Guard targeted SACL planning paths and ignored skip options

This commit is contained in:
Shirofune-Security committed 2026-09-19 05:35:23 +09:00
1 parent 6489775d30
commit acde16f149
4 files changed
+117 -11

No files matched your search

+3 -1
View File
@@ -11,9 +11,11 @@
./WELA.ps1 configure -Profile wela-2.2.0 -SaclMode Skip -Auto -ResultsPath results.json
```
Explicit `-SaclMode` is accepted only with `-Profile` on plan/audit/audit-settings/configure; `configure-sacl -SaclMode Skip` is rejected before dispatch, because that separate command does not consume this plan.
No SACL is written by a profile command. Audit policy configuration retains its existing scope. `configure-sacl` remains a **separate, broader opt-in workflow**: it sets its own File System, Registry and Handle Manipulation policies and applies all existing WELA targets, including loading offline user hives. It does not consume this selected profile's plan. Review its scope before running it. This companion plan does not enable privileges, mount hives, install software or configure global object auditing.
On a matching local Windows role/build, the plan inventories ProfileList, Default and loaded HKU hives. Unloaded hives remain unresolved; it never silently substitutes the operator's user environment for another user's paths. Loaded-user Startup/AppData locations come from that user's unexpanded `User Shell Folders` values. Redirected, remote, missing, inaccessible and unresolved paths are explicit; UNC destinations are not contacted. Reparse points are flagged. Enumeration failures and unmatched loaded hives are retained as inventory diagnostics. An offline plan (or plan for a different role/build) inspects no host targets. `Skip` performs no user/target inspection.
On a matching local Windows role/build, the plan inventories ProfileList, Default and loaded HKU hives. Unloaded hives remain unresolved; it never silently substitutes the operator's user environment for another user's paths. Loaded-user Startup/AppData locations come from that user's unexpanded `User Shell Folders` values. Redirected, remote, missing, inaccessible and unresolved paths are explicit; UNC destinations are not contacted. Mapped network drives and reparse points in any path component are flagged before descendant or SACL inspection. These are point-in-time observations, not an atomic guard against concurrent path replacement. Enumeration failures, per-profile path errors and unmatched loaded hives make the inventory incomplete and remain visible as diagnostics. ProfileList paths expand only known machine variables; operator user variables are never substituted. An offline plan (or plan for a different role/build) inspects no host targets. `Skip` performs no user/target inspection.
`Exists` and `SaclReadState=Readable` mean only that the object and its SACL could be read. They do **not** prove the necessary audit ACE is present, inheritance reaches every descendant, mandatory/temporary profiles are covered, or a Security event was generated. All rows remain `GenerationReadiness=Conditional`, with zero usable-rule credit. A failure to read SACLs is reported separately from a missing path; elevated privileges may be necessary for those reads.