Merge pull request #475 from Shirofune-Security/feat/384-audit-integrity-closure

docs: close audit-integrity rights gap (#384)
This commit is contained in:
田中ザック Isaac Mathis authored and GitHub committed 2026-09-23 06:46:32 +09:00
commit d03a4e78ce
5 files changed
+11

No files matched your search

+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384)
- LDAP 1644 診断の役割限定、明示的な Diagnostic/MdiCleanup モード、しきい値、既存設定の保持範囲を文書化しました。 (#383)
- ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382)
+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384)
- Document role-scoped, opt-in LDAP 1644 diagnostics with explicit Diagnostic and MdiCleanup modes and preservation of unrelated NTDS values. (Related #383)
- Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382)
+3
View File
@@ -68,3 +68,6 @@ The focused suite mocks every mutation and covers exact source sets/omissions, r
Remaining acceptance evidence requires disposable, snapshotted client/member/DC labs, including member/DC AD CS and relevant IIS/AD FS/Exchange dependencies: review affected principals, apply the chosen source profile, verify new-token behavior, readback after ordinary GPO refresh, benign audit generation and authorized collection, and selective recovery with unrelated rights preserved. Do not create an audit-exhaustion test. DC/member mutation, service-token and event/ingestion evidence is still pending; read-only CI cannot close those requirements.
This is audit-integrity hardening, not a new event family. Reports set `SigmaEvtxCredit=0`; no rule-eligibility or Sigma coverage increase is inferred. Sysmon is outside this native Windows workflow.
# Issue 384 coverage
Audit-integrity profiles cover the two logging rights (`SeAuditPrivilege` and `SeSecurityPrivilege`) and the `CrashOnAuditFail` DWORD independently. Omitted profile fields preserve the observed state; the disabled crash-on-audit setting is explicit for reviewed CIS profiles. Existing service-account exceptions and unknown values remain operator review items.
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384)
- LDAP 1644 診断の役割限定、明示的な Diagnostic/MdiCleanup モード、しきい値、既存設定の保持範囲を文書化しました。 (#383)
- ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382)
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384)
- Document role-scoped, opt-in LDAP 1644 diagnostics with explicit Diagnostic and MdiCleanup modes and preservation of unrelated NTDS values. (Related #383)
- Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382)