mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 23:35:28 +02:00
Separate SMB policy verification from runtime activation
This commit is contained in:
1 parent
374b931676
commit
be3a354f18
9 files changed
+89
-24
No files matched your search
@@ -4,7 +4,7 @@
|
||||
|
||||
**改善:**
|
||||
|
||||
- 6つのネイティブSMB監査ポリシーを監査・計画・設定する任意実行の`smb-auditing`を追加しました。OSビルドとローカルADMXの正確な定義を確認してから書き込み、ポリシーのDWORD値と取得可能な実行時設定を分けて表示します。Dry-run、復旧用記録、最終検証に対応し、署名・暗号化要件やゲストアクセスは変更しません。実イベント生成と収集の検証は別途必要です。 (#397) (@Shirofune-Security)
|
||||
- 6つのネイティブSMB監査ポリシーを監査・計画・設定する任意実行の`smb-auditing`を追加しました。OSビルドとローカルADMXの正確な定義を確認してから書き込み、ポリシーのDWORD値と取得可能な実行時設定を分けて表示します。Dry-run、復旧用記録、ポリシーレジストリの検証に対応します。実行時設定は有効・検証待ち・不明を区別し、Falseが観測されてもレジストリへの書き込み成功を失敗とは扱いません。署名・暗号化要件やゲストアクセスは変更しません。実イベント生成と収集の検証は別途必要です。 (#397) (@Shirofune-Security)
|
||||
- `audit-settings`、`plan`、`configure`で共有するバージョン付きの詳細監査ポリシープロファイルを追加した。59のサブカテゴリと14のプロファイルで、WELA、文書に基づくWindows既定値、Microsoft、確認済みのCIS v4.0.0、ASDのWindows標準機能向け監査ガイドに対応する。ホストの役割とビルドの検証、オフラインでの設定計画、出典と前提条件を含むJSON出力をサポートする。完全一致、最低限、任意、変更なし、未構成、適用対象外を区別する。Windows既定値は参照専用で、プロファイルの対象はSecurityログの詳細監査ポリシーに限定される。 (#390) (@Shirofune-Security)
|
||||
- WELAのプロファイルにWindows標準の監査サブカテゴリを6つ追加した。Group MembershipとAuthorization Policy Changeは成功、Application Group Management、MPSSVC Rule-Level Policy Change、IPsec Driver、Kernel Objectは成功と失敗を監査する。各ガイドに対応するプロファイルでは、それぞれの監査設定と前提条件を維持する。Kernel Objectのイベント生成には対象オブジェクトに適切なSACLが必要であり、この変更ではそのSACLを作成しない。 (#391) (@Shirofune-Security)
|
||||
- `configure`と`configure -Profile`に`-DryRun`と`-ResultsPath`を追加し、Windows設定を変更せずに変更内容を確認し、設定項目ごとの結果をJSONで出力できるようにした。`-DryRun`に対応していないコマンドは、実行前にエラーで停止する。 (#392) (@Shirofune-Security)
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@
|
||||
|
||||
**Improvements:**
|
||||
|
||||
- Added opt-in `smb-auditing` audit, plan and configure actions for six native SMB audit policies. Host builds and exact local ADMX mappings gate writes; policy DWORDs and available runtime values are reported separately, with dry-run, recovery journaling and final verification. Signing/encryption requirements and guest access are not changed; runtime event/ingestion validation remains required. (#397) (@Shirofune-Security)
|
||||
- Added opt-in `smb-auditing` audit, plan and configure actions for six native SMB audit policies. Host builds and exact local ADMX mappings gate writes; policy DWORDs and available runtime values are reported separately, with dry-run, recovery journaling and policy-registry verification. Runtime activation is reported separately as active, pending verification or unknown; an observed False does not turn a verified registry write into a failure. Signing/encryption requirements and guest access are not changed; runtime event/ingestion validation remains required. (#397) (@Shirofune-Security)
|
||||
- Added versioned advanced audit-policy profiles shared by `audit-settings`, `plan` and `configure`: 59 subcategories and 14 profiles covering WELA, documented Windows defaults, Microsoft, reviewed CIS v4.0.0 and ASD native guidance. Profiles support role/build validation, offline planning and JSON exports with sources and prerequisites. Exact, minimum, optional, unchanged, Not Configured and not-applicable settings remain distinct. Windows defaults are reference-only; profile scope is advanced Security audit policy. (#390) (@Shirofune-Security)
|
||||
- Added six native Windows audit subcategories to WELA's profile: Group Membership and Authorization Policy Change (Success), plus Application Group Management, MPSSVC Rule-Level Policy Change, IPsec Driver and Kernel Object (Success and Failure). Source-specific profiles retain their own audit settings and prerequisites; Kernel Object events require matching object SACLs, which this change does not create. (#391) (@Shirofune-Security)
|
||||
- Added `-DryRun` and `-ResultsPath` to `configure` and `configure -Profile` to preview changes without modifying Windows settings and export per-control results as JSON. Commands that do not support `-DryRun` reject it before running. (#392) (@Shirofune-Security)
|
||||
|
||||
+11
-7
@@ -11,7 +11,7 @@ Run in elevated **64-bit** Windows PowerShell 5.1 or PowerShell 7:
|
||||
.\WELA.ps1 smb-auditing -SmbAction Configure -Auto -BackupPath .\smb-before -ResultsPath smb-results.json
|
||||
```
|
||||
|
||||
`-Profile` and `-Baseline` are rejected for this command: their advanced Security audit-policy semantics do not include these SMB policies. Audit and Plan both read the current host and show desired DWORD values; the plan is evidence, not an offline authorization file. They write only the explicitly requested results JSON. Configure dry run performs no policy/key writes and creates no recovery directory. Unknown observations fail with exit code 1; known unsupported controls are skipped explicitly. A readable assessment with `ChangeRequired` has exit code 0 because the assessment completed.
