435 Commits
Author SHA1 Message Date
田中ザック Isaac Mathis 2fd37d0318 Measure bounded native event delivery and verify exact EVTX samples (#430)
* Add bounded local delivery measurement and exact EVTX samples

* Link delivery measurement changelog to PR 430

* Reject evidence aliases before Windows path normalization

* Use PowerShell 5.1-compatible record IDs and bound fixture cleanup

* Revalidate the native EVTX artifact before recording final evidence

* Require exact observed local computer identities for sampled events

* Clarify provider scope within shared built-in event channels

* Preserve mixed XML payload ordering in EVTX sample verification

* Bound ordered event XML comparisons for nested UserData

* Dispose observer wait handle when bookmark creation fails
2026-09-21 09:14:48 +09:00
田中ザック Isaac Mathis f21a9f30e4 Add transparent configuration and native rule readiness scores (#417)
* Add transparent native audit compliance and evidence readiness scores

* Link transparent audit scoring changelog to PR 417

* Resolve scoring outputs against the PowerShell filesystem location
2026-09-20 18:15:04 +09:00
田中ザック Isaac Mathis ec6a6df68a Export native audit profiles for reviewed Intune client policies (#414)
* Add offline Intune Audit CSP exports from shared client profiles

* Link Intune audit export changelog to PR 414
2026-09-20 18:10:52 +09:00
田中ザック Isaac Mathis 83b2ddd526 Support validated custom audit profile files through the shared engine (#416)
* Support validated operator-owned advanced audit profile files

* Reject lenient custom profile JSON and protect report output aliases

* Link custom audit profile changelog to PR 416

* Make custom JSON rejection fixtures portable across PowerShell versions
2026-09-20 18:09:52 +09:00
田中ザック Isaac Mathis 7719063f6f Add source-specific Windows audit privilege and integrity controls (#412)
* Add opt-in source-profile audit integrity controls

* Reference PR 412 in audit-integrity changelogs
2026-09-20 14:03:18 +09:00
田中ザック Isaac Mathis 55cc427c61 Report native log retention and collection health evidence (#410)
* Add read-only native retention and collection health evidence reports

* Verify retention HTML evidence across PowerShell JSON serializers

* Reference PR 410 in retention changelogs

* Preserve previous-report arrays on Windows PowerShell and test both server releases
2026-09-20 14:01:43 +09:00
田中ザック Isaac Mathis 14ac8667d4 Gate historical controls and require evidence for Windows defaults (#409)
* Gate historical controls and require provenance for Windows defaults

* Bind default evidence to UTC provenance and native architecture

* Reference PR 409 in applicability changelogs
2026-09-20 14:00:10 +09:00
田中ザック Isaac Mathis d35b1374d0 Add opt-in native DNS and provider audit packs (#411)
* Add selective native provider packs with pinned rule and schema evidence

* Reference PR 411 in provider-pack changelogs

* Fix provider pack service reader export and CI exit propagation
2026-09-20 13:58:49 +09:00
Shirofune-Security 8834dba4e6 Merge commit '45b6be91a8a35e1f08f6138fff70e0c6fafc58d1' into feat/387-native-rule-eligibility
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	tests/AuditProfileOutput.Tests.ps1
#	tests/NativeProviders.Tests.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 11:46:07 +09:00
Shirofune-Security 852de965a6 Merge commit 'f9303313148c80ad1d26376b943459d38598547b' into feat/387-native-rule-eligibility
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 11:45:05 +09:00
Shirofune-Security 36ad97114c Assess native rule eligibility with explicit evidence gates 2026-09-19 07:24:04 +09:00
Shirofune-Security 9a69600947 Add opt-in native WEF source and collector subscription controls 2026-09-19 07:23:47 +09:00
Shirofune-Security b2b7e0a9f7 Correct legacy token audit GUID and validate catalog mapping uncertainty 2026-09-19 07:01:50 +09:00
Shirofune-Security 1bf6bc26b3 Add opt-in native WEF channel settings and preserved CAPI2 read access 2026-09-19 05:36:29 +09:00
Shirofune-Security 3507734538 Merge commit '88c84fa' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:49:40 +09:00
Shirofune-Security 70e6207a84 Match rule channel patterns consistently against concrete sources 2026-09-19 04:37:02 +09:00
Shirofune-Security d29ffdd01b Unify event-log size and retention profiles with verified configuration 2026-09-19 02:30:41 +09:00
Shirofune-Security c4c7a33962 Assess native channels and provider prerequisites without static enabled claims 2026-09-19 02:29:56 +09:00
Shirofune-Security 5be186f952 Add six missing native audit subcategories with source-specific masks 2026-09-18 21:58:33 +09:00
Shirofune-Security ee7a0e2216 Unify advanced audit policy audit, plan and configure profiles 2026-09-18 21:54:38 +09:00
Shirofune-SecurityandClaude Opus 4.8 10c1bcaac7 Address Copilot re-review: %SystemRoot%, Entra SIDs, WOW64 gate, reg-unload check, subcategory-failure, help
- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system
  drive no longer skips every file target.
- Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*.
- WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows.
- reg unload is now checked (retry once, then error) so a failed unload no longer leaves the
  user's NTUSER.DAT mounted under the temp alias while reporting success.
- A failed auditpol subcategory is tracked; the final message warns (instead of claiming success)
  that SACLs for that class will not produce events.
- configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned.

Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with
SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:49:42 +09:00
Shirofune-SecurityandClaude Opus 4.8 1308bc003d Address Copilot review: privilege check, idempotency, ASEP provisioning, service inheritance, update-rules, CLI
- Enable-WelaPrivilege now validates ERROR_NOT_ALL_ASSIGNED per privilege; Set-AuditSacl
  aborts if SeSecurityPrivilege cannot be enabled (was silently proceeding).
- Idempotency (Test-WelaAuditRulePresent) translates IdentityReference to SID before
  comparing (Get-Acl returns NTAccount, not S-1-1-0) and also compares InheritanceFlags,
  so reruns no longer re-add rules and a non-inheriting rule no longer satisfies an
  inheriting target.
- Absent registry ASEP keys (RunOnceEx, Policies\Explorer\Run, ...) are now provisioned
  (created) before the SACL is applied, so a later attacker write is audited via the
  inheritable ACE instead of being missed.
- Services SACL is now inherited (SetValue,CreateSubKey,Delete) so 4657 on child-service
  ImagePath/ServiceDLL/Start edits and service deletion are captured (4697/7045 only cover
  install).
- update-rules now downloads config/audit_sacl_targets.json, matching the recovery message.
- Dropped the non-functional -WhatIf/-Confirm advertising (the script param block has a
  custom -Debug that precludes CmdletBinding); configure-sacl now uses a single -Auto-skippable
  confirmation prompt, consistent with 'configure'.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:11:03 +09:00
Shirofune-SecurityandClaude Opus 4.8 31aeeda768 configure-sacl: cover per-user objects across all profiles + Default
Enumerate every user profile from ProfileList (plus C:\Users\Default so future
users inherit the SACL) and apply per-user SACLs:
- user_files: file SACL under each profile dir (Startup folder, Signal AppData).
- user_registry: registry SACL on each user hive - loaded hives via
  HKEY_USERS\<SID> directly, offline/Default hives by reg-load/unload of
  NTUSER.DAT (HKCU Run/RunOnce, User Shell Folders, StartupApproved, Load/Run,
  Command Processor AutoRun, Control Panel\Desktop screensaver, Environment
  logon script, LangBarAddin, Outlook Addins).
Handles are released ([gc]) before reg unload; objects/hives absent on the host
are skipped. Not covered: folder-redirected AppData on network shares, mandatory
profiles.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:03:24 +09:00
Shirofune-SecurityandClaude Opus 4.8 db9a966a8b Add 'configure-sacl': targeted File System/Registry audit SACLs for detection
'configure' already enables Object Access subcategories such as File Share, SAM
and Certification Services, but File System (4663), Registry (4657) and Handle
Manipulation (4656) auditing produce no events without SACLs on the audited
objects - and enabling them globally floods the log. This adds targeted SACLs on
only the autostart/persistence registry keys (ASEPs) and sensitive files that the
Hayabusa/Sigma Security-channel rules actually watch, so those rules can fire
without global object auditing.

- config/audit_sacl_targets.json: curated, commented list of 30 registry keys
  (Run/RunOnce, Winlogon, IFEO, AppInit, Explorer shell extensions, Active Setup,
  Command Processor AutoRun, Session Manager, LSA packages, Winsock LSP, protocol
  handlers, logon scripts, Defender exclusions, service create/delete, ...) and 7
  files (NTDS dir, SAM/SECURITY/SYSTEM hives, lsass.exe, ntdsutil, vssadmin),
  each tagged with the ATT&CK technique / rule class it serves.
- WELA.ps1: new 'configure-sacl' command. Enables the File System / Registry /
  Handle Manipulation subcategories (by GUID) and applies the SACLs from the
  config (principal Everyone, Success+Failure, ContainerInherit on registry keys),
  idempotently, honoring -Auto / -WhatIf / -Confirm. Enables SeSecurityPrivilege
  first; skips objects absent on the host.

