mirror of
https://github.com/Yamato-Security/WELA.git
synced 2025-12-17 22:53:22 +01:00
update
This commit is contained in:
64
.github/workflows/check-audit.yml
vendored
64
.github/workflows/check-audit.yml
vendored
@@ -14,38 +14,38 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: auditpol /list /subcategory:* /r
|
||||
run: auditpol /list /subcategory:* /r
|
||||
|
||||
- name: auditpol /get /category:*
|
||||
run: auditpol /get /category:*
|
||||
|
||||
- name: Get-WinEvent -ListLog * | Select-Object LogName, MaximumSizeInBytes
|
||||
run: Get-WinEvent -ListLog * | Select-Object LogName, MaximumSizeInBytes
|
||||
|
||||
- name: Get-WinEvent -ListProvider *
|
||||
run: (Get-WinEvent -ListProvider Microsoft-Windows-Security-Auditing).Events | ForEach-Object { [PSCustomObject]@{EventID=$_.Id; Description=($_.Description -replace "`r`n", " ") -replace "\..*", ""} }
|
||||
|
||||
- name: Checkout self repository
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Load audit settings(json)
|
||||
run: |
|
||||
$startTime = Get-Date
|
||||
$audit_settings = Get-Content -Path ./config/security_rules.json -Raw | ConvertFrom-Json
|
||||
$audit_settings
|
||||
$endTime = Get-Date
|
||||
$duration = $endTime - $startTime
|
||||
Write-Output "Duration: $duration"
|
||||
|
||||
- name: Load audit settings(csv)
|
||||
run: |
|
||||
$startTime = Get-Date
|
||||
$audit_settings = Import-Csv ./config/eid_subcategory_mapping.csv
|
||||
$audit_settings
|
||||
$endTime = Get-Date
|
||||
$duration = $endTime - $startTime
|
||||
Write-Output "Duration: $duration"
|
||||
# - name: auditpol /list /subcategory:* /r
|
||||
# run: auditpol /list /subcategory:* /r
|
||||
#
|
||||
# - name: auditpol /get /category:*
|
||||
# run: auditpol /get /category:*
|
||||
#
|
||||
# - name: Get-WinEvent -ListLog * | Select-Object LogName, MaximumSizeInBytes
|
||||
# run: Get-WinEvent -ListLog * | Select-Object LogName, MaximumSizeInBytes
|
||||
#
|
||||
# - name: Get-WinEvent -ListProvider *
|
||||
# run: (Get-WinEvent -ListProvider Microsoft-Windows-Security-Auditing).Events | ForEach-Object { [PSCustomObject]@{EventID=$_.Id; Description=($_.Description -replace "`r`n", " ") -replace "\..*", ""} }
|
||||
#
|
||||
# - name: Checkout self repository
|
||||
# uses: actions/checkout@v4
|
||||
#
|
||||
# - name: Load audit settings(json)
|
||||
# run: |
|
||||
# $startTime = Get-Date
|
||||
# $audit_settings = Get-Content -Path ./config/security_rules.json -Raw | ConvertFrom-Json
|
||||
# $audit_settings
|
||||
# $endTime = Get-Date
|
||||
# $duration = $endTime - $startTime
|
||||
# Write-Output "Duration: $duration"
|
||||
#
|
||||
# - name: Load audit settings(csv)
|
||||
# run: |
|
||||
# $startTime = Get-Date
|
||||
# $audit_settings = Import-Csv ./config/eid_subcategory_mapping.csv
|
||||
# $audit_settings
|
||||
# $endTime = Get-Date
|
||||
# $duration = $endTime - $startTime
|
||||
# Write-Output "Duration: $duration"
|
||||
|
||||
- name: Run WELA.ps1
|
||||
run: |
|
||||
|
||||
Reference in New Issue
Block a user