|
||||
`-Profile` and `-Baseline` are rejected for this command: their advanced Security audit-policy semantics do not include these SMB policies. Audit and Plan both read the current host and show desired DWORD values; the plan is evidence, not an offline authorization file. They write only the explicitly requested results JSON. Configure dry run performs no policy/key writes and creates no recovery directory. Unknown read failures give exit code 1; known unsupported controls are skipped explicitly. Audit/Plan uses `PolicyConfigured` for the desired registry DWORD, with runtime state reported separately. A readable assessment with `ChangeRequired` has exit code 0 because the assessment completed. `Applied` and `AlreadyCompliant` rows verify the requested policy-registry DWORD. Exit code 0 means there are no failed/overridden controls; dry-run, declined and unsupported/skipped controls do not establish configuration. None of these results proves runtime auditing or event generation.
|
||||
|
||||
## Exact controls and capability gates
|
||||
|
||||
@@ -32,11 +32,13 @@ Microsoft's Policy CSP pages list **26100.3613** as the availability floor for t
|
||||
|
||||
Reports keep `Policy` (the actual policy-registry value/type) separate from `Runtime` (the corresponding property of `Get-SmbServerConfiguration` or `Get-SmbClientConfiguration`). WELA never substitutes the policy DWORD for a runtime observation:
|
||||
|
||||
- `Observed`: the getter exposes an actual Boolean. True supports effective configuration; False means the requested auditing is not yet observed. A write that leaves an exposed property False fails verification even when the DWORD was written successfully. Review policy application and repeat the audit; WELA does not restart a service or weaken security to make verification pass.
|
||||
- `NotExposed`: the getter or property is unavailable. With the exact local ADMX mapping, WELA can verify the registry policy only. The snapshot explicitly says **effective auditing not established**. A successful registry result is not proof of runtime activation or event generation.
|
||||
- `Observed`: the getter exposes an actual Boolean. `RuntimeState=Active` means that Boolean was True, not that representative events were generated. False is `NotActive` before the desired policy exists, or `PendingVerification` when the policy registry contains DWORD 1. A correctly written/read-back policy therefore succeeds even when the runtime Boolean remains False. Pending verification does **not** assert propagation delay, a future activation deadline, or that a policy refresh/restart will fix the discrepancy. Its cause and activation timing are unknown; investigate and repeat Audit independently. WELA performs no refresh/restart and never weakens security to make a Boolean change.
|
||||
- `NotExposed`: the getter or property is unavailable. `RuntimeState=Unknown` distinguishes this from an observed False. With the exact local ADMX mapping, WELA can verify the registry policy only. The snapshot explicitly says **effective auditing not established**. A successful registry result is not proof of runtime activation or event generation.
|
||||
- `Unknown`: a runtime read fails or returns an unexpected type. Configuration fails closed without treating the state as a default.
|
||||
|
||||
Configure uses the common recovery journal and result runner. It rechecks capabilities/current values before writing, verifies the DWORD and available runtime property afterward, and reads them again at completion. Changed previously compliant controls become `Overridden`. Read/write failures are reported per control and give a nonzero exit code while other controls continue. A prompt-time policy change is refused so recovery evidence does not silently describe a stale value.
