Merge pull request #487 from Shirofune-Security/feat/377-smb-closure

docs: close SMB audit policy gap (#377)
This commit is contained in:
田中ザック Isaac Mathis authored and GitHub committed 2026-09-23 08:59:03 +09:00
commit d59ebe38fa
5 files changed
+12

No files matched your search

+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- バージョン対応 SMB 監査ポリシーの範囲とランタイム上の制限を文書化しました。 (#377)
- バージョン対応 OneSettings と Security 警告設定の範囲を文書化しました。 (#378)
- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379)
+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document version-aware SMB audit policy scope and runtime limitations. (Related #377)
- Document version-aware OneSettings and Security warning configuration boundaries. (Related #378)
- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379)
+4
View File
@@ -1,5 +1,9 @@
# Version-aware native SMB audit policies
### Issue 377 coverage
SMB audit switches are version-gated and configured independently from signing, encryption, guest access, and service state. Native readback and cleanup prove policy changes only; runtime traffic, emitted events, forwarding, and Sigma matching remain separate evidence.
The opt-in `smb-auditing` command audits, plans and configures six built-in Windows audit policies. It does not enable insecure guest access, weaken signing/encryption, change SMB dialects or shares, restart services, or install Sysmon. It does not configure event forwarding, change channel settings or claim a Sigma coverage increase.
Run in elevated **64-bit** Windows PowerShell 5.1 or PowerShell 7:
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- バージョン対応 SMB 監査ポリシーの範囲とランタイム上の制限を文書化しました。 (#377)
- バージョン対応 OneSettings と Security 警告設定の範囲を文書化しました。 (#378)
- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379)
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document version-aware SMB audit policy scope and runtime limitations. (Related #377)
- Document version-aware OneSettings and Security warning configuration boundaries. (Related #378)
- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379)