Merge pull request #358 from Yamato-Security/refactor-fix-bugs

refactor: move baseline definitions to data and fix detection-logic bugs
This commit is contained in:
Zach Mathis (田中ザック) authored and GitHub committed 2026-09-02 07:10:38 +09:00
commit 89f681ac7c
9 files changed
+3377 -5111

No files matched your search

+6 -3
View File
@@ -10,7 +10,7 @@ jobs:
build:
strategy:
matrix:
os: [windows-2019, windows-2022, windows-2025]
os: [windows-2022, windows-2025]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
@@ -49,8 +49,11 @@ jobs:
- name: Commit changes
run: |
git add *.csv
if (git diff-index --quiet HEAD) {
# 生成先は config/ 配下なので、ルート直下の *.csv では拾えない
git add config/*.csv
# git diff-index の終了コードを見る($? を使わないと出力の真偽値判定になってしまう)
git diff-index --quiet HEAD
if ($LASTEXITCODE -eq 0) {
echo "No changes to commit"
} else {
git commit -m "Automated update"
+3 -3
View File
@@ -63,9 +63,9 @@ jobs:
if: matrix.info.os == 'macos-latest'
run: |
npm i -g md-to-pdf
md-to-pdf ./*.md --md-file-encoding utf-8
mv ./README.pdf ./README-${{ github.event.inputs.release_ver }}-English.pdf
mv ./README-Japanese.pdf ./README-${{ github.event.inputs.release_ver }}-Japanese.pdf
md-to-pdf ./OLD-README.md ./OLD-README-Japanese.md --md-file-encoding utf-8
mv ./OLD-README.pdf ./README-${{ github.event.inputs.release_ver }}-English.pdf
mv ./OLD-README-Japanese.pdf ./README-${{ github.event.inputs.release_ver }}-Japanese.pdf
- name: Upload Document Artifacts
if: matrix.info.os == 'macos-latest'
+5
View File
@@ -8,3 +8,8 @@ Cargo.lock
.DS_Store
# MkDocs documentation site build output
/website/site/
# WELA が実行時に生成する出力ファイル
/auditpol.txt
/mitre-ttp-navigator-current.json
/mitre-ttp-navigator-ideal.json
+27
View File
@@ -1,5 +1,32 @@
# CHANGELOG
## 2.2.0 [2026/xx/xx] - Dev Release
**改善:**
- ベースライン定義を`WELA.ps1`から`config/baselines.json`に外部化し、ベースラインの追加・変更をJSONの編集のみで行えるようにした。 (#358) (@fukusuket)
- `Microsoft-Windows-DFSN-Server/Admin`チャネルを`audit-settings`と`audit-filesize`の確認対象に追加した。 (#358) (@fukusuket)
**バグ修正:**
- ルールのフィルタ条件が全て適用されず最後の条件のみが適用されていたため、ルール数が正確ではなかった。 (#358) (@fukusuket)
- 依存するログが無効になっているルールも使用可能として報告されていた。 (#358) (@fukusuket)
- 複数のカテゴリに属するルールが重複してカウントされ、CSVファイルにも重複して出力されていた。 (#358) (@fukusuket)
- どのカテゴリにも一致しないルールがCSVファイルとカバレッジの母数から除外されていた。現在は`Uncategorized`として報告される。 (#358) (@fukusuket)
- 使用率のしきい値が文字列として比較されていたため、割合の表示色が正しくなかった。 (#358) (@fukusuket)
- 監査が有効であるにもかかわらず`Success and Failure`が赤色で表示されていた。 (#358) (@fukusuket)
- MITRE ATT&CK Navigatorのレイヤーに不正なテクニックIDが含まれ、またUTF-16で出力されるためATT&CK Navigatorで読み込めなかった。 (#358) (@fukusuket)
- WELAが配置されているディレクトリ以外から実行すると失敗していた。 (#358) (@fukusuket)
- `audit-filesize`で1つのログが存在しないだけでチェック全体が中断されていた。 (#358) (@fukusuket)
- PowerShellのログ設定を32bitのレジストリビューからしか読んでいなかったため、GPOで設定された端末が`Disabled`と報告されていた。 (#358) (@fukusuket)
- `auditpol`の出力のパースが失敗する場合があり、また管理者権限なしで`audit-settings`を実行すると誤った結果を報告していた。 (#358) (@fukusuket)
- `configure -Baseline ASD`が警告なくYamatoSecurityの設定を適用していた。 (#358) (@fukusuket)
- `update-rules`のダウンロードに失敗した場合、既存の設定ファイルが壊れる可能性があった。 (#358) (@fukusuket)
- `std`、`table`、`gui`の各出力形式でCSVの出力が一貫していなかった。 (#358) (@fukusuket)
- リリースとCSV作成のGitHub Actionsワークフローが失敗していた。 (#358) (@fukusuket)
**注意:** 上記の修正により、報告される使用率は2.1.0より低くなる(同一端末で23.38% -> 12.94%)。新しい値が正しい値であり、ログが無効なルールが使用可能としてカウントされなくなったことと、これまで除外されていたルールが母数に含まれるようになったことによるもの。
## 2.1.0 [2026/02/13] - Winter Release
**バグ修正:**
+27
View File
@@ -1,5 +1,32 @@
