42 Commits
Author SHA1 Message Date
Shirofune-Security ee7a0e2216 Unify advanced audit policy audit, plan and configure profiles 2026-09-18 21:54:38 +09:00
Shirofune-SecurityandClaude Opus 4.8 db9a966a8b Add 'configure-sacl': targeted File System/Registry audit SACLs for detection
'configure' already enables Object Access subcategories such as File Share, SAM
and Certification Services, but File System (4663), Registry (4657) and Handle
Manipulation (4656) auditing produce no events without SACLs on the audited
objects - and enabling them globally floods the log. This adds targeted SACLs on
only the autostart/persistence registry keys (ASEPs) and sensitive files that the
Hayabusa/Sigma Security-channel rules actually watch, so those rules can fire
without global object auditing.

- config/audit_sacl_targets.json: curated, commented list of 30 registry keys
  (Run/RunOnce, Winlogon, IFEO, AppInit, Explorer shell extensions, Active Setup,
  Command Processor AutoRun, Session Manager, LSA packages, Winsock LSP, protocol
  handlers, logon scripts, Defender exclusions, service create/delete, ...) and 7
  files (NTDS dir, SAM/SECURITY/SYSTEM hives, lsass.exe, ntdsutil, vssadmin),
  each tagged with the ATT&CK technique / rule class it serves.
- WELA.ps1: new 'configure-sacl' command. Enables the File System / Registry /
  Handle Manipulation subcategories (by GUID) and applies the SACLs from the
  config (principal Everyone, Success+Failure, ContainerInherit on registry keys),
  idempotently, honoring -Auto / -WhatIf / -Confirm. Enables SeSecurityPrivilege
  first; skips objects absent on the host.

Per-user objects (HKCU / profile AppData) and live LSASS memory/handle access are
intentionally out of scope (need a per-user mechanism / Sysmon EID 10) and are
documented as such.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 21:50:25 +09:00
Shirofune-SecurityandClaude Opus 4.8 ccf33bed31 docs: replace README with a landing page pointing to the documentation site
The WELA documentation now lives on a dedicated docs site
(https://yamato-security.github.io/WELA/). Replace the long single-page README
with a short landing page that points there, and preserve the originals.

- README.md / README-Japanese.md -> OLD-README.md / OLD-README-Japanese.md
  (their language-switcher cross-links updated to point at each other)
- New README.md: logo, badges, a prominent link to the docs site and its main
  sections, downloads, links to the archived READMEs, and the MIT license

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 10:15:41 +09:00
fukusuket d171042b68 fix: replace '--Baseline' with '-Baseline' in command examples in README files 2025-11-22 16:14:32 +09:00
fukusuket b64f3b4a00 fix: correct spelling of 'Baseline' in command examples in README files 2025-11-22 15:59:08 +09:00
YamatoSecurity 935045d715 add badge 2025-11-15 14:23:39 +09:00
fukusuket f23af771ea docs: add Mitre Attack Navigator section to README files 2025-11-15 13:13:32 +09:00
fukusuket ec7be1ea3a feat: add configure command to set recommended Windows event log audit policy and file size 2025-11-15 12:57:09 +09:00
Yamato Security e38d1360e1 update wording 2025-05-13 16:33:45 +09:00
Yamato Security 822c8c2015 add badges 2025-05-13 12:09:02 +09:00
Fukusuke TakahashiandCopilot 30d7211e15 Update README.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-05-12 12:08:42 +09:00
fukusuket a33f1f893d doc: add readme 2025-05-12 11:53:00 +09:00
fukusuket e37262b63a doc: add readme 2025-05-12 11:37:45 +09:00
fukusuket be2e747d2d doc: add readme 2025-05-12 11:33:07 +09:00
fukusuket 9501049f1c doc: add readme 2025-05-12 11:32:45 +09:00
fukusuket a6791587ee doc: add readme 2025-05-12 11:32:04 +09:00
fukusuket 6aaa558bb7 doc: add readme 2025-05-12 11:30:52 +09:00
fukusuket 3860a9a8d5 doc: add readme 2025-05-12 11:28:24 +09:00
fukusuket 2f53182930 doc: add readme 2025-05-12 11:24:52 +09:00
fukusuket b1f1e97966 doc: add readme 2025-05-12 11:20:27 +09:00
fukusuket 3aa0c4fcf5 doc: add readme 2025-05-12 11:19:31 +09:00
fukusuket 902da44231 doc: add readme 2025-05-12 11:16:35 +09:00
fukusuket 599b4dedb5 doc: add readme 2025-05-12 11:11:11 +09:00
fukusuket fc7eb39475 doc: add readme 2025-05-12 11:09:49 +09:00
fukusuket e9a385edbf doc: add readme 2025-05-12 11:09:05 +09:00
fukusuket 9eb2feef0d doc: add readme 2025-05-12 11:05:39 +09:00
fukusuket ffbf81539e doc: add readme 2025-05-12 11:04:10 +09:00
fukusuket f2b7f5e3ee doc: add readme 2025-05-12 11:03:57 +09:00
fukusuket 8369bce2e4 doc: add readme 2025-05-12 11:03:06 +09:00
fukusuket 67b99b998e doc: add readme 2025-05-12 11:01:05 +09:00
fukusuket 2f01bc2c6f doc: add readme 2025-05-12 10:53:08 +09:00
fukusuket 9228bdd1a6 doc: add readme 2025-05-12 10:52:08 +09:00
fukusuket 2b8fb8a8fe doc: add readme 2025-05-12 10:50:13 +09:00
fukusuket 9f511dfcc7 doc: add readme 2025-05-12 10:49:15 +09:00
fukusuket 1cd657b343 doc: add readme 2025-05-12 10:38:58 +09:00
fukusuket 8ad139fb60 doc: add readme 2025-05-12 10:35:35 +09:00
fukusuket b31e1066bf doc: add readme 2025-05-12 10:33:37 +09:00
fukusuket 1eb98f6d77 doc: add readme 2025-05-12 10:24:27 +09:00
fukusuket 0e70d72dd1 doc: add readme 2025-05-12 10:22:16 +09:00
fukusuket bf78a26d47 doc: add readme 2025-05-12 10:21:10 +09:00
fukusuket 2a46a43d70 doc: add readme 2025-05-12 10:17:50 +09:00
Zach Mathis (田中ザック) 5a2a63dd78 Initial commit 2025-03-08 20:47:54 +08:00