feat: add DFSN-Server Admin channel to baselines and update changelog

This commit is contained in:
fukusuket committed 2026-09-01 23:32:53 +09:00
1 parent a98af726d7
commit a9ceec469a
4 files changed
+68

No files matched your search

+1
View File
@@ -5,6 +5,7 @@
**改善:**
- ベースライン定義を`WELA.ps1`から`config/baselines.json`に外部化し、ベースラインの追加・変更をJSONの編集のみで行えるようにした。 (#358) (@fukusuket)
- `Microsoft-Windows-DFSN-Server/Admin`チャネルを`audit-settings`と`audit-filesize`の確認対象に追加した。 (#358) (@fukusuket)
**バグ修正:**
+1
View File
@@ -5,6 +5,7 @@
**Improvements:**
- Baseline definitions were moved out of `WELA.ps1` into a `config/baselines.json` config file, so adding or changing a baseline is now a JSON-only edit. (#358) (@fukusuket)
- The `Microsoft-Windows-DFSN-Server/Admin` channel is now checked by `audit-settings` and `audit-filesize`. (#358) (@fukusuket)
**Bug Fixes:**
+21
View File
@@ -309,6 +309,26 @@ function BuildAuditResult {
$enabled = $enabledguid -contains $item.select.guid
$current = $auditpol[$item.select.guid]
}
"channel" {
# レジストリの Enabled 値はマニフェストの既定値のままだと存在しないことがあり、
# 「値が無い」を無効と解釈すると既定で有効なチャネルを誤判定する。
# また役割未導入でチャネル自体が無い場合と無効化されている場合も区別できないため、
# 実際のチャネル状態を Get-WinEvent から取得する。
$logInfo = $null
try {
# Windows 以外や役割未導入の環境では取得できないので、その場合は判定不能とする
$logInfo = Get-WinEvent -ListLog $item.currentSetting.channel -ErrorAction Stop
} catch {
$logInfo = $null
}
if ($null -eq $logInfo) {
$enabled = $false
$current = "Unknown"
} else {
$enabled = [bool]$logInfo.IsEnabled
$current = if ($enabled) { "Enabled" } else { "Disabled" }
}
}
"registry" {
# 64bit/32bit でレジストリビューが分かれる設定があるため、いずれかで有効なら有効とみなす
$enabled = $false
@@ -656,6 +676,7 @@ function AuditFileSize {
"Microsoft-Windows-Bits-Client/Operational" = @("1 MB", "128 MB+")
"Microsoft-Windows-CodeIntegrity/Operational" = @("1 MB", "128 MB+")
"Microsoft-Windows-Crypto-DPAPI/Debug" = @("1 MB", "128 MB+")
"Microsoft-Windows-DFSN-Server/Admin" = @("1 MB", "128 MB+")
"Microsoft-Windows-DriverFrameworks-UserMode/Operational" = @("1 MB", "128 MB+")
"Microsoft-Windows-NTLM/Operational" = @("1 MB", "128 MB+")
"Microsoft-Windows-PowerShell/Operational" = @("15 MB", "256 MB+")
+45
View File
@@ -93,6 +93,23 @@
"value": 1
}
},
{
"id": "dfsn-server-admin",
"category": "DFSN-Server Admin",
"subCategory": "",
"select": {
"type": "filter",
"eventIds": [],
"channels": [
"Microsoft-Windows-DFSN-Server/Admin"
],
"guid": ""
},
"currentSetting": {
"type": "static",
"value": "Enabled"
}
},
{
"id": "diagnosis-scripted-operational",
"category": "Diagnosis-Scripted Operational",
@@ -968,6 +985,13 @@
"volume": "",
"note": ""
},
"dfsn-server-admin": {
"ideal": true,
"defaultSetting": "Enabled",
"recommendedSetting": "Enabled",
"volume": "",
"note": "Only exists on servers with the DFS Namespaces role installed."
},
"diagnosis-scripted-operational": {
"ideal": true,
"defaultSetting": "Enabled",
@@ -1432,6 +1456,13 @@
"volume": "",
"note": ""
},
"dfsn-server-admin": {
"ideal": false,
"defaultSetting": "Enabled",
"recommendedSetting": "",
"volume": "",
"note": "Only exists on servers with the DFS Namespaces role installed."
},
"diagnosis-scripted-operational": {
"ideal": true,
"defaultSetting": "Enabled",
@@ -1896,6 +1927,13 @@
"volume": "",
"note": ""
},
"dfsn-server-admin": {
"ideal": false,
"defaultSetting": "Enabled",
"recommendedSetting": "",
"volume": "",
"note": "Only exists on servers with the DFS Namespaces role installed."
},
"diagnosis-scripted-operational": {
"ideal": true,
"defaultSetting": "Enabled",
@@ -2360,6 +2398,13 @@
"volume": "",
"note": ""
},
"dfsn-server-admin": {
"ideal": false,
"defaultSetting": "Enabled",
"recommendedSetting": "",
"volume": "",
"note": "Only exists on servers with the DFS Namespaces role installed."
},
"diagnosis-scripted-operational": {
"ideal": true,
"defaultSetting": "Enabled",