Per-user objects (HKCU / profile AppData) and live LSASS memory/handle access are
intentionally out of scope (need a per-user mechanism / Sysmon EID 10) and are
documented as such.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 21:50:25 +09:00
github-actions[bot]andYamatoSecurity faa7988b87 Sigma Rule Update (2026-09-01 22:29:49) (#359)
Co-authored-by: YamatoSecurity <71482215+YamatoSecurity@users.noreply.github.com>
2026-09-01 22:29:56 +00:00
fukusuket eee2c58f5a feat: update baselines.json to change currentSetting type to channel and specify DFSN-Server Admin 2026-09-01 23:39:47 +09:00
fukusuket a9ceec469a feat: add DFSN-Server Admin channel to baselines and update changelog 2026-09-01 23:32:53 +09:00
fukusuket dcb183871d fix: remove extraneous closing parenthesis in baselines.json note 2026-08-30 21:20:23 +09:00
fukusuket 8d8e401fdb fix: correct spelling errors in baselines.json settings 2026-08-30 21:19:11 +09:00
fukusuket dcf29e4a59 fix: update .gitignore and release workflows for new output files and README changes 2026-08-30 21:08:16 +09:00
github-actions[bot]andYamatoSecurity ff2664b419 Sigma Rule Update (2026-08-01 20:59:49) (#357)
Co-authored-by: YamatoSecurity <71482215+YamatoSecurity@users.noreply.github.com>
2026-08-01 20:59:57 +00:00
github-actions[bot]andYamatoSecurity f312fc5fc9 Sigma Rule Update (2026-07-01 21:40:59) (#356)
Co-authored-by: YamatoSecurity <71482215+YamatoSecurity@users.noreply.github.com>
2026-07-01 21:41:06 +00:00
github-actions[bot]andYamatoSecurity afe91eea3b Sigma Rule Update (2026-06-01 22:34:27) (#353)
Co-authored-by: YamatoSecurity <71482215+YamatoSecurity@users.noreply.github.com>
2026-06-01 22:34:35 +00:00
github-actions[bot]andYamatoSecurity 5566538242 Sigma Rule Update (2026-05-22 21:04:11) (#351)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-22 21:04:19 +00:00
github-actions[bot]andYamatoSecurity 820d0c1283 Sigma Rule Update (2026-05-21 21:22:31) (#350)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-21 21:22:40 +00:00
github-actions[bot]andYamatoSecurity 499255fe32 Sigma Rule Update (2026-05-20 21:46:10) (#349)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-20 21:46:17 +00:00
github-actions[bot]andYamatoSecurity f7333c5358 Sigma Rule Update (2026-05-19 21:13:17) (#348)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-19 21:13:26 +00:00
github-actions[bot]andYamatoSecurity 887de1d5c9 Sigma Rule Update (2026-05-18 21:04:23) (#347)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-18 21:04:31 +00:00
github-actions[bot]andYamatoSecurity 404d781e88 Sigma Rule Update (2026-05-17 20:41:12) (#346)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-17 20:41:20 +00:00
github-actions[bot]andYamatoSecurity f75a0ebc00 Sigma Rule Update (2026-05-16 20:39:47) (#345)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-16 20:39:55 +00:00
github-actions[bot]andYamatoSecurity c1fa19a5f0 Sigma Rule Update (2026-05-15 20:54:25) (#344)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-15 20:54:32 +00:00
github-actions[bot]andYamatoSecurity 028b7f9ab6 Sigma Rule Update (2026-05-14 21:04:35) (#343)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-14 21:04:44 +00:00
github-actions[bot]andYamatoSecurity 1a13a15b44 Sigma Rule Update (2026-05-13 21:20:14) (#342)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-13 21:20:23 +00:00
github-actions[bot]andYamatoSecurity 77194e48f0 Sigma Rule Update (2026-05-12 21:12:57) (#341)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-12 21:13:05 +00:00
github-actions[bot]andYamatoSecurity d2c31c1d22 Sigma Rule Update (2026-05-11 21:12:00) (#340)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-11 21:12:08 +00:00
github-actions[bot]andYamatoSecurity 08e6fddb82 Sigma Rule Update (2026-05-10 20:40:41) (#339)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-10 20:40:48 +00:00
github-actions[bot]andYamatoSecurity f0bdac1f79 Sigma Rule Update (2026-05-09 20:37:40) (#338)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-09 20:37:48 +00:00
github-actions[bot]andYamatoSecurity 50d1217ca9 Sigma Rule Update (2026-05-08 20:52:30) (#337)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-08 20:52:37 +00:00
github-actions[bot]andYamatoSecurity e52bfe34ff Sigma Rule Update (2026-05-07 20:59:31) (#336)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-07 20:59:39 +00:00
github-actions[bot]andYamatoSecurity cc10302d3d Sigma Rule Update (2026-05-06 21:05:07) (#335)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2026-05-06 21:05:14 +00:00