mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
Retain actual process identity for scoped logging and native attribution
This commit is contained in:
1 parent
e419b073fe
commit
adaf3f9681
4 files changed
+7
-5
No files matched your search
@@ -22,7 +22,7 @@
|
||||
-Auto -BackupPath C:\WELA-Recovery\new-run -ResultsPath new-result.json
|
||||
```
|
||||
|
||||
Use a native 64-bit Windows PowerShell 5.1 or PowerShell 7 host. The actual Windows role, build, patch and installed Windows PowerShell engine are read; caller role/build overrides are refused. Reviewed families are Windows 11 builds 22000, 22621, 22631, 26100 and 26200, and Server 2022/2025 builds 20348/26100. Native client, joined-member, DC and AD CS acceptance remains separate from hosted standalone-server tests. `Winmgmt` and `EventLog` must already run; the command starts no service. Configure requires elevation and a fresh recovery directory. Plan and Configure require explicit controls; there is no implicit enable-everything selection. Audit without selection inventories existing policy only.
|
||||
Use a native 64-bit Windows PowerShell 5.1 or PowerShell 7 host. The actual process SID, Windows role, build, patch and installed Windows PowerShell engine are read; impersonated callers are refused and caller role/build overrides are refused. Reviewed families are Windows 11 builds 22000, 22621, 22631, 26100 and 26200, and Server 2022/2025 builds 20348/26100. Native client, joined-member, DC and AD CS acceptance remains separate from hosted standalone-server tests. `Winmgmt` and `EventLog` must already run; the command starts no service. Configure requires elevation and a fresh recovery directory. Plan and Configure require explicit controls; there is no implicit enable-everything selection. Audit without selection inventories existing policy only.
|
||||
|
||||
The array examples are PowerShell syntax. When launching `powershell.exe -File` from another shell, use a reviewed PowerShell wrapper to bind multiple array elements correctly. Literal module names can contain ASCII letters, digits, dots, underscores and hyphens, up to 128 characters each. Up to 32 unique names can be selected. Paths and wildcard patterns are refused; the exact `*` value is accepted **only when explicitly supplied** to request all modules. Installation and execution of arbitrary selected modules are not performed or asserted.
|
||||
|
||||
|
||||
Reference in new issue
Block a user