Merge remote-tracking branch 'origin/dev' into feat/384-audit-integrity-closure

This commit is contained in:
Shirofune-Security committed 2026-09-23 06:46:12 +09:00
commit e6e4c0e692
5 files changed
+7 -4

No files matched your search

+1 -1
View File
@@ -2,7 +2,7 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384)
- LDAP 1644 診断の役割限定、明示的な Diagnostic/MdiCleanup モード、しきい値、既存設定の保持範囲を文書化しました。 (#383)
- ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382)
+1 -1
View File
@@ -2,7 +2,7 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384)
- Document role-scoped, opt-in LDAP 1644 diagnostics with explicit Diagnostic and MdiCleanup modes and preservation of unrelated NTDS values. (Related #383)
- Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382)
+3
View File
@@ -35,3 +35,6 @@ Writes require a fresh complete snapshot and a saved `before.jsonl` recovery rec
For recovery, compare fresh values with both the journal's original state and this run's desired values. Restore original values/types only where this run's changes still remain; remove only a value that was originally absent. Preserve any newer operator changes and keep the recovery journal. MDI cleanup is not a general rollback command.
Tests cover default preservation, explicit setup/cleanup, positive bounds, type/read/write errors, journal ordering, stale plans, races, partial failures, repeated application and final drift. Windows CI queries native role applicability without configuring a DC. Before closing #383, use an isolated DC snapshot to verify a benign query against the selected thresholds, retain matching 1644 XML and before/after policy, measure volume, and verify forwarding. Registry readback is not event-generation or Sigma detection evidence. Sysmon is out of scope.
# Issue 383 coverage
LDAP 1644 diagnostics are opt-in and role-scoped. `Preserve` changes nothing, `Diagnostic` accepts explicit threshold values, and `MdiCleanup` removes only the four named legacy NTDS values after a fresh local-DC observation. WELA never silently overwrites existing diagnostics, and event volume, forwarding, and MDI compliance remain separate validation steps.
+1 -1
View File
@@ -5,7 +5,7 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- `SeAuditPrivilege`、`SeSecurityPrivilege`、`CrashOnAuditFail` の独立したプロファイル対応と、省略時の保持およびレビュー範囲を文書化しました。 (#384)
- LDAP 1644 診断の役割限定、明示的な Diagnostic/MdiCleanup モード、しきい値、既存設定の保持範囲を文書化しました。 (#383)
- ASD のアーカイブ、転送、時刻源、ロールオーバー、ローカルバッファ証跡に関する `retention-health` の対応範囲を文書化しました。 (#382)
+1 -1
View File
@@ -5,7 +5,7 @@
## 2.2.0 [2026/xx/xx] - Dev Release
- Document independent audit-right and CrashOnAuditFail profile coverage, including omission-preserves semantics and service-account review boundaries. (Related #384)
- Document role-scoped, opt-in LDAP 1644 diagnostics with explicit Diagnostic and MdiCleanup modes and preservation of unrelated NTDS values. (Related #383)
- Document the completed retention-health coverage for ASD-style archive, forwarding, time-source, rollover, and bounded local-buffer evidence. (Related #382)