CurrentSetting -ne "Unknown" }).Count -eq 0) { # 設定を確認できないカテゴリ。無効と断定はできない $out = "Unknown" $color = "DarkYellow" diff --git a/tests/DomainNtlm.Tests.ps1 b/tests/DomainNtlm.Tests.ps1 index fb57c41a..719d0278 100644 --- a/tests/DomainNtlm.Tests.ps1 +++ b/tests/DomainNtlm.Tests.ps1 @@ -102,6 +102,17 @@ Assert-Equal $script:writes 0 'Declining preserves policy' $script:response = '' Set-WelaDomainNtlmAudit Assert-Equal $script:value 7 'Confirming applies policy' +foreach ($confirmation in @('y', 'Y')) { + Reset-Policy 2 + $script:response = $confirmation + Set-WelaDomainNtlmAudit + Assert-Equal $script:value 7 "Confirmation '$confirmation' applies policy" + Assert-Equal $script:writes 1 "Confirmation '$confirmation' writes once" +} +Reset-Policy 2 +$script:response = 'N' +Set-WelaDomainNtlmAudit +Assert-Equal $script:writes 0 'Uppercase refusal preserves policy' Reset-Policy 2 $script:writeFails = $true Assert-Throws { Set-WelaDomainNtlmAudit -Auto } 'Write failure propagates' diff --git a/tests/DomainNtlmAuditOutput.Tests.ps1 b/tests/DomainNtlmAuditOutput.Tests.ps1 new file mode 100644 index 00000000..0b352fd5 --- /dev/null +++ b/tests/DomainNtlmAuditOutput.Tests.ps1 @@ -0,0 +1,65 @@ +# Exercise the real audit renderer/CSV exports with injected observations and rules. +# Only a temporary directory is written; no Windows policy is read or changed. +$ErrorActionPreference = 'Stop' +$tokens = $null; $parseErrors = $null +$ast = [System.Management.Automation.Language.Parser]::ParseFile((Join-Path $PSScriptRoot '../WELA.ps1'), [ref]$tokens, [ref]$parseErrors) +if ($parseErrors.Count) { throw ($parseErrors | Out-String) } +$class = $ast.Find({ param($node) $node -is [System.Management.Automation.Language.TypeDefinitionAst] -and $node.Name -eq 'WELA' }, $true) +. ([scriptblock]::Create($class.Extent.Text)) +$definition = $ast.Find({ param($node) $node -is [System.Management.Automation.Language.FunctionDefinitionAst] -and $node.Name -eq 'AuditLogSetting' }, $true) +. ([scriptblock]::Create($definition.Extent.Text)) + +$script:assertions = 0 +function Assert-Equal($Actual, $Expected, [string]$Message) { + if ($Actual -cne $Expected) { throw "$Message. Expected '$Expected', got '$Actual'." } + $script:assertions++ +} +function TestAdministrator { return $true } +function CollectAuditpol { param([switch]$UseCached) return $true } +function GetAuditpol { return @{} } +function Get-WelaDomainNtlmState { return [pscustomobject]@{ Description = $script:description } } +function Export-MitreHeatmap { param($sigmaRules, $OutputPath, $UseIdealCount) } +function BuildAuditResult { + param($all_rules, $Baseline, $enabledguid) + $all_rules[0].applicable = $true + @( + [WELA]::new('Fixture rules', 'Available', 'Success', @($all_rules[0])) + [WELA]::new('Fixture rules', 'Unavailable', 'No Auditing', @($all_rules[1])) + ) +} + +$script:ScriptRoot = Join-Path ([IO.Path]::GetTempPath()) ('wela-domain-output-' + [guid]::NewGuid().ToString('N')) +$null = New-Item -ItemType Directory -Path $script:ScriptRoot +$script:SecurityRulesPath = Join-Path $script:ScriptRoot 'rules.json' +try { + @( + @{ id = 'available-rule'; title = 'Available fixture'; level = 'high'; subcategory_guids = @() } + @{ id = 'unavailable-rule'; title = 'Unavailable fixture'; level = 'medium'; subcategory_guids = @() } + ) | ConvertTo-Json -Depth 4 | Set-Content -LiteralPath $script:SecurityRulesPath -Encoding UTF8 + foreach ($observed in @( + 'Enable all (7)', + 'Disabled (0)', + 'Not configured', + 'Value 2 (not interpreted as Enable all)', + 'Not applicable (Windows client)', + 'Not applicable (member or standalone server, including non-DC AD CS)', + 'Unknown (computer role could not be determined)', + 'Unknown (domain NTLM registry read failed: Access denied)' + )) { + $script:description = $observed + $output = (AuditLogSetting -outType std -Baseline YamatoSecurity 6>&1 | Out-String) + $expectedHeading = 'NTLM Authentication: ' + $observed + Assert-Equal ($output -match ('(?m)^' + [regex]::Escape($expectedHeading) + '\r?$')) $true "Console heading retains '$observed'" + Assert-Equal ($output -match 'NTLM Authentication: Partially Enabled') $false 'An empty rule array does not imply partial enablement' + Assert-Equal ($output -match 'Fixture rules: Partially Enabled') $true 'Ordinary rule coverage aggregation is preserved' + $row = @(Import-Csv -LiteralPath (Join-Path $script:ScriptRoot 'WELA-Audit-Result.csv') | Where-Object SubCategory -eq 'Domain NTLM auditing') + Assert-Equal $row.Count 1 'CSV contains one domain NTLM setting row' + Assert-Equal $row[0].CurrentSetting $observed 'CSV retains the observed configuration state' + Assert-Equal $row[0].RuleCount '0' 'Configuration row claims no detection rules' + Assert-Equal @(Import-Csv -LiteralPath (Join-Path $script:ScriptRoot 'UsableRules.csv')).Count 1 'Configuration row does not change usable rule counts' + Assert-Equal @(Import-Csv -LiteralPath (Join-Path $script:ScriptRoot 'UnusableRules.csv')).Count 1 'Configuration row does not change unusable rule counts' + } + Write-Host "PASS: $script:assertions domain NTLM output assertions (mocked observations; temporary CSV files only)." +} finally { + Remove-Item -LiteralPath $script:ScriptRoot -Recurse -Force +} diff --git a/website/docs/commands/usage.md b/website/docs/commands/usage.md index 5e273ab1..353b6545 100644 --- a/website/docs/commands/usage.md +++ b/website/docs/commands/usage.md @@ -55,6 +55,14 @@ an isolated DC before deployment. `tests/DomainNtlm.Tests.ps1` uses mocked OS an registry access; the associated Windows workflow runs Windows PowerShell 5.1 and PowerShell 7 without changing host policy. +Live-DC validation for [issue #363](https://github.com/Yamato-Security/WELA/issues/363) +remains pending. Before closing that issue, record the Windows build and confirmed +DC role, the previous registry value/type, the verified `AuditNTLMInDomain=7` +DWORD, and representative NTLM event XML from benign test authentication. Also +check that a second run is idempotent and that clients, member servers and non-DC CAs leave +this domain-only setting unchanged. Mocked policy tests and console/CSV regression +tests do not provide this event-generation evidence. + #### `configure` command examples Apply Yamato Security's recommended settings (with confirmation prompt before changing settings): ```