diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index a01b6f3a..33f60c36 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,7 +2,9 @@ ## 2.2.0 [2026/xx/xx] - Dev Release -- 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) +- `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384) + +- LDAP 1644 診断の役割限定、明示的な Diagnostic/MdiCleanup モード、しきい値、既存設定の保持範囲を文書化しました。 (#383) - ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382) diff --git a/CHANGELOG.md b/CHANGELOG.md index 200652b6..00c5ccc0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,7 +2,9 @@ ## 2.2.0 [2026/xx/xx] - Dev Release -- Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) +- Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384) + +- Document role-scoped, opt-in LDAP 1644 diagnostics with explicit Diagnostic and MdiCleanup modes and preservation of unrelated NTDS values. (Related #383) - Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382) diff --git a/docs/audit-integrity.md b/docs/audit-integrity.md index 09544e45..4b984167 100644 --- a/docs/audit-integrity.md +++ b/docs/audit-integrity.md @@ -68,3 +68,6 @@ The focused suite mocks every mutation and covers exact source sets/omissions, r Remaining acceptance evidence requires disposable, snapshotted client/member/DC labs, including member/DC AD CS and relevant IIS/AD FS/Exchange dependencies: review affected principals, apply the chosen source profile, verify new-token behavior, readback after ordinary GPO refresh, benign audit generation and authorized collection, and selective recovery with unrelated rights preserved. Do not create an audit-exhaustion test. DC/member mutation, service-token and event/ingestion evidence is still pending; read-only CI cannot close those requirements. This is audit-integrity hardening, not a new event family. Reports set `SigmaEvtxCredit=0`; no rule-eligibility or Sigma coverage increase is inferred. Sysmon is outside this native Windows workflow. +# Issue 384 coverage + +Audit-integrity profiles cover the two logging rights (`SeAuditPrivilege` and `SeSecurityPrivilege`) and the `CrashOnAuditFail` DWORD independently. Omitted profile fields preserve the observed state; the disabled crash-on-audit setting is explicit for reviewed CIS profiles. Existing service-account exceptions and unknown values remain operator review items. diff --git a/docs/ldap-diagnostics.md b/docs/ldap-diagnostics.md index 3919aab7..9ec17c87 100644 --- a/docs/ldap-diagnostics.md +++ b/docs/ldap-diagnostics.md @@ -35,3 +35,6 @@ Writes require a fresh complete snapshot and a saved `before.jsonl` recovery rec For recovery, compare fresh values with both the journal's original state and this run's desired values. Restore original values/types only where this run's changes still remain; remove only a value that was originally absent. Preserve any newer operator changes and keep the recovery journal. MDI cleanup is not a general rollback command. Tests cover default preservation, explicit setup/cleanup, positive bounds, type/read/write errors, journal ordering, stale plans, races, partial failures, repeated application and final drift. Windows CI queries native role applicability without configuring a DC. Before closing #383, use an isolated DC snapshot to verify a benign query against the selected thresholds, retain matching 1644 XML and before/after policy, measure volume, and verify forwarding. Registry readback is not event-generation or Sigma detection evidence. Sysmon is out of scope. +# Issue 383 coverage + +LDAP 1644 diagnostics are opt-in and role-scoped. `Preserve` changes nothing, `Diagnostic` accepts explicit threshold values, and `MdiCleanup` removes only the four named legacy NTDS values after a fresh local-DC observation. WELA never silently overwrites existing diagnostics, and event volume, forwarding, and MDI compliance remain separate validation steps. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 262410b4..08191e30 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,7 +5,9 @@ ## 2.2.0 [2026/xx/xx] - Dev Release -- 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) +- `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384) + +- LDAP 1644 診断の役割限定、明示的な Diagnostic/MdiCleanup モード、しきい値、既存設定の保持範囲を文書化しました。 (#383) - ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 8e90b3b8..d31bfbd2 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,7 +5,9 @@ ## 2.2.0 [2026/xx/xx] - Dev Release -- Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) +- Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384) + +- Document role-scoped, opt-in LDAP 1644 diagnostics with explicit Diagnostic and MdiCleanup modes and preservation of unrelated NTDS values. (Related #383) - Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382)