Shirofune-Security
559a9d1b82
Merge commit '008a8c80b9820318be8d9f833c6adf31c2dbf9a9' into feat/362-scoped-outgoing-ntlm
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 11:42:30 +09:00
Shirofune-Security
008a8c80b9
Merge remote-tracking branch 'origin/dev' into fix/368-native-collector-observation
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 11:42:00 +09:00
Shirofune-Security
494f9c2f93
fix: accept exact native empty catalog representations and document recovery
2026-09-22 11:01:38 +09:00
Shirofune-Security
314d25e6a2
fix: validate native empty catalogue and exercise registry recovery refusals
2026-09-22 10:57:17 +09:00
Shirofune-Security
530b49f26b
feat: checkpoint reviewed native registry SACL recovery
2026-09-22 10:11:02 +09:00
Shirofune-Security
b61a3c6bca
Handle native WinRM manifest IDs without Int32 overflow
2026-09-22 10:10:01 +09:00
Shirofune-Security
0777a5d0f8
Add scoped outgoing NTLM audit configuration with native acceptance
2026-09-22 10:09:37 +09:00
Shirofune-Security
af88b87e01
Fix native collector subscription inventory and Unicode readback
2026-09-22 09:46:28 +09:00
Shirofune-Security
dc7867b6bc
Merge commit 'ffe4ed473414438d5465156e15b62796393daf80' into feat/368-reviewed-wec-authorization
...
# Conflicts:
# .gitattributes
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 09:35:07 +09:00
Shirofune-Security
59a83a20cc
Fix WEC variant decoding and native authorization fixture
2026-09-22 08:08:17 +09:00
Shirofune-Security
806e979ede
Accept genuine native channel snapshot size and provider representation
2026-09-22 08:02:36 +09:00
Shirofune-Security
ef2f07f0c6
Reject final-write drift in original or retained recovery evidence
2026-09-22 07:59:16 +09:00
Shirofune-Security
0ff81052e6
Merge commit '39e8ce1' into feat/367-reviewed-channel-recovery
...
# Conflicts:
# .gitattributes
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 07:53:01 +09:00
Shirofune-Security
0c51232a40
Add reviewed recovery of one completed native channel operation
2026-09-22 07:52:16 +09:00
Shirofune-Security
0051f8c662
Review and update only source SID authorization on disabled WEC subscriptions
2026-09-22 07:50:50 +09:00
Shirofune-Security
0d1adfb442
Integrate reviewed CLI, channel and native probe changes
2026-09-22 07:25:37 +09:00
Shirofune-Security
c89a21f81b
Integrate reviewed CLI, channels and AppLocker Script probe
2026-09-22 07:24:32 +09:00
Shirofune-Security
8bd7aa0c74
Verify effective native worker module path and complete fixture exit status
2026-09-21 23:07:16 +09:00
Shirofune-Security
2301bf1e85
Bind native listener adapter modules and normalize cross-engine context JSON
2026-09-21 23:03:17 +09:00
Shirofune-Security
3e9ba8c403
Create one reviewed exact-IP collector listener through a bounded native adapter
2026-09-21 22:58:08 +09:00
Shirofune-Security
d832b1e090
Measure held-readback phase and refuse implementation targets before hashing
2026-09-21 22:51:50 +09:00
Shirofune-Security
03bc63e996
Respect inherited execution policy for the fixed file worker
2026-09-21 22:43:07 +09:00
Shirofune-Security
ce7b49a5ac
Bind observed native file paths and document exact read evidence
2026-09-21 22:40:50 +09:00
Shirofune-Security
dc4360a886
Merge branch 'feat/375-firewall-log-recovery' into feat/373-native-file-access-probe
...