|
||||
Configure uses the common recovery journal and result runner. It rechecks capabilities/current values before writing, verifies the DWORD afterward, and reads policy/runtime again at completion. Registry value/type drift becomes `Overridden`; actual read/write failures remain failures and give a nonzero exit code while other controls continue. A runtime Boolean that remains or becomes False is reported separately as pending verification, rather than a registry write failure. An existing DWORD 1 is not rewritten merely to try to make the runtime Boolean change. A later audit can observe `Active` without any additional writes. A prompt-time policy change is refused so recovery evidence does not silently describe a stale value.
|
||||
|
||||
Configure JSON includes an explicit `VerificationScope` and `RuntimeVerification` counts for Active, PendingVerification, NotActive, Unknown and NotApplicable, alongside each actual before/after observation. Failed controls count as Unknown in that summary so an older snapshot cannot be mistaken for a successful final runtime read. Console output scopes success to policy-registry verification and prints the runtime counts. None of these statuses proves event generation or central collection.
|
||||
|
||||
The registry policy is a current observation, not proof of GPO/MDM ownership or long-term persistence. Future policy refresh can replace it. A direct local policy write also is not an edit to the domain GPO or its authoritative registry.pol source.
|
||||
|
||||
@@ -57,12 +59,14 @@ if ($old.ValueExists) {
|
||||
}
|
||||
```
|
||||
|
||||
Review concurrent administrator changes and GPO/MDM ownership first; a failed write may have left the original state unchanged. Restore controls individually and rerun Audit. Keep newly created parent policy keys unless separately reviewed as empty and safe to remove; never delete the entire LanmanServer/Workstation policy key. Service runtime can lag a registry change, so recovery also requires a later runtime check. This command has not changed guest access, signing/encryption requirements, shares or service state.
|
||||
Review concurrent administrator changes and GPO/MDM ownership first; a failed write may have left the original state unchanged. Restore controls individually and rerun Audit. Keep newly created parent policy keys unless separately reviewed as empty and safe to remove; never delete the entire LanmanServer/Workstation policy key. Registry and runtime observations can differ, and this implementation has not established why or when they converge; recovery also requires a later runtime check. This command has not changed guest access, signing/encryption requirements, shares or service state.
|
||||
|
||||
## Evidence still needed before closing issue #377
|
||||
|
||||
Mocked tests exercise OS/build and per-policy ADMX gating, all six exact policy targets, DWORD types, supported/unsupported/unknown states, runtime read errors and unavailable properties, dry run, recovery ordering, idempotence, ineffective runtime state and final drift. Windows CI adds read-only registry/local-ADMX/native-runtime observations and dry-run checks under PowerShell 5.1 and 7. It does not generate SMB traffic or alter runner policy.
|
||||
Mocked tests exercise OS/build and per-policy ADMX gating, all six exact policy targets, DWORD types, supported/unsupported/unknown states, runtime read errors and unavailable properties, dry run, recovery ordering, idempotence, pending runtime verification despite successful DWORD writes, later runtime activation without rewriting, actual runtime read failures and final registry drift. Windows CI adds read-only registry/local-ADMX/native-runtime observations and dry-run checks under PowerShell 5.1 and 7. It does not generate SMB traffic or alter runner policy.
|
||||
|
||||
On isolated supported client/server snapshots, retain OS build/revision, PowerShell version, WELA commit, ADMX hashes and before/after reports. Confirm a policy refresh does not unexpectedly override the requested setting. Capture representative native SMB audit events under the existing security requirements and verify collector delivery. Microsoft's signing/encryption guide identifies SMBClient/Audit 31998/31999 and SMBServer/Audit 3021/3022; validate the event actually corresponds to the test condition. Inspect guest-audit behavior without enabling guest access or weakening signing/encryption. If the existing secure configuration prevents a guest-session event, record that limitation rather than changing the security posture merely to obtain a test event. Also verify manual recovery. These traffic and ingestion tests remain pending; keep the issue open until the required evidence exists.
|
||||
|
||||
Sources: [LanmanServer Policy CSP mappings](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-lanmanserver), [LanmanWorkstation Policy CSP mappings](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-lanmanworkstation), [SMB signing and encryption auditing](https://learn.microsoft.com/en-us/windows-server/storage/file-server/smb-signing-overview), [SMB feature availability](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview), [SMB server audit parameters](https://learn.microsoft.com/en-us/powershell/module/smbshare/set-smbserverconfiguration?view=windowsserver2025-ps), and [issue #377](https://github.com/Yamato-Security/WELA/issues/377).
