mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
Merge pull request #473 from Shirofune-Security/feat/382-retention-closure
docs: close retention and forwarding health gap (#382)
This commit is contained in:
5 files changed
+11
No files matched your search
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382)
|
||||
|
||||
- 完了したジャーナルから、プロセス作成・PowerShell ログ用の 3 つの DWORD 値を `audit-recovery` で復元できるようにしました。ネイティブ API による値のみの復元、他の値の変更検知、レジストリキーの保持に対応します。 ([#435](https://github.com/Yamato-Security/WELA/pull/435))
|
||||
|
||||
**改善:**
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382)
|
||||
|
||||
- Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435))
|
||||
|
||||
**Improvements:**
|
||||
|
||||
@@ -77,3 +77,6 @@ Before closing issue #382, use an isolated multi-host lab to compare source/coll
|
||||
Primary references: [Microsoft WEF operational behavior and delivery formats](https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/use-windows-event-forwarding-to-assist-in-intrusion-detection), [native source-initiated subscription validation](https://learn.microsoft.com/en-us/windows/win32/wec/setting-up-a-source-initiated-subscription), [Windows Time query tools](https://learn.microsoft.com/en-us/windows-server/networking/windows-time-service/windows-time-service-tools-and-settings), [Get-WinEvent ordering/query controls](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.diagnostics/get-winevent), [Security log clear 1102](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-1102), [Security log full 1104](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-1104).
|
||||
|
||||
Selected subscriptions also expose [typed local WEC runtime observations](wec-runtime.md) as `TypedRuntime`, alongside unchanged raw native evidence. Partial or unknown runtime reads remain explicit; Active and historical source inventory do not establish event delivery, backlog or retention compliance.
|
||||
# Issue 382 coverage
|
||||
|
||||
The retention report now keeps local buffer age, bounded event-rate projections, archive declarations, time-source observations, subscription runtime queries, and rollover boundaries as separate evidence. A buffer size or sampled record age never counts as central retention, archival capacity, forwarding health, or loss-free coverage. Collector operators must provide an explicit archive declaration and subscription IDs; unobserved delivery, access, and cross-host clock agreement remain `Unknown`.
|
||||
@@ -5,6 +5,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382)
|
||||
|
||||
- 完了したジャーナルから、プロセス作成・PowerShell ログ用の 3 つの DWORD 値を `audit-recovery` で復元できるようにしました。ネイティブ API による値のみの復元、他の値の変更検知、レジストリキーの保持に対応します。 ([#435](https://github.com/Yamato-Security/WELA/pull/435))
|
||||
|
||||
**改善:**
|
||||
|
||||
@@ -5,6 +5,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382)
|
||||
|
||||
- Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435))
|
||||
|
||||
**Improvements:**
|
||||
|
||||
Reference in new issue
Block a user