'configure' already enables Object Access subcategories such as File Share, SAM
and Certification Services, but File System (4663), Registry (4657) and Handle
Manipulation (4656) auditing produce no events without SACLs on the audited
objects - and enabling them globally floods the log. This adds targeted SACLs on
only the autostart/persistence registry keys (ASEPs) and sensitive files that the
Hayabusa/Sigma Security-channel rules actually watch, so those rules can fire
without global object auditing.
- config/audit_sacl_targets.json: curated, commented list of 30 registry keys
(Run/RunOnce, Winlogon, IFEO, AppInit, Explorer shell extensions, Active Setup,
Command Processor AutoRun, Session Manager, LSA packages, Winsock LSP, protocol
handlers, logon scripts, Defender exclusions, service create/delete, ...) and 7
files (NTDS dir, SAM/SECURITY/SYSTEM hives, lsass.exe, ntdsutil, vssadmin),
each tagged with the ATT&CK technique / rule class it serves.
- WELA.ps1: new 'configure-sacl' command. Enables the File System / Registry /
Handle Manipulation subcategories (by GUID) and applies the SACLs from the
config (principal Everyone, Success+Failure, ContainerInherit on registry keys),
idempotently, honoring -Auto / -WhatIf / -Confirm. Enables SeSecurityPrivilege
first; skips objects absent on the host.
Per-user objects (HKCU / profile AppData) and live LSASS memory/handle access are
intentionally out of scope (need a per-user mechanism / Sysmon EID 10) and are
documented as such.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
The WELA documentation now lives on a dedicated docs site
(https://yamato-security.github.io/WELA/). Replace the long single-page README
with a short landing page that points there, and preserve the originals.
- README.md / README-Japanese.md -> OLD-README.md / OLD-README-Japanese.md
(their language-switcher cross-links updated to point at each other)
- New README.md: logo, badges, a prominent link to the docs site and its main
sections, downloads, links to the archived READMEs, and the MIT license
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>