diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index be3168f6..673c716b 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/CHANGELOG.md b/CHANGELOG.md index effd312c..2cdaa683 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) diff --git a/docs/native-rule-eligibility.md b/docs/native-rule-eligibility.md index 6c0c96a0..dd04be3d 100644 --- a/docs/native-rule-eligibility.md +++ b/docs/native-rule-eligibility.md @@ -69,3 +69,6 @@ Only relative files inside the bundle directory are read. Traversal, UNC paths, Use separate Windows 11, member-server, DC and member-server CA snapshots. Record build/patch, domain membership, roles, corpus/mapping hashes and backend version. Capture before state, apply an approved source profile, generate a benign operation corresponding to one explicitly selected full rule, save native XML, then capture after state. Confirm field normalization and source identity at the collector/backend, execute the exact translated query, retain its match and independently review the normalization. SACL-dependent rules require additional reviewed adapters; a file/AD/WMI policy toggle alone never closes that gap. Measure event volume, loss/backlog and overhead separately and preserve those records; this importer does not infer EPS or storage capacity. Hosted CI uses synthetic fixtures and read-only Windows observations. It supplies no clean-image before/after matrix, genuine backend-query/ingestion result or end-to-end detection claim. Issue #387 remains open for those acceptance tests and for additional rule/parser adapters. +### Issue 387 coverage + +Eligibility is reported as `Ready`, `Conditional`, `Blocked`, or `NotApplicable` from versioned native rule metadata and observed prerequisites. Channel enablement, SACLs, field availability, forwarding, and matching remain separate stages; native 4688 command-line limitations and Sysmon exclusions are explicit. diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index c6d60d09..76eeab7c 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ限定 Sigma 適格性の再現可能な状態と、VM・証跡の境界を文書化しました。 (#387) + - ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 4799aff0..5888265d 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document reproducible native-only Sigma eligibility states and explicit VM/evidence boundaries. (Related #387) + - Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385)