From f4cc10cbbaa9feed1955426822df24bd8ed8e3f8 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:48:50 +0900 Subject: [PATCH 01/11] docs: document issue coverage --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ docs/native-rule-eligibility.md | 3 +++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 5 files changed, 11 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index be3168f6..673c716b 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/CHANGELOG.md b/CHANGELOG.md index effd312c..2cdaa683 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) diff --git a/docs/native-rule-eligibility.md b/docs/native-rule-eligibility.md index 6c0c96a0..7da44a35 100644 --- a/docs/native-rule-eligibility.md +++ b/docs/native-rule-eligibility.md @@ -69,3 +69,6 @@ Only relative files inside the bundle directory are read. Traversal, UNC paths, Use separate Windows 11, member-server, DC and member-server CA snapshots. Record build/patch, domain membership, roles, corpus/mapping hashes and backend version. Capture before state, apply an approved source profile, generate a benign operation corresponding to one explicitly selected full rule, save native XML, then capture after state. Confirm field normalization and source identity at the collector/backend, execute the exact translated query, retain its match and independently review the normalization. SACL-dependent rules require additional reviewed adapters; a file/AD/WMI policy toggle alone never closes that gap. Measure event volume, loss/backlog and overhead separately and preserve those records; this importer does not infer EPS or storage capacity. Hosted CI uses synthetic fixtures and read-only Windows observations. It supplies no clean-image before/after matrix, genuine backend-query/ingestion result or end-to-end detection claim. Issue #387 remains open for those acceptance tests and for additional rule/parser adapters. ++### Issue 387 coverage + +Eligibility is reported as `Ready`, `Conditional`, `Blocked`, or `NotApplicable` from versioned native rule metadata and observed prerequisites. Channel enablement, SACLs, field availability, forwarding, and matching remain separate stages; native 4688 command-line limitations and Sysmon exclusions are explicit. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index c6d60d09..76eeab7c 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 4799aff0..5888265d 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) From 8a1e4e2d87bc98724043a96f752694402649597f Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:48:56 +0900 Subject: [PATCH 02/11] docs: document issue coverage --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ docs/custom-audit-profiles.md | 3 +++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 5 files changed, 11 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index be3168f6..c44602bb 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/CHANGELOG.md b/CHANGELOG.md index effd312c..e3b94184 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) diff --git a/docs/custom-audit-profiles.md b/docs/custom-audit-profiles.md index ef5cfb4d..828b19ce 100644 --- a/docs/custom-audit-profiles.md +++ b/docs/custom-audit-profiles.md @@ -121,3 +121,6 @@ These are hosted standalone servers classified by the shared profile engine as MemberServer; no domain join or GPO refresh is simulated. Configuration and benign event/backend acceptance on Windows 11, domain-joined servers, DC and AD CS labs remain separate; no clean-install or detection-coverage claim is made. ++### Issue 185 coverage + +Custom audit settings are loaded from a versioned JSON profile instead of requiring script edits. Exact, minimum, preserve, optional, and not-configured semantics are validated before configuration, with profile hashes guarding against drift. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index c6d60d09..077b51cf 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 4799aff0..8d02b226 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) From 61f57715f09237ee6f3c31881d913c3d2b2de872 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:49:00 +0900 Subject: [PATCH 03/11] docs: document issue coverage --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ docs/audit-scoring.md | 3 +++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 5 files changed, 11 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index be3168f6..3299ddaa 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/CHANGELOG.md b/CHANGELOG.md index effd312c..6063057a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) diff --git a/docs/audit-scoring.md b/docs/audit-scoring.md index 6c29c7a0..f3c60f5f 100644 --- a/docs/audit-scoring.md +++ b/docs/audit-scoring.md @@ -65,3 +65,6 @@ JSON retains the definition/version/hash, profile plan and source provenance, ac Version 1.0.0 is defined in `config/audit_scoring.json` as `native-audit-score-v1`. Changing weights requires a reviewed definition-version change, rather than silently moving the denominator. Exact profile and corpus fingerprints let a reviewer identify what was assessed. The profile hash must match before and after planning and the plan's returned hash; observed source changes abort reporting. Hashes bind recorded content, not the trustworthiness of a malicious evidence author. Letter grades and a combined security score are deliberately not defined by this first implementation of issue #10. Tests cover exact/minimum mask truth tables, optional/role omissions, unknown and empty denominators, severity weights, exclusions/unique IDs, evidence-context preservation, source changes, output collisions, HTML encoding and public command isolation. Windows Server 2022/2025 PowerShell 5.1/7 tests read real policy and verify that native masks/precedence remain unchanged. Synthetic Ready rows test arithmetic only. No Windows 11/DC/AD CS deployment or backend query evidence is claimed by those tests. ++### Issue 10 coverage + +Audit scoring uses weighted rule metadata and reports numerator, denominator, exclusions, and conditional evidence. A score summarizes reviewed eligibility states; it does not prove event generation, forwarding, or detection. