205 Commits
Author SHA1 Message Date
Shirofune-Security 559a9d1b82 Merge commit '008a8c80b9820318be8d9f833c6adf31c2dbf9a9' into feat/362-scoped-outgoing-ntlm
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 11:42:30 +09:00
Shirofune-Security 008a8c80b9 Merge remote-tracking branch 'origin/dev' into fix/368-native-collector-observation
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 11:42:00 +09:00
Shirofune-Security 494f9c2f93 fix: accept exact native empty catalog representations and document recovery 2026-09-22 11:01:38 +09:00
Shirofune-Security 314d25e6a2 fix: validate native empty catalogue and exercise registry recovery refusals 2026-09-22 10:57:17 +09:00
Shirofune-Security 530b49f26b feat: checkpoint reviewed native registry SACL recovery 2026-09-22 10:11:02 +09:00
Shirofune-Security b61a3c6bca Handle native WinRM manifest IDs without Int32 overflow 2026-09-22 10:10:01 +09:00
Shirofune-Security 0777a5d0f8 Add scoped outgoing NTLM audit configuration with native acceptance 2026-09-22 10:09:37 +09:00
Shirofune-Security af88b87e01 Fix native collector subscription inventory and Unicode readback 2026-09-22 09:46:28 +09:00
Shirofune-Security dc7867b6bc Merge commit 'ffe4ed473414438d5465156e15b62796393daf80' into feat/368-reviewed-wec-authorization
# Conflicts:
#	.gitattributes
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 09:35:07 +09:00
Shirofune-Security 59a83a20cc Fix WEC variant decoding and native authorization fixture 2026-09-22 08:08:17 +09:00
Shirofune-Security 806e979ede Accept genuine native channel snapshot size and provider representation 2026-09-22 08:02:36 +09:00
Shirofune-Security ef2f07f0c6 Reject final-write drift in original or retained recovery evidence 2026-09-22 07:59:16 +09:00
Shirofune-Security 0ff81052e6 Merge commit '39e8ce1' into feat/367-reviewed-channel-recovery
# Conflicts:
#	.gitattributes
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 07:53:01 +09:00
Shirofune-Security 0c51232a40 Add reviewed recovery of one completed native channel operation 2026-09-22 07:52:16 +09:00
Shirofune-Security 0051f8c662 Review and update only source SID authorization on disabled WEC subscriptions 2026-09-22 07:50:50 +09:00
Shirofune-Security 0d1adfb442 Integrate reviewed CLI, channel and native probe changes 2026-09-22 07:25:37 +09:00
Shirofune-Security c89a21f81b Integrate reviewed CLI, channels and AppLocker Script probe 2026-09-22 07:24:32 +09:00
Shirofune-Security 8bd7aa0c74 Verify effective native worker module path and complete fixture exit status 2026-09-21 23:07:16 +09:00
Shirofune-Security 2301bf1e85 Bind native listener adapter modules and normalize cross-engine context JSON 2026-09-21 23:03:17 +09:00
Shirofune-Security 3e9ba8c403 Create one reviewed exact-IP collector listener through a bounded native adapter 2026-09-21 22:58:08 +09:00
Shirofune-Security d832b1e090 Measure held-readback phase and refuse implementation targets before hashing 2026-09-21 22:51:50 +09:00
Shirofune-Security 03bc63e996 Respect inherited execution policy for the fixed file worker 2026-09-21 22:43:07 +09:00
Shirofune-Security ce7b49a5ac Bind observed native file paths and document exact read evidence 2026-09-21 22:40:50 +09:00
Shirofune-Security dc4360a886 Merge branch 'feat/375-firewall-log-recovery' into feat/373-native-file-access-probe
# Conflicts:
#	WELA.ps1
2026-09-21 22:38:41 +09:00
Shirofune-Security 37e93e10eb Refuse stopped service dependencies before AppLocker CIM observation 2026-09-21 22:34:09 +09:00
Shirofune-Security bfbdc6c476 Read the owned release pipe with encoding-preamble detection 2026-09-21 22:29:03 +09:00
Shirofune-Security 019f13b566 Merge branch 'feat/375-firewall-log-recovery' into feat/381-native-applocker-script-probe
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 22:27:49 +09:00
Shirofune-Security a61181e860 Checkpoint exact native one-byte file access probe 2026-09-21 22:27:26 +09:00
Shirofune-Security ef64b08bd2 Document Script evidence boundaries and retain bounded startup diagnostics 2026-09-21 22:26:34 +09:00
Shirofune-Security 8fed328442 Integrate the reviewed recovery and native probe batch 2026-09-21 22:23:25 +09:00
Shirofune-Security 8ac4c45653 Add fixed native AppLocker Script probe and disposable evidence matrix 2026-09-21 22:22:21 +09:00
Shirofune-Security 2f442af4da Integrate reviewed recovery and failed-logon commands 2026-09-21 22:21:35 +09:00
Shirofune-Security c4e9e765ff Integrate reviewed event-log recovery and failed-logon changes 2026-09-21 22:20:02 +09:00
Shirofune-Security 89f520511b Merge dev after failed-logon probe integration 2026-09-21 22:13:52 +09:00
田中ザック Isaac Mathis 6d228fedef Add a native local failed-logon audit probe (#444)
* Add native local nonexistent-account failed-logon probe