|
||||
Microsoft documents the policy-to-registry mappings and the SMB configuration cmdlets, but the cited pages do not establish synchronous propagation of a direct policy-registry write into the getter or promise that refreshing Group Policy resolves any discrepancy. WELA makes neither assumption.
|
||||
|
||||
Sources: [LanmanServer Policy CSP mappings](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-lanmanserver), [LanmanWorkstation Policy CSP mappings](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-lanmanworkstation), [SMB signing and encryption auditing](https://learn.microsoft.com/en-us/windows-server/storage/file-server/smb-signing-overview), [SMB feature availability](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview), [SMB configuration getter](https://learn.microsoft.com/en-us/powershell/module/smbshare/get-smbclientconfiguration?view=windowsserver2025-ps), [SMB server audit parameters](https://learn.microsoft.com/en-us/powershell/module/smbshare/set-smbserverconfiguration?view=windowsserver2025-ps), and [issue #377](https://github.com/Yamato-Security/WELA/issues/377).
|
||||
@@ -95,7 +95,8 @@ function Invoke-WelaConfigurationControl {
|
||||
function Complete-WelaConfiguration {
|
||||
param($Context, [string]$ResultsPath, $Plan,
|
||||
[ValidateSet("native-windows-configuration", "advanced-audit-policy-only", "smb-audit-policies-only")]
|
||||
[string]$Scope = "native-windows-configuration")
|
||||
[string]$Scope = "native-windows-configuration",
|
||||
[string]$SuccessMessage = 'Configuration completed; all requested controls verified.')
|
||||
# A second read detects a value that was compliant earlier but changed during
|
||||
# this run. It does not establish whether GPO or another writer caused drift.
|
||||
foreach ($check in $Context.Checks) {
|
||||
@@ -133,7 +134,7 @@ function Complete-WelaConfiguration {
|
||||
if ($report.ExitCode) { Write-Host "Configuration incomplete: $failed failed or overridden control(s). Review results and recovery journal." -ForegroundColor Red }
|
||||
elseif ($Context.DryRun) { Write-Host 'Dry run completed. No Windows configuration was changed.' -ForegroundColor Cyan }
|
||||
elseif ($skipped) { Write-Host "Configuration completed with $skipped skipped control(s)." -ForegroundColor Yellow }
|
||||
else { Write-Host 'Configuration completed; all requested controls verified.' -ForegroundColor Green }
|
||||
else { Write-Host $SuccessMessage -ForegroundColor Green }
|
||||
return $report
|
||||
}
|
||||
|
||||
|
||||
+41
-8
@@ -77,7 +77,11 @@ function Get-WelaSmbAuditRuntime {
|
||||
}
|
||||
if ($property.Value -isnot [bool]) { throw 'Runtime audit property is not a Boolean.' }
|
||||
$result.Status = 'Observed'; $result.Value = $property.Value
|
||||
$result.Diagnostic = 'Observed runtime configuration, not proof of generated or collected events.'
|
||||
$result.Diagnostic = if ($property.Value) {
|
||||
'Runtime audit Boolean is True; generated or collected events have not been verified.'
|
||||
} else {
|
||||
'Runtime audit Boolean is False; enabled auditing is not currently observed. The cause and activation timing are unknown; a policy refresh or restart is not assumed to resolve this.'
|
||||
}
|
||||
} catch { $result.Status = 'Unknown'; $result.Diagnostic = $_.Exception.Message }
|
||||
return $result
|
||||
}
|
||||
@@ -90,14 +94,27 @@ function Get-WelaSmbAuditState {
|
||||
$policy = Get-WelaRegistryState -Path $Definition.Path -Name $Definition.Name
|
||||
$runtime = Get-WelaSmbAuditRuntime -Definition $Definition
|
||||
}
|
||||
[pscustomobject]@{ Capability = $capability; Policy = $policy; Runtime = $runtime; VerificationScope = $(if ($runtime -and $runtime.Status -eq 'Observed') { 'Policy registry and observed runtime' } else { 'Policy registry only; effective auditing not established' }) }
|
||||
$policyConfigured = $capability.Status -eq 'Supported' -and $policy.ValueExists -and $policy.Type -eq 'DWord' -and $policy.Value -eq 1
|
||||
$runtimeState = if ($capability.Status -eq 'NotApplicable') { 'NotApplicable' }
|
||||
elseif ($runtime -and $runtime.Status -eq 'Observed' -and $runtime.Value) { 'Active' }
|
||||
elseif ($runtime -and $runtime.Status -eq 'Observed' -and $policyConfigured) { 'PendingVerification' }
|
||||
elseif ($runtime -and $runtime.Status -eq 'Observed') { 'NotActive' }
|
||||
else { 'Unknown' }
|
||||
[pscustomobject]@{
|
||||
Capability = $capability; Policy = $policy; Runtime = $runtime
|
||||
PolicyRegistryConfigured = [bool]$policyConfigured; RuntimeState = $runtimeState
|
||||
VerificationScope = $(if ($runtimeState -eq 'Active') { 'Policy registry and runtime audit flag observed separately; event generation not established' }
|
||||
elseif ($runtimeState -eq 'PendingVerification') { 'Policy registry configured; runtime verification pending (observed False)' }
|
||||
else { 'Policy registry only; effective auditing not established' })
|
||||
}
|
||||
}
|
||||
|
||||
function Test-WelaSmbAuditCompliance {
|
||||
param($Snapshot)
