docs: document native issue coverage

This commit is contained in:
Shirofune-Security committed 2026-09-23 07:37:25 +09:00
1 parent 94d69b0280
commit d5d7630cf2
5 files changed
+12

No files matched your search

+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- バージョン対応 SMB 監査ポリシーの範囲とランタイム上の制限を文書化しました。 (#377)
- バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1)
- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2)
+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document version-aware SMB audit policy scope and runtime limitations. (Related #377)
- Document the versioned offline Intune audit export and assignment limitations. (Related #1)
- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2)
+4
View File
@@ -1,5 +1,9 @@
# Version-aware native SMB audit policies
### Issue 377 coverage
SMB audit switches are version-gated and configured independently from signing, encryption, guest access, and service state. Native readback and cleanup prove policy changes only; runtime traffic, emitted events, forwarding, and Sigma matching remain separate evidence.
The opt-in `smb-auditing` command audits, plans and configures six built-in Windows audit policies. It does not enable insecure guest access, weaken signing/encryption, change SMB dialects or shares, restart services, or install Sysmon. It does not configure event forwarding, change channel settings or claim a Sigma coverage increase.
Run in elevated **64-bit** Windows PowerShell 5.1 or PowerShell 7:
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- バージョン対応 SMB 監査ポリシーの範囲とランタイム上の制限を文書化しました。 (#377)
- バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1)
- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2)
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document version-aware SMB audit policy scope and runtime limitations. (Related #377)
- Document the versioned offline Intune audit export and assignment limitations. (Related #1)
- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2)