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index c6d60d09..6b572496 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 4799aff0..3b3e7ddb 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) From 0b8627bbc05d0b9919dc3535970feadfb49ec129 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:49:05 +0900 Subject: [PATCH 04/11] docs: document issue coverage --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ docs/gpo-creation.md | 3 +++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 5 files changed, 11 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index be3168f6..8b1c765c 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/CHANGELOG.md b/CHANGELOG.md index effd312c..a8e5e892 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) diff --git a/docs/gpo-creation.md b/docs/gpo-creation.md index 70f60588..32e01f13 100644 --- a/docs/gpo-creation.md +++ b/docs/gpo-creation.md @@ -83,3 +83,6 @@ Windows Server 2022/2025 CI exercises real GPMC backup/report/OverallStatus usin - [GPMBackup report generation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmbackup-generatereport) - [Native GPO import: settings replacement and destination ACL/link preservation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmgpo-import) - [OverallStatus must be checked as well as the native operation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmresult-overallstatus) ++### Issue 2 coverage + +GPO creation is an explicit export workflow with role/build/profile provenance and unsupported-control disclosures. Export success does not claim domain linking, delegation, replication, client refresh, or resultant-policy application. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index c6d60d09..c54f859f 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 4799aff0..9fe08ce8 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) From 03f553e1692f7271f0837a7d8dda6d5f1cef5a3f Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:05:51 +0900 Subject: [PATCH 05/11] docs: fix issue coverage heading --- docs/native-rule-eligibility.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/native-rule-eligibility.md b/docs/native-rule-eligibility.md index 7da44a35..dd04be3d 100644 --- a/docs/native-rule-eligibility.md +++ b/docs/native-rule-eligibility.md @@ -69,6 +69,6 @@ Only relative files inside the bundle directory are read. Traversal, UNC paths, Use separate Windows 11, member-server, DC and member-server CA snapshots. Record build/patch, domain membership, roles, corpus/mapping hashes and backend version. Capture before state, apply an approved source profile, generate a benign operation corresponding to one explicitly selected full rule, save native XML, then capture after state. Confirm field normalization and source identity at the collector/backend, execute the exact translated query, retain its match and independently review the normalization. SACL-dependent rules require additional reviewed adapters; a file/AD/WMI policy toggle alone never closes that gap. Measure event volume, loss/backlog and overhead separately and preserve those records; this importer does not infer EPS or storage capacity. Hosted CI uses synthetic fixtures and read-only Windows observations. It supplies no clean-image before/after matrix, genuine backend-query/ingestion result or end-to-end detection claim. Issue #387 remains open for those acceptance tests and for additional rule/parser adapters. -+### Issue 387 coverage +### Issue 387 coverage Eligibility is reported as `Ready`, `Conditional`, `Blocked`, or `NotApplicable` from versioned native rule metadata and observed prerequisites. Channel enablement, SACLs, field availability, forwarding, and matching remain separate stages; native 4688 command-line limitations and Sysmon exclusions are explicit. From 042970a895667303f3cfc17e901440e7a62027be Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:05:54 +0900 Subject: [PATCH 06/11] docs: fix issue coverage heading --- docs/custom-audit-profiles.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/custom-audit-profiles.md b/docs/custom-audit-profiles.md index 828b19ce..b03e8cf8 100644 --- a/docs/custom-audit-profiles.md +++ b/docs/custom-audit-profiles.md @@ -121,6 +121,6 @@ These are hosted standalone servers classified by the shared profile engine as MemberServer; no domain join or GPO refresh is simulated. Configuration and benign event/backend acceptance on Windows 11, domain-joined servers, DC and AD CS labs remain separate; no clean-install or detection-coverage claim is made. -+### Issue 185 coverage +### Issue 185 coverage Custom audit settings are loaded from a versioned JSON profile instead of requiring script edits. Exact, minimum, preserve, optional, and not-configured semantics are validated before configuration, with profile hashes guarding against drift. From d9f864c0139d14729869ca729f2bc832b3107c50 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:05:56 +0900 Subject: [PATCH 07/11] docs: fix issue coverage heading --- docs/audit-scoring.