Shirofune-Security
54f9d6bf51
Add bounded native preflight for one selected WEF QueryList
2026-09-22 12:00:26 +09:00
Shirofune-Security
af88b87e01
Fix native collector subscription inventory and Unicode readback
2026-09-22 09:46:28 +09:00
田中ザック Isaac Mathis
203fdfc942
Add reviewed scoped collector firewall ingress creation ( #442 )
...
* Add reviewed scoped collector firewall ingress creation
* Avoid Windows Clear-Item alias in native ingress fixture
* Handle native nullable package scope and retain bounded filter evidence
* Match native firewall network spelling in collector prerequisites
2026-09-21 18:19:30 +09:00
田中ザック Isaac Mathis
b7e649185b
Gate conditional IPsec auditing on native prerequisite evidence ( #439 )
...
* Gate conditional stronger-profile IPsec auditing on native evidence
* Use supported literal shells in native prerequisite matrix
* Retain native IPsec fixture diagnostics and allow inactive rule omission
* Expose exact native rule fields when prerequisite classification fails
* Recognize native inactive IPsec rules without granting applicability
* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
田中ザック Isaac Mathis
913b1dfaee
Add typed native WEC runtime observations ( #424 )
...
* Observe typed native WEC subscription runtime status
* Link typed WEC runtime changelog to PR 424
* Pass a native null source for subscription runtime queries
* Ignore unused count storage for native null WEC variants
* Keep unavailable WEC source inventories unknown and diagnose native XML reads
* Read native WEC subscription XML with bounded explicit Unicode pipes
* Use bounded Unicode subscription reads in runtime observations and cleanup
* Decode native WEC XML BOMs without unsupported Unicode switch
* Describe strict native WEC XML byte decoding
* Reference System.Xml explicitly when compiling under Windows PowerShell
* Regenerate website changelog snapshots with their proper headers
2026-09-20 22:48:32 +09:00
田中ザック Isaac Mathis
83b2ddd526
Support validated custom audit profile files through the shared engine ( #416 )
...
* Support validated operator-owned advanced audit profile files
* Reject lenient custom profile JSON and protect report output aliases
* Link custom audit profile changelog to PR 416
* Make custom JSON rejection fixtures portable across PowerShell versions
2026-09-20 18:09:52 +09:00
田中ザック Isaac Mathis
14ac8667d4
Gate historical controls and require evidence for Windows defaults ( #409 )
...
* Gate historical controls and require provenance for Windows defaults
* Bind default evidence to UTC provenance and native architecture
* Reference PR 409 in applicability changelogs
2026-09-20 14:00:10 +09:00
田中ザック Isaac Mathis
d35b1374d0
Add opt-in native DNS and provider audit packs ( #411 )
...
* Add selective native provider packs with pinned rule and schema evidence
* Reference PR 411 in provider-pack changelogs
* Fix provider pack service reader export and CI exit propagation
2026-09-20 13:58:49 +09:00
Shirofune-Security
8834dba4e6
Merge commit '45b6be91a8a35e1f08f6138fff70e0c6fafc58d1' into feat/387-native-rule-eligibility
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# WELA.ps1
# tests/AuditProfileOutput.Tests.ps1
# tests/NativeProviders.Tests.ps1
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 11:46:07 +09:00
Shirofune-Security
852de965a6
Merge commit 'f9303313148c80ad1d26376b943459d38598547b' into feat/387-native-rule-eligibility
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# WELA.ps1
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 11:45:05 +09:00
Shirofune-Security
2df9715dc1
Use explicit canonical framing for portable metadata hashes
2026-09-19 07:39:47 +09:00
Shirofune-Security
e8a0aeb59b
Keep rule evidence identities stable across Windows checkouts and shells
2026-09-19 07:34:10 +09:00
Shirofune-Security
d6da8f82c8
Retain recorded eligibility evidence scope in HTML reports
2026-09-19 07:25:44 +09:00
Shirofune-Security
36ad97114c
Assess native rule eligibility with explicit evidence gates
2026-09-19 07:24:04 +09:00
Shirofune-Security
9a69600947
Add opt-in native WEF source and collector subscription controls
2026-09-19 07:23:47 +09:00
Shirofune-Security
b2b7e0a9f7
Correct legacy token audit GUID and validate catalog mapping uncertainty
2026-09-19 07:01:50 +09:00
Shirofune-Security
75fd28a3d5
Use integer masks for byte-backed ACE flags on PowerShell 5.1
2026-09-19 05:40:00 +09:00
Shirofune-Security
c89a28190a
Bind Windows descriptor byte overload explicitly and link PR 401
2026-09-19 05:38:28 +09:00
Shirofune-Security
1bf6bc26b3
Add opt-in native WEF channel settings and preserved CAPI2 read access
2026-09-19 05:36:29 +09:00
Shirofune-Security
3507734538
Merge commit '88c84fa' into HEAD
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# WELA.ps1
# scripts/Configuration.ps1
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 04:49:40 +09:00
Shirofune-Security
d29ffdd01b
Unify event-log size and retention profiles with verified configuration
2026-09-19 02:30:41 +09:00
Shirofune-Security
c4c7a33962
Assess native channels and provider prerequisites without static enabled claims
2026-09-19 02:29:56 +09:00
Shirofune-Security
7d2117ebba
Fix audit applicability, NTLM value types, and native exit verification
2026-09-19 00:36:38 +09:00
Shirofune-Security
d3160a2033
Preserve additional minimum audit flags and reject unknown CA roles
2026-09-18 22:04:43 +09:00
Shirofune-Security
98d37fbf37
Retain policy prerequisites and evidence in apply results
2026-09-18 21:59:59 +09:00
Shirofune-Security
ee7a0e2216
Unify advanced audit policy audit, plan and configure profiles
2026-09-18 21:54:38 +09:00