|
||||
# The mutation requests a policy DWORD, not synchronous runtime activation.
|
||||
# Runtime evidence stays separate; read errors still fail in the read callback.
|
||||
return $Snapshot.Capability.Status -eq 'Supported' -and $Snapshot.Policy.ValueExists -and
|
||||
$Snapshot.Policy.Type -eq 'DWord' -and $Snapshot.Policy.Value -eq 1 -and
|
||||
($Snapshot.Runtime.Status -eq 'NotExposed' -or ($Snapshot.Runtime.Status -eq 'Observed' -and $Snapshot.Runtime.Value))
|
||||
$Snapshot.Policy.Type -eq 'DWord' -and $Snapshot.Policy.Value -eq 1
|
||||
}
|
||||
|
||||
function Get-WelaSmbAuditPlan {
|
||||
@@ -107,7 +124,7 @@ function Get-WelaSmbAuditPlan {
|
||||
$state = Get-WelaSmbAuditState -Definition $definition
|
||||
$status = if ($state.Capability.Status -ne 'Supported') { $state.Capability.Status }
|
||||
elseif ($state.Runtime.Status -eq 'Unknown') { 'Unknown' }
|
||||
elseif (Test-WelaSmbAuditCompliance $state) { 'Compliant' } else { 'ChangeRequired' }
|
||||
elseif (Test-WelaSmbAuditCompliance $state) { 'PolicyConfigured' } else { 'ChangeRequired' }
|
||||
$diagnostic = if ($state.Capability.Status -ne 'Supported') { $state.Capability.Diagnostic } else { $state.Runtime.Diagnostic }
|
||||
[pscustomobject]@{ Definition = $definition; Status = $status; Before = $state; Diagnostic = $diagnostic }
|
||||
} catch { [pscustomobject]@{ Definition = $definition; Status = 'Unknown'; Before = $state; Diagnostic = $_.Exception.Message } }
|
||||
@@ -142,7 +159,7 @@ function Set-WelaSmbAuditControls {
|
||||
}
|
||||
New-WelaRegistryKey -Path $state.Definition.Path
|
||||
Set-ItemProperty -LiteralPath $state.Definition.Path -Name $state.Definition.Name -Type DWord -Value 1 -ErrorAction Stop
|
||||
'Audit policy DWORD written. Runtime may require policy refresh; event generation/collection and policy persistence remain unverified.'
|
||||
'Audit policy DWORD written. Runtime activation is observed separately; its cause/timing, event generation/collection and policy persistence remain unverified.'
|
||||
}
|
||||
Invoke-WelaConfigurationControl -Context $Context -Id $id -Kind SmbAudit -Target @{ Path = $definition.Path; Name = $definition.Name } `
|
||||
-Desired @{ Value = 1; Type = 'DWord' } -Read $read -Compliant $test -Apply $apply -CallbackState $callback `
|
||||
@@ -158,8 +175,24 @@ function Invoke-WelaSmbAuditCommand {
|
||||
if ($Action -eq 'Configure') {
|
||||
$context = New-WelaConfigurationContext -Auto:$Auto -DryRun:$DryRun -BackupPath $BackupPath
|
||||
Set-WelaSmbAuditControls -Context $context -Plan $plan
|
||||
Write-Host 'SMB verification covers the policy registry and available runtime properties only. Event generation, collection and persistence after policy refresh are not established.' -ForegroundColor Yellow
|
||||
return Complete-WelaConfiguration -Context $context -ResultsPath $ResultsPath -Scope 'smb-audit-policies-only'
|
||||
$report = Complete-WelaConfiguration -Context $context -Scope 'smb-audit-policies-only' `
|
||||
-SuccessMessage 'SMB policy registry values verified. Runtime activation and event generation are reported separately.'
