Merge pull request #480 from Shirofune-Security/feat/10-scoring-closure

docs: close audit scoring gap (#10)
This commit is contained in:
田中ザック Isaac Mathis authored and GitHub committed 2026-09-23 07:35:11 +09:00
commit b337eb05de
5 files changed
+11

No files matched your search

+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10)
- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185)
- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387)
+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10)
- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185)
- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387)
+3
View File
@@ -65,3 +65,6 @@ JSON retains the definition/version/hash, profile plan and source provenance, ac
Version 1.0.0 is defined in `config/audit_scoring.json` as `native-audit-score-v1`. Changing weights requires a reviewed definition-version change, rather than silently moving the denominator. Exact profile and corpus fingerprints let a reviewer identify what was assessed. The profile hash must match before and after planning and the plan's returned hash; observed source changes abort reporting. Hashes bind recorded content, not the trustworthiness of a malicious evidence author. Letter grades and a combined security score are deliberately not defined by this first implementation of issue #10.
Tests cover exact/minimum mask truth tables, optional/role omissions, unknown and empty denominators, severity weights, exclusions/unique IDs, evidence-context preservation, source changes, output collisions, HTML encoding and public command isolation. Windows Server 2022/2025 PowerShell 5.1/7 tests read real policy and verify that native masks/precedence remain unchanged. Synthetic Ready rows test arithmetic only. No Windows 11/DC/AD CS deployment or backend query evidence is claimed by those tests.
### Issue 10 coverage
Audit scoring uses weighted rule metadata and reports numerator, denominator, exclusions, and conditional evidence. A score summarizes reviewed eligibility states; it does not prove event generation, forwarding, or detection.
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10)
- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185)
- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387)
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10)
- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185)
- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387)