10 Commits
Author SHA1 Message Date
Shirofune-Security 9a4a3fca95 Exercise public profile configuration against native audit policy 2026-09-22 07:41:18 +09:00
田中ザック Isaac Mathis b7e649185b Gate conditional IPsec auditing on native prerequisite evidence (#439)
* Gate conditional stronger-profile IPsec auditing on native evidence

* Use supported literal shells in native prerequisite matrix

* Retain native IPsec fixture diagnostics and allow inactive rule omission

* Expose exact native rule fields when prerequisite classification fails

* Recognize native inactive IPsec rules without granting applicability

* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
田中ザック Isaac Mathis 83b2ddd526 Support validated custom audit profile files through the shared engine (#416)
* Support validated operator-owned advanced audit profile files

* Reject lenient custom profile JSON and protect report output aliases

* Link custom audit profile changelog to PR 416

* Make custom JSON rejection fixtures portable across PowerShell versions
2026-09-20 18:09:52 +09:00
Shirofune-Security b861e86d3a Plan targeted SACL prerequisites alongside audit profiles 2026-09-19 05:25:38 +09:00
Shirofune-Security 24a77ee9ce Read audit precedence provenance from documented RSoP schemas 2026-09-19 02:35:06 +09:00
Shirofune-Security 1a12220b51 Verify advanced audit precedence before applying subcategories 2026-09-19 02:21:55 +09:00
Shirofune-Security c7b4e47925 Merge commit 'd3160a2' into feat/369-missing-audit-controls 2026-09-18 22:05:01 +09:00
Shirofune-Security d3160a2033 Preserve additional minimum audit flags and reject unknown CA roles 2026-09-18 22:04:43 +09:00
Shirofune-Security 5be186f952 Add six missing native audit subcategories with source-specific masks 2026-09-18 21:58:33 +09:00
Shirofune-Security ee7a0e2216 Unify advanced audit policy audit, plan and configure profiles 2026-09-18 21:54:38 +09:00