mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-07 23:14:45 +02:00
Create new disabled, unlinked GPOs from reviewed native audit backups (#427)
* Add guarded creation of disabled unlinked audit GPOs * Reference PR 427 in GPO creation changelogs * Accept only inert native ADM placeholders and fix PS5 JSON fixture * Preserve fractional UTC strings in existing probe fixtures
This commit is contained in:
1 parent
610d27e8ff
commit
f1ed90d189
15 files changed
+893
-46
No files matched your search
@@ -0,0 +1,48 @@
|
||||
name: Disabled unlinked GPO creation regressions
|
||||
on:
|
||||
push:
|
||||
branches: ['**']
|
||||
paths:
|
||||
- 'WELA.ps1'
|
||||
- 'scripts/GpoCreation.ps1'
|
||||
- 'scripts/GpoAuditPackages.ps1'
|
||||
- 'scripts/AdObjectSacl.ps1'
|
||||
- 'scripts/EvtxRecovery.ps1'
|
||||
- 'scripts/Configuration.ps1'
|
||||
- 'modules/AuditProfiles.psm1'
|
||||
- 'config/audit_profiles.json'
|
||||
- 'docs/gpo-*'
|
||||
- 'tests/GpoCreation*'
|
||||
- '.github/workflows/gpo-creation.yml'
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
gpo-creation:
|
||||
timeout-minutes: 25
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os: [windows-2022, windows-2025]
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
- name: Windows PowerShell 5.1 safe fixtures
|
||||
shell: powershell
|
||||
run: ./tests/GpoCreation.Tests.ps1
|
||||
- name: Windows PowerShell 5.1 public dispatch
|
||||
shell: powershell
|
||||
run: ./tests/GpoCreation.Cli.Tests.ps1
|
||||
- name: Windows PowerShell 5.1 genuine backup reads and workgroup refusal
|
||||
shell: powershell
|
||||
run: ./tests/GpoCreation.Windows.Tests.ps1 -AllowHostedGpmcInstall -OutputPath "$env:RUNNER_TEMP/gpo-native-51"
|
||||
- name: PowerShell 7 safe fixtures
|
||||
shell: pwsh
|
||||
run: ./tests/GpoCreation.Tests.ps1
|
||||
- name: PowerShell 7 public dispatch
|
||||
shell: pwsh
|
||||
run: ./tests/GpoCreation.Cli.Tests.ps1
|
||||
- name: PowerShell 7 genuine backup reads and workgroup refusal
|
||||
shell: pwsh
|
||||
run: ./tests/GpoCreation.Windows.Tests.ps1 -OutputPath "$env:RUNNER_TEMP/gpo-native-7"
|
||||
@@ -41,7 +41,7 @@ jobs:
|
||||
Copy-Item -Recurse -Path ./scripts -Destination release-binaries/
|
||||
Copy-Item -Recurse -Path ./modules -Destination release-binaries/
|
||||
New-Item -ItemType Directory -Path release-binaries/docs -Force | Out-Null
|
||||
Copy-Item -Path ./docs/gpo-audit-packages.md, ./docs/gpo-package-deployment.md -Destination release-binaries/docs/
|
||||
Copy-Item -Path ./docs/gpo-audit-packages.md, ./docs/gpo-package-deployment.md, ./docs/gpo-creation.md -Destination release-binaries/docs/
|
||||
|
||||
- name: Set Artifact Name
|
||||
if: contains(matrix.info.os, 'windows') == true
|
||||
|
||||
Reference in new issue
Block a user