mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
Document bounded WMI tree guarantees and record native protection behavior
This commit is contained in:
1 parent
036f51886a
commit
ddcdd8e2b8
11 files changed
+71
-8
No files matched your search
@@ -264,7 +264,12 @@ function Get-WelaWmiAuditPlan {
|
||||
} else {$snapshot = Get-WelaWmiNamespaceSnapshot $name}
|
||||
$descriptor = $snapshot.DescriptorJson | ConvertFrom-Json
|
||||
$missing = @(Get-WelaWmiMissingAces $descriptor $selected)
|
||||
[pscustomobject]@{ Namespace = $name; Status = $(if ($missing.Count) { 'ChangeRequired' } else { 'AlreadyCompliant' }); Before = $snapshot; Definitions = $selected; Missing = $missing; Descendants=$tree; Diagnostic = '' }
|
||||
$status=if($missing.Count){'ChangeRequired'}else{'AlreadyCompliant'};$diagnostic=''
|
||||
if($tree -and -not $missing.Count){
|
||||
$outcomes=Test-WelaWmiDescendantOutcomes $tree $tree $selected
|
||||
if($outcomes.Status -cne 'Observed'){$status='Unknown';$diagnostic='Parent entry exists but descendants are unverified: '+($outcomes.Diagnostics -join '; ')}
|
||||
}
|
||||
[pscustomobject]@{ Namespace = $name; Status = $status; Before = $snapshot; Definitions = $selected; Missing = $missing; Descendants=$tree; Diagnostic = $diagnostic }
|
||||
} catch { [pscustomobject]@{ Namespace = $name; Status = 'Unknown'; Before = $null; Definitions = $selected; Missing = @(); Diagnostic = $_.Exception.Message } }
|
||||
}
|
||||
}
|
||||
@@ -282,6 +287,7 @@ function Set-WelaWmiAuditControls {
|
||||
if((Get-WelaWmiDescendantKey $tree) -cne (Get-WelaWmiDescendantKey $state.PlannedTree)){throw 'WMI descendant tree changed after planning; no SACL was written.'}
|
||||
$state.OriginalTree=$tree
|
||||
}
|
||||
if($tree.Context -cne $state.OriginalTree.Context){throw 'Caller token, host, source or service context changed since descendant planning.'}
|
||||
$snapshot=$tree.Root|Select-Object *
|
||||
$snapshot|Add-Member NoteProperty Descendants $tree -Force
|
||||
} else {$snapshot = Get-WelaWmiNamespaceSnapshot $state.Namespace}
|
||||
|
||||
@@ -4,7 +4,7 @@ function Get-WelaWmiDescendantContext {
|
||||
Initialize-WelaWmiProbeNative
|
||||
if((Get-Service Winmgmt -ErrorAction Stop).Status -ne 'Running'){throw 'Winmgmt must already be running before descendant observation.'}
|
||||
$sources=[ordered]@{}
|
||||
foreach($name in @('WmiNamespaceAuditing.ps1','WmiNamespaceDescendants.ps1','WmiProbeNative.cs')){$sources[$name]=(Get-FileHash -LiteralPath (Join-Path $PSScriptRoot $name) -Algorithm SHA256 -ErrorAction Stop).Hash}
|
||||
foreach($name in @('WmiNamespaceAuditing.ps1','WmiNamespaceDescendants.ps1','WmiProbeNative.cs','WmiProbe.ps1','Configuration.ps1')){$sources[$name]=(Get-FileHash -LiteralPath (Join-Path $PSScriptRoot $name) -Algorithm SHA256 -ErrorAction Stop).Hash}
|
||||
[ordered]@{Computer=[Environment]::MachineName;Version=[Environment]::OSVersion.VersionString;Token=(Get-WelaWmiProbeTokenKey ([Wela.WmiProbe.Native]::Snapshot()));Sources=$sources}|ConvertTo-Json -Compress -Depth 5
|
||||
}
|
||||
function Get-WelaWmiChildNames {
|
||||
|
||||
Reference in new issue
Block a user