Document bounded WMI tree guarantees and record native protection behavior

This commit is contained in:
Shirofune-Security committed 2026-09-22 14:40:25 +09:00
1 parent 036f51886a
commit ddcdd8e2b8
11 files changed
+71 -8

No files matched your search

+7 -1
View File
@@ -264,7 +264,12 @@ function Get-WelaWmiAuditPlan {
} else {$snapshot = Get-WelaWmiNamespaceSnapshot $name}
$descriptor = $snapshot.DescriptorJson | ConvertFrom-Json
$missing = @(Get-WelaWmiMissingAces $descriptor $selected)
[pscustomobject]@{ Namespace = $name; Status = $(if ($missing.Count) { 'ChangeRequired' } else { 'AlreadyCompliant' }); Before = $snapshot; Definitions = $selected; Missing = $missing; Descendants=$tree; Diagnostic = '' }
$status=if($missing.Count){'ChangeRequired'}else{'AlreadyCompliant'};$diagnostic=''
if($tree -and -not $missing.Count){
$outcomes=Test-WelaWmiDescendantOutcomes $tree $tree $selected
if($outcomes.Status -cne 'Observed'){$status='Unknown';$diagnostic='Parent entry exists but descendants are unverified: '+($outcomes.Diagnostics -join '; ')}
}
[pscustomobject]@{ Namespace = $name; Status = $status; Before = $snapshot; Definitions = $selected; Missing = $missing; Descendants=$tree; Diagnostic = $diagnostic }
} catch { [pscustomobject]@{ Namespace = $name; Status = 'Unknown'; Before = $null; Definitions = $selected; Missing = @(); Diagnostic = $_.Exception.Message } }
}
}
@@ -282,6 +287,7 @@ function Set-WelaWmiAuditControls {
if((Get-WelaWmiDescendantKey $tree) -cne (Get-WelaWmiDescendantKey $state.PlannedTree)){throw 'WMI descendant tree changed after planning; no SACL was written.'}
$state.OriginalTree=$tree
}
if($tree.Context -cne $state.OriginalTree.Context){throw 'Caller token, host, source or service context changed since descendant planning.'}
$snapshot=$tree.Root|Select-Object *
$snapshot|Add-Member NoteProperty Descendants $tree -Force
} else {$snapshot = Get-WelaWmiNamespaceSnapshot $state.Namespace}
+1 -1
View File
@@ -4,7 +4,7 @@ function Get-WelaWmiDescendantContext {
Initialize-WelaWmiProbeNative
if((Get-Service Winmgmt -ErrorAction Stop).Status -ne 'Running'){throw 'Winmgmt must already be running before descendant observation.'}
$sources=[ordered]@{}
foreach($name in @('WmiNamespaceAuditing.ps1','WmiNamespaceDescendants.ps1','WmiProbeNative.cs')){$sources[$name]=(Get-FileHash -LiteralPath (Join-Path $PSScriptRoot $name) -Algorithm SHA256 -ErrorAction Stop).Hash}
foreach($name in @('WmiNamespaceAuditing.ps1','WmiNamespaceDescendants.ps1','WmiProbeNative.cs','WmiProbe.ps1','Configuration.ps1')){$sources[$name]=(Get-FileHash -LiteralPath (Join-Path $PSScriptRoot $name) -Algorithm SHA256 -ErrorAction Stop).Hash}
[ordered]@{Computer=[Environment]::MachineName;Version=[Environment]::OSVersion.VersionString;Token=(Get-WelaWmiProbeTokenKey ([Wela.WmiProbe.Native]::Snapshot()));Sources=$sources}|ConvertTo-Json -Compress -Depth 5
}
function Get-WelaWmiChildNames {