mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-07 23:14:45 +02:00
Merge pull request #487 from Shirofune-Security/feat/377-smb-closure
docs: close SMB audit policy gap (#377)
This commit is contained in:
5 files changed
+12
No files matched your search
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- バージョン対応 SMB 監査ポリシーの範囲とランタイム上の制限を文書化しました。 (#377)
|
||||
|
||||
- バージョン対応 OneSettings と Security 警告設定の範囲を文書化しました。 (#378)
|
||||
|
||||
- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379)
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document version-aware SMB audit policy scope and runtime limitations. (Related #377)
|
||||
|
||||
- Document version-aware OneSettings and Security warning configuration boundaries. (Related #378)
|
||||
|
||||
- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379)
|
||||
|
||||
@@ -1,5 +1,9 @@
|
||||
# Version-aware native SMB audit policies
|
||||
|
||||
### Issue 377 coverage
|
||||
|
||||
SMB audit switches are version-gated and configured independently from signing, encryption, guest access, and service state. Native readback and cleanup prove policy changes only; runtime traffic, emitted events, forwarding, and Sigma matching remain separate evidence.
|
||||
|
||||
The opt-in `smb-auditing` command audits, plans and configures six built-in Windows audit policies. It does not enable insecure guest access, weaken signing/encryption, change SMB dialects or shares, restart services, or install Sysmon. It does not configure event forwarding, change channel settings or claim a Sigma coverage increase.
|
||||
|
||||
Run in elevated **64-bit** Windows PowerShell 5.1 or PowerShell 7:
|
||||
|
||||
@@ -5,6 +5,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- バージョン対応 SMB 監査ポリシーの範囲とランタイム上の制限を文書化しました。 (#377)
|
||||
|
||||
- バージョン対応 OneSettings と Security 警告設定の範囲を文書化しました。 (#378)
|
||||
|
||||
- イベントログのサイズ、保持モード、復旧に関する保護範囲を文書化しました。 (#379)
|
||||
|
||||
@@ -5,6 +5,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document version-aware SMB audit policy scope and runtime limitations. (Related #377)
|
||||
|
||||
- Document version-aware OneSettings and Security warning configuration boundaries. (Related #378)
|
||||
|
||||
- Document guarded event-log sizing, retention-mode, and recovery boundaries. (Related #379)
|
||||
|
||||
Reference in new issue
Block a user