* Match actual MSV1 local authentication event package

* Refuse coerced identity and authentication receipt fields

* Preserve explicit UTC DateTime receipts on older PowerShell7

* Reject unknown failed-logon probe options before dispatch
2026-09-21 22:13:20 +09:00
Shirofune-Security 6bf4360362 Merge final dev and verify strict transcription recovery CLI 2026-09-21 18:22:31 +09:00
Shirofune-Security 9bc243a041 Integrate final reviewed development base for CAPI2 probe 2026-09-21 18:21:10 +09:00
Shirofune-Security e61056caba Merge final dev and preserve recovery and ingress command handlers 2026-09-21 18:21:06 +09:00
Shirofune-Security 3abe3018ba Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:20:57 +09:00
Shirofune-Security 22d3a13180 Reject coerced transcription recovery history discriminators 2026-09-21 18:19:57 +09:00
田中ザック Isaac Mathis 203fdfc942 Add reviewed scoped collector firewall ingress creation (#442)
* Add reviewed scoped collector firewall ingress creation

* Avoid Windows Clear-Item alias in native ingress fixture

* Handle native nullable package scope and retain bounded filter evidence

* Match native firewall network spelling in collector prerequisites
2026-09-21 18:19:30 +09:00
Shirofune-Security fa720f1454 Bind the reviewed native host gate and context dependency 2026-09-21 18:17:23 +09:00
Shirofune-Security 6c6edc7a68 Preserve supported UTC timestamp parsing in recovery history 2026-09-21 18:15:45 +09:00
Shirofune-Security 83ab9c8752 Require running firewall providers before recovery observations 2026-09-21 18:15:02 +09:00
Shirofune-Security 3ee0d7b6bd Require typed completion and identity fields in recovery evidence 2026-09-21 18:14:13 +09:00
Shirofune-Security e068bd8f52 Merge dev and preserve independent recovery and WEC commands 2026-09-21 18:11:29 +09:00
Shirofune-Security dd950c7358 Reject boolean coercion in completed recovery evidence 2026-09-21 18:11:21 +09:00
Shirofune-Security ec21453cf2 Bind strict receipt parser into CAPI2 source evidence 2026-09-21 18:11:13 +09:00
Shirofune-Security 07e3d37265 Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:09:42 +09:00
田中ザック Isaac Mathis 9d03a19082 Activate native SMB audit runtime switches explicitly (#441)
* Add explicit native SMB runtime audit activation

* Select explicit PowerShell workflow shells and link PR changelog

* Clear expected refusal child exit codes after assertions

* Retain native SMB command provenance in capability diagnostics

* Bind SMB command guards to observed native CDXML module identities
2026-09-21 18:09:10 +09:00