mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
Normalize WEF XML evidence before PowerShell 5.1 JSON serialization
This commit is contained in:
1 parent
9b93473904
commit
787c66e009
3 files changed
+18
-7
No files matched your search
@@ -9,18 +9,25 @@ permissions:
|
||||
jobs:
|
||||
wef-deployment:
|
||||
runs-on: windows-latest
|
||||
timeout-minutes: 15
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- name: Safe public command fixtures in Windows PowerShell 5.1
|
||||
shell: powershell
|
||||
run: |
|
||||
./tests/WefDeployment.Tests.ps1
|
||||
./tests/WefDeployment.Cli.Tests.ps1
|
||||
timeout-minutes: 3
|
||||
run: ./tests/WefDeployment.Tests.ps1
|
||||
- name: Public CLI rejection checks in Windows PowerShell 5.1
|
||||
shell: powershell
|
||||
timeout-minutes: 3
|
||||
run: ./tests/WefDeployment.Cli.Tests.ps1
|
||||
- name: Safe public command fixtures in PowerShell 7
|
||||
shell: pwsh
|
||||
run: |
|
||||
./tests/WefDeployment.Tests.ps1
|
||||
./tests/WefDeployment.Cli.Tests.ps1
|
||||
timeout-minutes: 3
|
||||
run: ./tests/WefDeployment.Tests.ps1
|
||||
- name: Public CLI rejection checks in PowerShell 7
|
||||
shell: pwsh
|
||||
timeout-minutes: 3
|
||||
run: ./tests/WefDeployment.Cli.Tests.ps1
|
||||
- name: Native read-only smoke in Windows PowerShell 5.1
|
||||
shell: powershell
|
||||
run: ./tests/WefDeployment.Windows.Tests.ps1
|
||||
|
||||
@@ -32,7 +32,10 @@ function Get-WelaWefControlState {
|
||||
'Subscription' {
|
||||
$ids = @((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('es')).Output | ForEach-Object { $_.ToString().Trim() } | Where-Object { $_ })
|
||||
if ($ids -notcontains $Target.Id) { return [pscustomobject]@{ Exists=$false; Xml=$null; Key=$null; Definition=$null } }
|
||||
$xml = (Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('gs',$Target.Id,'/f:xml')).Diagnostic
|
||||
# Keep evidence as a plain string. Windows PowerShell 5.1's JSON
|
||||
# serializer expands ETS properties on strings (for example a test
|
||||
# reader's PSDrive/PSProvider graph), unlike modern PowerShell.
|
||||
$xml = [string]::Concat((Invoke-WelaNative -FilePath 'wecutil.exe' -Arguments @('gs',$Target.Id,'/f:xml')).Diagnostic)
|
||||
$model = ConvertFrom-WelaWefSubscription -Xml $xml -SourceSids $Target.SourceSids -Observed
|
||||
return [pscustomobject]@{ Exists=$true; Xml=$xml; Key=$model.Key; Definition=$model.Definition }
|
||||
}
|
||||
|
||||
@@ -202,6 +202,7 @@ try {
|
||||
$global:WelaWefFixture.Forwarded=$false
|
||||
$report=Invoke-Collector -ResultsPath (Join-Path $temp 'collector-result.json')
|
||||
Assert ($report.ExitCode -eq 0 -and $global:WelaWefFixture.Subs.Count -eq 1) 'Verified collector creates only the selected explicit subscription'
|
||||
Assert ($null -eq $report.Subscriptions[0].ObservedSubscription.Xml.PSObject.Properties['PSDrive']) 'Observed XML strips reader ETS metadata before Windows PowerShell 5.1 JSON serialization'
|
||||
Assert ($report.Subscriptions[0].Runtime.Raw -eq 'Localized runtime fixture' -and $report.Subscriptions[0].EventArrival -eq 'Not tested') 'Native runtime evidence is retained without inventing successful arrivals'
|
||||
Assert ($report.Subscriptions[0].ChannelObservationLocation -like 'Collector only*') 'Collector channel inventory is not misrepresented as remote source state'
|
||||
$beforeWrites=$global:WelaWefFixture.Writes.Count; $script:backup=Join-Path $temp ([guid]::NewGuid().ToString('N')); $global:WelaWefFixture.Backup=$backup
|
||||
|
||||
Reference in new issue
Block a user