Merge remote-tracking branch 'origin/dev' into feat/1-intune-closure

This commit is contained in:
Shirofune-Security committed 2026-09-23 07:35:41 +09:00
commit db46798b9b
8 files changed
+40 -4

No files matched your search

+7 -1
View File
@@ -2,7 +2,13 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1)
- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2)
- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10)
- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185)
- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387)
- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386)
+7 -1
View File
@@ -2,7 +2,13 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document the versioned offline Intune audit export and its assignment limitations. (Related #1)
- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2)
- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10)
- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185)
- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387)
- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386)
+3
View File
@@ -65,3 +65,6 @@ JSON retains the definition/version/hash, profile plan and source provenance, ac
Version 1.0.0 is defined in `config/audit_scoring.json` as `native-audit-score-v1`. Changing weights requires a reviewed definition-version change, rather than silently moving the denominator. Exact profile and corpus fingerprints let a reviewer identify what was assessed. The profile hash must match before and after planning and the plan's returned hash; observed source changes abort reporting. Hashes bind recorded content, not the trustworthiness of a malicious evidence author. Letter grades and a combined security score are deliberately not defined by this first implementation of issue #10.
Tests cover exact/minimum mask truth tables, optional/role omissions, unknown and empty denominators, severity weights, exclusions/unique IDs, evidence-context preservation, source changes, output collisions, HTML encoding and public command isolation. Windows Server 2022/2025 PowerShell 5.1/7 tests read real policy and verify that native masks/precedence remain unchanged. Synthetic Ready rows test arithmetic only. No Windows 11/DC/AD CS deployment or backend query evidence is claimed by those tests.
### Issue 10 coverage
Audit scoring uses weighted rule metadata and reports numerator, denominator, exclusions, and conditional evidence. A score summarizes reviewed eligibility states; it does not prove event generation, forwarding, or detection.
+3
View File
@@ -121,3 +121,6 @@ These are hosted standalone servers classified by the shared profile engine as
MemberServer; no domain join or GPO refresh is simulated. Configuration and
benign event/backend acceptance on Windows 11, domain-joined servers, DC and AD CS labs remain separate;
no clean-install or detection-coverage claim is made.
### Issue 185 coverage
Custom audit settings are loaded from a versioned JSON profile instead of requiring script edits. Exact, minimum, preserve, optional, and not-configured semantics are validated before configuration, with profile hashes guarding against drift.
+3
View File
@@ -83,3 +83,6 @@ Windows Server 2022/2025 CI exercises real GPMC backup/report/OverallStatus usin
- [GPMBackup report generation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmbackup-generatereport)
- [Native GPO import: settings replacement and destination ACL/link preservation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmgpo-import)
- [OverallStatus must be checked as well as the native operation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmresult-overallstatus)
### Issue 2 coverage
GPO creation is an explicit export workflow with role/build/profile provenance and unsupported-control disclosures. Export success does not claim domain linking, delegation, replication, client refresh, or resultant-policy application.
+3
View File
@@ -69,3 +69,6 @@ Only relative files inside the bundle directory are read. Traversal, UNC paths,
Use separate Windows 11, member-server, DC and member-server CA snapshots. Record build/patch, domain membership, roles, corpus/mapping hashes and backend version. Capture before state, apply an approved source profile, generate a benign operation corresponding to one explicitly selected full rule, save native XML, then capture after state. Confirm field normalization and source identity at the collector/backend, execute the exact translated query, retain its match and independently review the normalization. SACL-dependent rules require additional reviewed adapters; a file/AD/WMI policy toggle alone never closes that gap. Measure event volume, loss/backlog and overhead separately and preserve those records; this importer does not infer EPS or storage capacity.
Hosted CI uses synthetic fixtures and read-only Windows observations. It supplies no clean-image before/after matrix, genuine backend-query/ingestion result or end-to-end detection claim. Issue #387 remains open for those acceptance tests and for additional rule/parser adapters.
### Issue 387 coverage
Eligibility is reported as `Ready`, `Conditional`, `Blocked`, or `NotApplicable` from versioned native rule metadata and observed prerequisites. Channel enablement, SACLs, field availability, forwarding, and matching remain separate stages; native 4688 command-line limitations and Sysmon exclusions are explicit.
+7 -1
View File
@@ -5,7 +5,13 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1)
- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2)
- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10)
- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185)
- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387)
- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386)
+7 -1
View File
@@ -5,7 +5,13 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document the versioned offline Intune audit export and its assignment limitations. (Related #1)
- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2)
- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10)
- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185)
- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387)
- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386)