From ec21453cf24619552e709a53fb1d95b4fe44960b Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Mon, 21 Sep 2026 18:11:13 +0900 Subject: [PATCH] Bind strict receipt parser into CAPI2 source evidence --- .gitattributes | 2 ++ scripts/Capi2Probe.ps1 | 2 +- tests/Capi2Probe.Tests.ps1 | 2 ++ 3 files changed, 5 insertions(+), 1 deletion(-) diff --git a/.gitattributes b/.gitattributes index fd80ff1a..dce06776 100644 --- a/.gitattributes +++ b/.gitattributes @@ -61,3 +61,5 @@ tests/SelectedSaclFixtureProtection.cs text eol=lf /scripts/Capi2Probe* text eol=lf /tests/Capi2Probe* text eol=lf + +/scripts/CustomAuditProfiles.ps1 text eol=lf diff --git a/scripts/Capi2Probe.ps1 b/scripts/Capi2Probe.ps1 index b7651196..c06e5947 100644 --- a/scripts/Capi2Probe.ps1 +++ b/scripts/Capi2Probe.ps1 @@ -7,7 +7,7 @@ function Initialize-WelaCapi2ProbeNative { } function Get-WelaCapi2ProbeSources { $sources=[ordered]@{} - foreach($name in @('WELA.ps1','scripts/Capi2Probe.ps1','scripts/Capi2ProbeWorker.ps1','scripts/Capi2ProbeNative.cs','scripts/WmiProbe.ps1','scripts/WmiProbeNative.cs','scripts/ChannelRead.ps1','scripts/WefArrival.ps1','modules/AuditProfiles.psm1')){$sources[$name]=(Get-FileHash -LiteralPath (Join-Path $PSScriptRoot ('../'+$name)) -Algorithm SHA256).Hash.ToLowerInvariant()} + foreach($name in @('WELA.ps1','scripts/Capi2Probe.ps1','scripts/Capi2ProbeWorker.ps1','scripts/Capi2ProbeNative.cs','scripts/WmiProbe.ps1','scripts/WmiProbeNative.cs','scripts/ChannelRead.ps1','scripts/WefArrival.ps1','modules/AuditProfiles.psm1','scripts/CustomAuditProfiles.ps1')){$sources[$name]=(Get-FileHash -LiteralPath (Join-Path $PSScriptRoot ('../'+$name)) -Algorithm SHA256).Hash.ToLowerInvariant()} $sources|ConvertTo-Json -Compress } function Get-WelaCapi2ProbeChannel { diff --git a/tests/Capi2Probe.Tests.ps1 b/tests/Capi2Probe.Tests.ps1 index e9e136af..d61734ab 100644 --- a/tests/Capi2Probe.Tests.ps1 +++ b/tests/Capi2Probe.Tests.ps1 @@ -7,6 +7,8 @@ $count=0 function Assert($Value,$Message){if(-not $Value){throw $Message};$script:count++} function Reject([scriptblock]$Action,$Message){$failed=$false;try{&$Action|Out-Null}catch{$failed=$true};Assert $failed $Message} function Clone($Value){ConvertFrom-WelaArrivalJson ($Value|ConvertTo-Json -Depth 24)} +$sources=Get-WelaCapi2ProbeSources|ConvertFrom-Json +Assert ($sources.'scripts/CustomAuditProfiles.ps1' -ceq (Get-FileHash -LiteralPath "$repo/scripts/CustomAuditProfiles.ps1" -Algorithm SHA256).Hash.ToLowerInvariant()) 'Strict worker-receipt parser implementation is included in source identity.' $nonce='0123456789abcdef0123456789abcdef';$now=[DateTime]::UtcNow $token=[pscustomobject]@{Sid='S-1-5-21-1-2-3-1001';Name='HOST\user';AuthenticationId='0x1234';AuthenticationType='NTLM';Groups=@([pscustomobject]@{Sid='S-1-5-32-545';Attributes=7});Privileges=@()} $state=[pscustomobject]@{Computer='HOST';Services=@([pscustomobject]@{Name='CryptSvc';Status='Running'},[pscustomobject]@{Name='EventLog';Status='Running'},[pscustomobject]@{Name='Winmgmt';Status='Running'});Host=[pscustomobject]@{Computer='HOST';Build=20348;UBR=1;ProductType=3;DomainJoined=$false;Domain='WORKGROUP'};Token=$token;Channel=[pscustomobject]@{Name='Microsoft-Windows-CAPI2/Operational';Enabled=$true;SecurityDescriptor='O:SYG:SYD:(A;;1;;;SY)';Type='Operational';Provider='Microsoft-Windows-CAPI2'};Provider=[pscustomobject]@{Name='Microsoft-Windows-CAPI2';Guid='5bbca4a8-b209-48dc-a8c7-b23d3e5216fb';Event11Versions=@(0);LogNames=@('Microsoft-Windows-CAPI2/Operational')}}