|
||||
$runtimeSummary = [ordered]@{ Active = 0; PendingVerification = 0; NotActive = 0; Unknown = 0; NotApplicable = 0 }
|
||||
foreach ($row in $report.Results) {
|
||||
# A failed final read can leave an earlier snapshot in After. Do not
|
||||
# promote that stale observation to a successful runtime summary.
|
||||
$snapshot = if ($row.Status -eq 'Failed') { $null } elseif ($row.After) { $row.After } else { $row.Before }
|
||||
$runtimeState = if ($snapshot -and $snapshot.RuntimeState) { $snapshot.RuntimeState } else { 'Unknown' }
|
||||
$runtimeSummary[$runtimeState]++
|
||||
}
|
||||
$report | Add-Member NoteProperty VerificationScope 'Policy registry write/read-back verification; runtime activation and event generation are separate observations.'
|
||||
$report | Add-Member NoteProperty RuntimeVerification ([pscustomobject]$runtimeSummary)
|
||||
Write-Host "SMB runtime observations: $($runtimeSummary.Active) active, $($runtimeSummary.PendingVerification) pending verification, $($runtimeSummary.NotActive) not active, $($runtimeSummary.Unknown) unknown, $($runtimeSummary.NotApplicable) not applicable. Pending means observed False despite policy DWORD 1; the cause and activation timing are unknown. No refresh or restart was performed." -ForegroundColor Yellow
|
||||
if ($ResultsPath) {
|
||||
try { $report | ConvertTo-Json -Depth 14 | Set-Content -LiteralPath $ResultsPath -Encoding UTF8 -ErrorAction Stop }
|
||||
catch { $report.ExitCode = 1; Write-Host "[Failed] Writing SMB results: $_" -ForegroundColor Red }
|
||||
}
|
||||
return $report
|
||||
}
|
||||
$report = [pscustomobject]@{ Scope = 'smb-audit-policies-only'; Action = $Action; Controls = $plan; ExitCode = $(if (@($plan | Where-Object Status -eq Unknown).Count) { 1 } else { 0 }) }
|
||||
if ($ResultsPath) { $report | ConvertTo-Json -Depth 14 | Set-Content -LiteralPath $ResultsPath -Encoding UTF8 -ErrorAction Stop }
|
||||
|
||||
@@ -121,8 +121,34 @@ try {
|
||||
$script:runtimeFollows = $false
|
||||
$context = New-TestContext
|
||||
Set-WelaSmbAuditControls $context @(Get-WelaSmbAuditPlan)
|
||||
Assert ($script:writes -eq 6 -and (Complete-WelaConfiguration $context).Failed -eq 6) 'Policy DWORD alone cannot claim effective success when runtime is observably false'
|
||||
Assert ($context.Results[0].After.Policy.Value -eq 1 -and $context.Results[0].After.Runtime.Value -eq $false) 'Failed effective read-back keeps policy and runtime separate'
|
||||
$result = Complete-WelaConfiguration $context
|
||||
Assert ($script:writes -eq 6 -and $result.Failed -eq 0 -and $result.ExitCode -eq 0) 'Correct policy writes succeed independently of synchronous runtime activation'
|
||||
Assert ($context.Results[0].After.Policy.Value -eq 1 -and $context.Results[0].After.Runtime.Value -eq $false) 'Successful policy read-back retains the actual false runtime observation'
|
||||
Assert ($context.Results[0].After.PolicyRegistryConfigured -and $context.Results[0].After.RuntimeState -eq 'PendingVerification') 'Policy configuration and pending runtime verification are distinct'
|
||||
Assert ($context.Results[0].After.Runtime.Diagnostic -match 'cause and activation timing are unknown') 'False runtime state does not assume a refresh will resolve it'
|
||||
$plan = @(Get-WelaSmbAuditPlan)
|
||||
Assert (@($plan | Where-Object Status -eq PolicyConfigured).Count -eq 6) 'Audit/plan reports configured policy despite pending runtime'
|
||||
$context = New-TestContext
|
||||
Set-WelaSmbAuditControls $context $plan
|
||||
Assert ($script:writes -eq 6 -and @($context.Results | Where-Object Status -eq AlreadyCompliant).Count -eq 6) 'Pending runtime alone never causes redundant DWORD writes'
|
||||
$env:OS = 'Windows_NT'
|
||||
$pendingJson = Join-Path $root 'pending-runtime.json'
|
||||
