From 1183be332bd0a113f19889b8a0665e2e94b95443 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Tue, 22 Sep 2026 18:20:25 +0900 Subject: [PATCH 1/4] docs: close issue providers --- CHANGELOG.md | 2 ++ docs/native-provider-packs.md | 3 +++ 2 files changed, 5 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index ceecb503..be7cf96b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document opt-in native provider-pack schema pinning, manual-review fallbacks, and the separation between channel configuration and Sigma eligibility. (Related #386) + - Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435)) **Improvements:** diff --git a/docs/native-provider-packs.md b/docs/native-provider-packs.md index e9b02158..6be571e3 100644 --- a/docs/native-provider-packs.md +++ b/docs/native-provider-packs.md @@ -54,3 +54,6 @@ Primary references: [Microsoft WEF Appendix C/F](https://learn.microsoft.com/en- For an explicitly reviewed DNS Server analytical transition with stopped-trace archival, use the separate [DNS analytical lifecycle](dns-analytical.md). The ordinary provider-pack setter continues to refuse Analytical/Debug configuration. The separate [`dns-client-probe`](dns-client-probe.md) can collect a fixed native DNS Client lookup completion and exact Operational3008 XML. The six pinned rule channel strings remain mismatched; the probe grants no Sigma readiness credit. +# Issue 386 coverage + +Provider packs are explicit and opt-in. Each pack pins its provider, channel, event IDs, required string fields, source rule hashes, supported role/build families, and minimum buffer size. Schema or service uncertainty produces a manual-review result; analytical/debug channels stay inventory-only. A configured channel receives no Sigma or detection credit until emitted XML, field mapping, forwarding, and matching are validated separately. From 099530df0acba4f7a658c9c10d8d642d94254785 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:44:18 +0900 Subject: [PATCH 2/4] docs: sync translated changelog snapshots --- CHANGELOG-Japanese.md | 2 ++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 3 files changed, 6 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index c433bc87..566ef18d 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) + - 完了したジャーナルから、プロセス作成・PowerShell ログ用の 3 つの DWORD 値を `audit-recovery` で復元できるようにしました。ネイティブ API による値のみの復元、他の値の変更検知、レジストリキーの保持に対応します。 ([#435](https://github.com/Yamato-Security/WELA/pull/435)) **改善:** diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index c40b06f5..abf02c18 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) + - 完了したジャーナルから、プロセス作成・PowerShell ログ用の 3 つの DWORD 値を `audit-recovery` で復元できるようにしました。ネイティブ API による値のみの復元、他の値の変更検知、レジストリキーの保持に対応します。 ([#435](https://github.com/Yamato-Security/WELA/pull/435)) **改善:** diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index d66f272c..eede35b1 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document opt-in native provider-pack schema pinning, manual-review fallbacks, and the separation between channel configuration and Sigma eligibility. (Related #386) + - Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435)) **Improvements:** From 1da7ea5cb263758073553fc774246a2680b70805 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:45:58 +0900 Subject: [PATCH 3/4] docs: restore changelog entries after dev sync --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 4 files changed, 8 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index be32f71c..b1b6a239 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) + - ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382) - 完了したジャーナルから、プロセス作成・PowerShell ログ用の 3 つの DWORD 値を `audit-recovery` で復元できるようにしました。ネイティブ API による値のみの復元、他の値の変更検知、レジストリキーの保持に対応します。 ([#435](https://github.com/Yamato-Security/WELA/pull/435)) diff --git a/CHANGELOG.md b/CHANGELOG.md index 0fbf37e0..468022ce 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) + - Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382) - Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435)) diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 03c91b3c..49de0a84 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) + - ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382) - 完了したジャーナルから、プロセス作成・PowerShell ログ用の 3 つの DWORD 値を `audit-recovery` で復元できるようにしました。ネイティブ API による値のみの復元、他の値の変更検知、レジストリキーの保持に対応します。 ([#435](https://github.com/Yamato-Security/WELA/pull/435)) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 378e1817..b322b7b3 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) + - Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382) - Extend `audit-recovery` to restore three named process/PowerShell logging DWORDs from completed journals, with native value-only writes, neighboring-data guards and retained registry keys. ([#435](https://github.com/Yamato-Security/WELA/pull/435)) From 2373923e2106f05170bdb20818f305cf1d99c495 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Wed, 23 Sep 2026 06:47:14 +0900 Subject: [PATCH 4/4] docs: restore provider-pack changelog entry --- CHANGELOG-Japanese.md | 2 ++ CHANGELOG.md | 2 ++ website/docs/resources/changelog.ja.md | 2 ++ website/docs/resources/changelog.md | 2 ++ 4 files changed, 8 insertions(+) diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index af4fb139..be3168f6 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) + - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) - `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3cbce61b..effd312c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) + - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) - Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384) diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index 3237a671..c6d60d09 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブプロバイダーパックのスキーマ固定、役割・ビルド制約、手動レビューへのフォールバック、チャネル設定と検出適格性の分離を文書化しました。 (#386) + - 履歴管理項目と既定値スナップショットのビルド、エディション、役割、機能削除、クリーンインストール証跡の適用性ゲートを文書化しました。 (#385) - `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 178415ed..4799aff0 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document opt-in native provider-pack schema pinning, role/build gating, manual-review fallbacks, and the separation between configured channels and detection eligibility. (Related #386) + - Document build, role, edition, feature, and removal applicability gates plus provenance requirements for clean-install defaults. (Related #385) - Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384)