Merge pull request #477 from Shirofune-Security/feat/386-provider-packs-closure

docs: close optional provider-pack gap (#386)
This commit is contained in:
田中ザック Isaac Mathis authored and GitHub committed 2026-09-23 06:47:20 +09:00
commit e5cb8f4e5d
5 files changed
+11

No files matched your search

+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386)
- 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385)
- `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384)
+2
View File
@@ -2,6 +2,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386)
- Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385)
- Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384)
+3
View File
@@ -54,3 +54,6 @@ Primary references: [Microsoft WEF Appendix C/F](https://learn.microsoft.com/en-
For an explicitly reviewed DNS Server analytical transition with stopped-trace archival, use the separate [DNS analytical lifecycle](dns-analytical.md). The ordinary provider-pack setter continues to refuse Analytical/Debug configuration.
The separate [`dns-client-probe`](dns-client-probe.md) can collect a fixed native DNS Client lookup completion and exact Operational3008 XML. The six pinned rule channel strings remain mismatched; the probe grants no Sigma readiness credit.
# Issue 386 coverage
Provider packs are explicit and opt-in. Each pack pins its provider, channel, event IDs, required string fields, source rule hashes, supported role/build families, and minimum buffer size. Schema or service uncertainty produces a manual-review result; analytical/debug channels stay inventory-only. A configured channel receives no Sigma or detection credit until emitted XML, field mapping, forwarding, and matching are validated separately.
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386)
- 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385)
- `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384)
+2
View File
@@ -5,6 +5,8 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386)
- Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385)
- Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384)