$pendingReport = Invoke-WelaSmbAuditCommand -Action Configure -Auto -BackupPath (Join-Path $root 'pending-runtime-backup') -ResultsPath $pendingJson
|
||||
$savedPending = Get-Content $pendingJson -Raw | ConvertFrom-Json
|
||||
Assert ($pendingReport.ExitCode -eq 0 -and $savedPending.RuntimeVerification.PendingVerification -eq 6 -and $savedPending.RuntimeVerification.Active -eq 0) 'Public JSON explicitly summarizes pending runtime without a policy failure'
|
||||
Assert ($savedPending.VerificationScope -match 'Policy registry.*runtime activation.*separate') 'Public result success is explicitly scoped to the policy registry'
|
||||
foreach ($id in @($script:runtime.Keys)) { $script:runtime[$id] = $true }
|
||||
$later = @(Get-WelaSmbAuditPlan)
|
||||
Assert (@($later | Where-Object { $_.Status -eq 'PolicyConfigured' -and $_.Before.RuntimeState -eq 'Active' }).Count -eq 6) 'A later independent audit observes runtime activation without rewriting policy'
|
||||
$result = Complete-WelaConfiguration $context
|
||||
Assert ($result.ExitCode -eq 0 -and $script:writes -eq 6 -and @($result.Results | Where-Object { $_.After.RuntimeState -eq 'Active' }).Count -eq 6) 'Final recheck records later activation independently of write success'
|
||||
$script:runtime['LanmanServer/AuditClientDoesNotSupportEncryption'] = $false
|
||||
$result = Complete-WelaConfiguration $context
|
||||
Assert ($result.ExitCode -eq 0 -and $result.Results[0].After.RuntimeState -eq 'PendingVerification') 'Runtime returning false remains visible without relabeling an unchanged policy as overridden'
|
||||
$script:runtimeFails = $true
|
||||
Assert ((Complete-WelaConfiguration $context).Failed -eq 6) 'An actual runtime read error still fails the final verification instead of being treated as pending False'
|
||||
$unknownReport = Invoke-WelaSmbAuditCommand -Action Configure -Auto -BackupPath (Join-Path $root 'unknown-runtime-backup')
|
||||
Assert ($unknownReport.ExitCode -eq 1 -and $unknownReport.RuntimeVerification.Unknown -eq 6 -and $unknownReport.RuntimeVerification.Active -eq 0) 'Failed observations summarize as unknown and never reuse an older active runtime snapshot'
|
||||
|
||||
Reset-Mocks
|
||||
$script:runtimeMissing = $true
|
||||
@@ -130,6 +156,7 @@ try {
|
||||
Set-WelaSmbAuditControls $context @(Get-WelaSmbAuditPlan)
|
||||
Assert ((Complete-WelaConfiguration $context).ExitCode -eq 0) 'Exact ADMX permits registry-only configuration when runtime property is absent'
|
||||
Assert ($context.Results[0].After.Runtime.Status -eq 'NotExposed' -and $context.Results[0].After.VerificationScope -like '*effective auditing not established*') 'Registry-only outcome never claims runtime confirmation'
|
||||
Assert ($context.Results[0].After.RuntimeState -eq 'Unknown') 'An unavailable runtime property is Unknown rather than Active or pending False'
|
||||
|
||||
Reset-Mocks
|
||||
$script:wrongTypeWrite = $true
|
||||
|
||||
@@ -15,7 +15,7 @@ $clientBefore = Get-SmbClientConfiguration | Select-Object RequireSecuritySignat
|
||||
$plan = @(Get-WelaSmbAuditPlan)
|
||||
if ($plan.Count -ne 6) { throw 'Expected all six SMB audit controls.' }
|
||||
foreach ($entry in $plan) {
|
||||
if ($entry.Status -notin @('NotApplicable', 'Unknown', 'ChangeRequired', 'Compliant')) { throw 'Unexpected assessment status.' }
|
||||
if ($entry.Status -notin @('NotApplicable', 'Unknown', 'ChangeRequired', 'PolicyConfigured')) { throw 'Unexpected assessment status.' }
|
||||
Write-Host "$($entry.Definition.Component)/$($entry.Definition.Name): $($entry.Status); $($entry.Diagnostic)"
|
||||
if ($entry.Before.Runtime) { Write-Host "Runtime: $($entry.Before.Runtime.Status) / $($entry.Before.Runtime.Value)" }
|
||||
}
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
|
||||
**改善:**
|
||||
|
||||