# CHANGELOG
## 2.2.0 [2026/xx/xx] - Dev Release
**Improvements:**
- Baseline definitions were moved out of `WELA.ps1` into a `config/baselines.json` config file, so adding or changing a baseline is now a JSON-only edit. (#358) (@fukusuket)
- The `Microsoft-Windows-DFSN-Server/Admin` channel is now checked by `audit-settings` and `audit-filesize`. (#358) (@fukusuket)
**Bug Fixes:**
- Rule filtering applied only the last criterion instead of all of them, so rule counts were inaccurate. (#358) (@fukusuket)
- Rules were reported as usable even when the logs they depend on were disabled. (#358) (@fukusuket)
- Rules that belong to multiple categories were counted and written to the CSV files multiple times. (#358) (@fukusuket)
- Rules that did not match any category were dropped from the CSV files and from the coverage total. They are now reported under `Uncategorized`. (#358) (@fukusuket)
- The utilization threshold was compared as a string, so the percentage was shown in the wrong color. (#358) (@fukusuket)
- `Success and Failure` was shown in red even though auditing was enabled. (#358) (@fukusuket)
- The MITRE ATT&CK Navigator layer contained invalid technique IDs and was written as UTF-16, which ATT&CK Navigator cannot read. (#358) (@fukusuket)
- Running WELA from a directory other than the one it is installed in failed. (#358) (@fukusuket)
- `audit-filesize` aborted the whole check when a single log was missing. (#358) (@fukusuket)
- PowerShell logging settings were only read from the 32-bit registry view, so a machine configured by GPO was reported as `Disabled`. (#358) (@fukusuket)
- Parsing of the `auditpol` output could fail, and running `audit-settings` without Administrator privileges produced a confidently wrong report. (#358) (@fukusuket)
- `configure -Baseline ASD` silently applied the YamatoSecurity settings. (#358) (@fukusuket)
- A failed download in `update-rules` could corrupt the existing config files. (#358) (@fukusuket)
- CSV output was inconsistent between the `std`, `table` and `gui` output types. (#358) (@fukusuket)
- The release and CSV creation GitHub Actions workflows were failing. (#358) (@fukusuket)
**Note:** because of the fixes above, the reported utilization is now lower than in 2.1.0 (23.38% -> 12.94% on the same machine). The new number is the correct one: rules whose logs are disabled are no longer counted as usable, and rules that were previously dropped are now included in the total.
## 2.1.0 [2026/02/13] - Winter Release
**Bug Fixes:**
+420 -5105
View File
File diff suppressed because it is too large. Load diff
File diff suppressed because it is too large. Load diff
+26
View File
@@ -3,6 +3,32 @@
!!! info "情報"
このページはプロジェクトの [`CHANGELOG.md`](https://github.com/Yamato-Security/WELA/blob/main/CHANGELOG-Japanese.md) を反映したものです。ダウンロードは [リリースページ](https://github.com/Yamato-Security/WELA/releases) をご覧ください。
## 2.2.0 [2026/08/31] - Dev Release
**改善:**
- ベースライン定義を`WELA.ps1`から`config/baselines.json`に外部化し、ベースラインの追加・変更をJSONの編集のみで行えるようにした。 (#358) (@fukusuket)
**バグ修正:**
- ルールのフィルタ条件が全て適用されず最後の条件のみが適用されていたため、ルール数が正確ではなかった。 (#358) (@fukusuket)
- 依存するログが無効になっているルールも使用可能として報告されていた。 (#358) (@fukusuket)
- 複数のカテゴリに属するルールが重複してカウントされ、CSVファイルにも重複して出力されていた。 (#358) (@fukusuket)
- どのカテゴリにも一致しないルールがCSVファイルとカバレッジの母数から除外されていた。現在は`Uncategorized`として報告される。 (#358) (@fukusuket)
- 使用率のしきい値が文字列として比較されていたため、割合の表示色が正しくなかった。 (#358) (@fukusuket)
- 監査が有効であるにもかかわらず`Success and Failure`が赤色で表示されていた。 (#358) (@fukusuket)
- MITRE ATT&CK Navigatorのレイヤーに不正なテクニックIDが含まれ、またUTF-16で出力されるためATT&CK Navigatorで読み込めなかった。 (#358) (@fukusuket)