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/audit-scoring.md b/docs/audit-scoring.md index f3c60f5f..3fdc6dbf 100644 --- a/docs/audit-scoring.md +++ b/docs/audit-scoring.md @@ -65,6 +65,6 @@ JSON retains the definition/version/hash, profile plan and source provenance, ac Version 1.0.0 is defined in `config/audit_scoring.json` as `native-audit-score-v1`. Changing weights requires a reviewed definition-version change, rather than silently moving the denominator. Exact profile and corpus fingerprints let a reviewer identify what was assessed. The profile hash must match before and after planning and the plan's returned hash; observed source changes abort reporting. Hashes bind recorded content, not the trustworthiness of a malicious evidence author. Letter grades and a combined security score are deliberately not defined by this first implementation of issue #10. Tests cover exact/minimum mask truth tables, optional/role omissions, unknown and empty denominators, severity weights, exclusions/unique IDs, evidence-context preservation, source changes, output collisions, HTML encoding and public command isolation. Windows Server 2022/2025 PowerShell 5.1/7 tests read real policy and verify that native masks/precedence remain unchanged. Synthetic Ready rows test arithmetic only. No Windows 11/DC/AD CS deployment or backend query evidence is claimed by those tests. -+### Issue 10 coverage +### Issue 10 coverage Audit scoring uses weighted rule metadata and reports numerator, denominator, exclusions, and conditional evidence. A score summarizes reviewed eligibility states; it does not prove event generation, forwarding, or detection. From 9cf5afe62b17f54bd91ac14116c111a448b4d699 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:05:57 +0900 Subject: [PATCH 08/11] docs: fix issue coverage heading --- docs/gpo-creation.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/gpo-creation.md b/docs/gpo-creation.md index 32e01f13..f9ef0577 100644 --- a/docs/gpo-creation.md +++ b/docs/gpo-creation.md @@ -83,6 +83,6 @@ Windows Server 2022/2025 CI exercises real GPMC backup/report/OverallStatus usin - [GPMBackup report generation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmbackup-generatereport) - [Native GPO import: settings replacement and destination ACL/link preservation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmgpo-import) - [OverallStatus must be checked as well as the native operation](https://learn.microsoft.com/en-us/windows/win32/api/gpmgmt/nf-gpmgmt-igpmresult-overallstatus) -+### Issue 2 coverage +### Issue 2 coverage GPO creation is an explicit export workflow with role/build/profile provenance and unsupported-control disclosures. Export success does not claim domain linking, delegation, replication, client refresh, or resultant-policy application. From 16e913423d643c3438f80570bf7bf3d9a4b1a43b Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:34:42 +0900 Subject: [PATCH 09/11] docs: restore custom profile changelog entry --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 4 files changed, 8 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index 673c716b..f5447ecc 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) + - ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) diff --git a/CHANGELOG.md b/CHANGELOG.md index 2cdaa683..ca8686ae 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) + - Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 76eeab7c..0bd234a5 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) + - ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 5888265d..91d9d750 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) + - Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) From 69ea640f42ffca540cba4ccae0918793ff19f84c Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:35:05 +0900 Subject: [PATCH 10/11] docs: restore scoring changelog entry --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 4 files changed, 8 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index f5447ecc..de779ff3 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) + - バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) - ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) diff --git a/CHANGELOG.md b/CHANGELOG.md index ca8686ae..c78e5739 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) + - Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) - Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 0bd234a5..2b3d7a20 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) + - バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) - ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 91d9d750..564b665c 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) + - Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) - Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) From 7e93606b7276faeeb2225f2d3b35a151afb90aae Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 07:35:31 +0900 Subject: [PATCH 11/11] docs: restore GPO changelog entry --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 4 files changed, 8 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index de779ff3..0c1ae8f6 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) + - 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) - バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) diff --git a/CHANGELOG.md b/CHANGELOG.md index c78e5739..c3677ed0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) + - Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) - Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185) diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 2b3d7a20..2ceac9cc 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) + - 監査スコアの重み付き入力、除外、証跡上の制限を文書化しました。 (#10) - バージョン付きカスタム監査プロファイルの読込、意味、変更検知を文書化しました。 (#185) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 564b665c..9826859f 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) + - Document weighted audit scoring inputs, exclusions, and evidence limitations. (Related #10) - Document versioned custom audit-profile loading, semantics, and drift protection. (Related #185)