- 6つのネイティブSMB監査ポリシーを監査・計画・設定する任意実行の`smb-auditing`を追加しました。OSビルドとローカルADMXの正確な定義を確認してから書き込み、ポリシーのDWORD値と取得可能な実行時設定を分けて表示します。Dry-run、復旧用記録、最終検証に対応し、署名・暗号化要件やゲストアクセスは変更しません。実イベント生成と収集の検証は別途必要です。 (#397) (@Shirofune-Security)
|
||||
- 6つのネイティブSMB監査ポリシーを監査・計画・設定する任意実行の`smb-auditing`を追加しました。OSビルドとローカルADMXの正確な定義を確認してから書き込み、ポリシーのDWORD値と取得可能な実行時設定を分けて表示します。Dry-run、復旧用記録、ポリシーレジストリの検証に対応します。実行時設定は有効・検証待ち・不明を区別し、Falseが観測されてもレジストリへの書き込み成功を失敗とは扱いません。署名・暗号化要件やゲストアクセスは変更しません。実イベント生成と収集の検証は別途必要です。 (#397) (@Shirofune-Security)
|
||||
- `audit-settings`、`plan`、`configure`で共有するバージョン付きの詳細監査ポリシープロファイルを追加した。59のサブカテゴリと14のプロファイルで、WELA、文書に基づくWindows既定値、Microsoft、確認済みのCIS v4.0.0、ASDのWindows標準機能向け監査ガイドに対応する。ホストの役割とビルドの検証、オフラインでの設定計画、出典と前提条件を含むJSON出力をサポートする。完全一致、最低限、任意、変更なし、未構成、適用対象外を区別する。Windows既定値は参照専用で、プロファイルの対象はSecurityログの詳細監査ポリシーに限定される。 (#390) (@Shirofune-Security)
|
||||
- WELAのプロファイルにWindows標準の監査サブカテゴリを6つ追加した。Group MembershipとAuthorization Policy Changeは成功、Application Group Management、MPSSVC Rule-Level Policy Change、IPsec Driver、Kernel Objectは成功と失敗を監査する。各ガイドに対応するプロファイルでは、それぞれの監査設定と前提条件を維持する。Kernel Objectのイベント生成には対象オブジェクトに適切なSACLが必要であり、この変更ではそのSACLを作成しない。 (#391) (@Shirofune-Security)
|
||||
- `configure`と`configure -Profile`に`-DryRun`と`-ResultsPath`を追加し、Windows設定を変更せずに変更内容を確認し、設定項目ごとの結果をJSONで出力できるようにした。`-DryRun`に対応していないコマンドは、実行前にエラーで停止する。 (#392) (@Shirofune-Security)
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
|
||||
**Improvements:**
|
||||
|
||||
- Added opt-in `smb-auditing` audit, plan and configure actions for six native SMB audit policies. Host builds and exact local ADMX mappings gate writes; policy DWORDs and available runtime values are reported separately, with dry-run, recovery journaling and final verification. Signing/encryption requirements and guest access are not changed; runtime event/ingestion validation remains required. (#397) (@Shirofune-Security)
|
||||
- Added opt-in `smb-auditing` audit, plan and configure actions for six native SMB audit policies. Host builds and exact local ADMX mappings gate writes; policy DWORDs and available runtime values are reported separately, with dry-run, recovery journaling and policy-registry verification. Runtime activation is reported separately as active, pending verification or unknown; an observed False does not turn a verified registry write into a failure. Signing/encryption requirements and guest access are not changed; runtime event/ingestion validation remains required. (#397) (@Shirofune-Security)
|
||||
- Added versioned advanced audit-policy profiles shared by `audit-settings`, `plan` and `configure`: 59 subcategories and 14 profiles covering WELA, documented Windows defaults, Microsoft, reviewed CIS v4.0.0 and ASD native guidance. Profiles support role/build validation, offline planning and JSON exports with sources and prerequisites. Exact, minimum, optional, unchanged, Not Configured and not-applicable settings remain distinct. Windows defaults are reference-only; profile scope is advanced Security audit policy. (#390) (@Shirofune-Security)
|
||||
- Added six native Windows audit subcategories to WELA's profile: Group Membership and Authorization Policy Change (Success), plus Application Group Management, MPSSVC Rule-Level Policy Change, IPsec Driver and Kernel Object (Success and Failure). Source-specific profiles retain their own audit settings and prerequisites; Kernel Object events require matching object SACLs, which this change does not create. (#391) (@Shirofune-Security)
|
||||
- Added `-DryRun` and `-ResultsPath` to `configure` and `configure -Profile` to preview changes without modifying Windows settings and export per-control results as JSON. Commands that do not support `-DryRun` reject it before running. (#392) (@Shirofune-Security)
|
||||
|
||||
Reference in new issue
Block a user