mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-09-30 03:27:15 +02:00
docs: close issue integrity
This commit is contained in:
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384)
|
||||
|
||||
- Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435))
|
||||
|
||||
**Improvements:**
|
||||
|
||||
@@ -68,3 +68,6 @@ The focused suite mocks every mutation and covers exact source sets/omissions, r
|
||||
Remaining acceptance evidence requires disposable, snapshotted client/member/DC labs, including member/DC AD CS and relevant IIS/AD FS/Exchange dependencies: review affected principals, apply the chosen source profile, verify new-token behavior, readback after ordinary GPO refresh, benign audit generation and authorized collection, and selective recovery with unrelated rights preserved. Do not create an audit-exhaustion test. DC/member mutation, service-token and event/ingestion evidence is still pending; read-only CI cannot close those requirements.
|
||||
|
||||
This is audit-integrity hardening, not a new event family. Reports set `SigmaEvtxCredit=0`; no rule-eligibility or Sigma coverage increase is inferred. Sysmon is outside this native Windows workflow.
|
||||
# Issue 384 coverage
|
||||
|
||||
Audit-integrity profiles cover the two logging rights (`SeAuditPrivilege` and `SeSecurityPrivilege`) and the `CrashOnAuditFail` DWORD independently. Omitted profile fields preserve the observed state; the disabled crash-on-audit setting is explicit for reviewed CIS profiles. Existing service-account exceptions and unknown values remain operator review items.
|
||||
|
||||
Reference in New Issue
Block a user