diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index 673c716b..f5447ecc 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) + - ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) diff --git a/CHANGELOG.md b/CHANGELOG.md index 2cdaa683..ca8686ae 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) + - Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) diff --git a/docs/custom-audit-profiles.md b/docs/custom-audit-profiles.md index ef5cfb4d..b03e8cf8 100644 --- a/docs/custom-audit-profiles.md +++ b/docs/custom-audit-profiles.md @@ -121,3 +121,6 @@ These are hosted standalone servers classified by the shared profile engine as MemberServer; no domain join or GPO refresh is simulated. Configuration and benign event/backend acceptance on Windows 11, domain-joined servers, DC and AD CS labs remain separate; no clean-install or detection-coverage claim is made. +### Issue 185 coverage + +Custom audit settings are loaded from a versioned JSON profile instead of requiring script edits. Exact, minimum, preserve, optional, and not-configured semantics are validated before configuration, with profile hashes guarding against drift. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 76eeab7c..0bd234a5 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) + - ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 5888265d..91d9d750 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) + - Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386)