- WELAが配置されているディレクトリ以外から実行すると失敗していた。 (#358) (@fukusuket)
- `audit-filesize`で1つのログが存在しないだけでチェック全体が中断されていた。 (#358) (@fukusuket)
- PowerShellのログ設定を32bitのレジストリビューからしか読んでいなかったため、GPOで設定された端末が`Disabled`と報告されていた。 (#358) (@fukusuket)
- `auditpol`の出力のパースが失敗する場合があり、また管理者権限なしで`audit-settings`を実行すると誤った結果を報告していた。 (#358) (@fukusuket)
- `configure -Baseline ASD`が警告なくYamatoSecurityの設定を適用していた。 (#358) (@fukusuket)
- `update-rules`のダウンロードに失敗した場合、既存の設定ファイルが壊れる可能性があった。 (#358) (@fukusuket)
- `std`、`table`、`gui`の各出力形式でCSVの出力が一貫していなかった。 (#358) (@fukusuket)
- リリースとCSV作成のGitHub Actionsワークフローが失敗していた。 (#358) (@fukusuket)
**注意:** 上記の修正により、報告される使用率は2.1.0より低くなる(同一端末で23.38% -> 12.94%)。新しい値が正しい値であり、ログが無効なルールが使用可能としてカウントされなくなったことと、これまで除外されていたルールが母数に含まれるようになったことによるもの。
## 2.1.0 [2026/02/13] - Winter Release
**バグ修正:**
+26
View File
@@ -3,6 +3,32 @@
!!! info
This page mirrors the project [`CHANGELOG.md`](https://github.com/Yamato-Security/WELA/blob/main/CHANGELOG.md). See the [Releases page](https://github.com/Yamato-Security/WELA/releases) for downloads.
## 2.2.0 [2026/08/31] - Dev Release
**Improvements:**
- Baseline definitions were moved out of `WELA.ps1` into a `config/baselines.json` config file, so adding or changing a baseline is now a JSON-only edit. (#358) (@fukusuket)
**Bug Fixes:**
- Rule filtering applied only the last criterion instead of all of them, so rule counts were inaccurate. (#358) (@fukusuket)
- Rules were reported as usable even when the logs they depend on were disabled. (#358) (@fukusuket)
- Rules that belong to multiple categories were counted and written to the CSV files multiple times. (#358) (@fukusuket)
- Rules that did not match any category were dropped from the CSV files and from the coverage total. They are now reported under `Uncategorized`. (#358) (@fukusuket)
- The utilization threshold was compared as a string, so the percentage was shown in the wrong color. (#358) (@fukusuket)
- `Success and Failure` was shown in red even though auditing was enabled. (#358) (@fukusuket)
- The MITRE ATT&CK Navigator layer contained invalid technique IDs and was written as UTF-16, which ATT&CK Navigator cannot read. (#358) (@fukusuket)
- Running WELA from a directory other than the one it is installed in failed. (#358) (@fukusuket)
- `audit-filesize` aborted the whole check when a single log was missing. (#358) (@fukusuket)
- PowerShell logging settings were only read from the 32-bit registry view, so a machine configured by GPO was reported as `Disabled`. (#358) (@fukusuket)
- Parsing of the `auditpol` output could fail, and running `audit-settings` without Administrator privileges produced a confidently wrong report. (#358) (@fukusuket)
- `configure -Baseline ASD` silently applied the YamatoSecurity settings. (#358) (@fukusuket)
- A failed download in `update-rules` could corrupt the existing config files. (#358) (@fukusuket)
- CSV output was inconsistent between the `std`, `table` and `gui` output types. (#358) (@fukusuket)
- The release and CSV creation GitHub Actions workflows were failing. (#358) (@fukusuket)
**Note:** because of the fixes above, the reported utilization is now lower than in 2.1.0 (23.38% -> 12.94% on the same machine). The new number is the correct one: rules whose logs are disabled are no longer counted as usable, and rules that were previously dropped are now included in the total.
## 2.1.0 [2026/02/13] - Winter Release
**Bug Fixes:**