mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
Fix audit applicability, NTLM value types, and native exit verification
This commit is contained in:
1 parent
71215ab498
commit
7d2117ebba
14 files changed
+426
-40
No files matched your search
@@ -370,10 +370,10 @@ function Set-WelaNtlmConfigurationControl {
|
||||
$skipReason = $state.Description
|
||||
} elseif (-not $state.Readable) {
|
||||
throw "$Scope NTLM current state could not be read: $($state.Description)"
|
||||
} elseif ($Scope -eq 'Outgoing' -and $Mode -eq 'PreserveOrAudit' -and $state.Value -eq 2) {
|
||||
} elseif ($Scope -eq 'Outgoing' -and $Mode -eq 'PreserveOrAudit' -and $state.Type -eq 'DWord' -and $state.Value -eq 2) {
|
||||
$skipReason = 'Preserved existing Deny all enforcement (2); use -OutgoingNtlmMode Audit to explicitly replace it.'
|
||||
} elseif ($Scope -eq 'Outgoing' -and $Mode -eq 'PreserveOrAudit' -and $null -ne $state.Value -and $state.Value -notin @(0, 1, 2)) {
|
||||
$skipReason = "Preserved unknown outgoing NTLM value ($($state.Value)); select an explicit mode after policy review."
|
||||
} elseif ($Scope -eq 'Outgoing' -and $Mode -eq 'PreserveOrAudit' -and $null -ne $state.Type -and ($state.Type -ne 'DWord' -or $state.Value -notin @(0, 1, 2))) {
|
||||
$skipReason = "Preserved unknown outgoing NTLM value/type ($($state.Value)/$($state.Type)); select an explicit mode after policy review."
|
||||
}
|
||||
if (-not $skipReason) {
|
||||
if ($Scope -eq 'Outgoing' -and $Mode -eq 'Deny') {
|
||||
|
||||
Reference in new issue
Block a user