# Conflicts:
# WELA.ps1
2026-09-21 22:38:41 +09:00
Shirofune-Security
37e93e10eb
Refuse stopped service dependencies before AppLocker CIM observation
2026-09-21 22:34:09 +09:00
Shirofune-Security
bfbdc6c476
Read the owned release pipe with encoding-preamble detection
2026-09-21 22:29:03 +09:00
Shirofune-Security
019f13b566
Merge branch 'feat/375-firewall-log-recovery' into feat/381-native-applocker-script-probe
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 22:27:49 +09:00
Shirofune-Security
a61181e860
Checkpoint exact native one-byte file access probe
2026-09-21 22:27:26 +09:00
Shirofune-Security
ef64b08bd2
Document Script evidence boundaries and retain bounded startup diagnostics
2026-09-21 22:26:34 +09:00
Shirofune-Security
8fed328442
Integrate the reviewed recovery and native probe batch
2026-09-21 22:23:25 +09:00
Shirofune-Security
8ac4c45653
Add fixed native AppLocker Script probe and disposable evidence matrix
2026-09-21 22:22:21 +09:00
Shirofune-Security
2f442af4da
Integrate reviewed recovery and failed-logon commands
2026-09-21 22:21:35 +09:00
Shirofune-Security
c4e9e765ff
Integrate reviewed event-log recovery and failed-logon changes
2026-09-21 22:20:02 +09:00
Shirofune-Security
89f520511b
Merge dev after failed-logon probe integration
2026-09-21 22:13:52 +09:00
田中ザック Isaac Mathis
6d228fedef
Add a native local failed-logon audit probe ( #444 )
...
* Add native local nonexistent-account failed-logon probe
* Match actual MSV1 local authentication event package
* Refuse coerced identity and authentication receipt fields
* Preserve explicit UTC DateTime receipts on older PowerShell7
* Reject unknown failed-logon probe options before dispatch
2026-09-21 22:13:20 +09:00
Shirofune-Security
6bf4360362
Merge final dev and verify strict transcription recovery CLI
2026-09-21 18:22:31 +09:00
Shirofune-Security
9bc243a041
Integrate final reviewed development base for CAPI2 probe
2026-09-21 18:21:10 +09:00
Shirofune-Security
e61056caba
Merge final dev and preserve recovery and ingress command handlers
2026-09-21 18:21:06 +09:00
Shirofune-Security
3abe3018ba
Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 18:20:57 +09:00
Shirofune-Security
22d3a13180
Reject coerced transcription recovery history discriminators
2026-09-21 18:19:57 +09:00
田中ザック Isaac Mathis
203fdfc942
Add reviewed scoped collector firewall ingress creation ( #442 )
...
* Add reviewed scoped collector firewall ingress creation
* Avoid Windows Clear-Item alias in native ingress fixture
* Handle native nullable package scope and retain bounded filter evidence
* Match native firewall network spelling in collector prerequisites
2026-09-21 18:19:30 +09:00
Shirofune-Security
fa720f1454
Bind the reviewed native host gate and context dependency
2026-09-21 18:17:23 +09:00
Shirofune-Security
6c6edc7a68
Preserve supported UTC timestamp parsing in recovery history
2026-09-21 18:15:45 +09:00
Shirofune-Security
83ab9c8752
Require running firewall providers before recovery observations
2026-09-21 18:15:02 +09:00
Shirofune-Security
3ee0d7b6bd
Require typed completion and identity fields in recovery evidence
2026-09-21 18:14:13 +09:00
Shirofune-Security
e068bd8f52
Merge dev and preserve independent recovery and WEC commands
2026-09-21 18:11:29 +09:00
Shirofune-Security
dd950c7358
Reject boolean coercion in completed recovery evidence
2026-09-21 18:11:21 +09:00
Shirofune-Security
ec21453cf2
Bind strict receipt parser into CAPI2 source evidence
2026-09-21 18:11:13 +09:00
Shirofune-Security
07e3d37265
Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 18:09:42 +09:00
田中ザック Isaac Mathis
9d03a19082
Activate native SMB audit runtime switches explicitly ( #441 )
...
* Add explicit native SMB runtime audit activation
* Select explicit PowerShell workflow shells and link PR changelog
* Clear expected refusal child exit codes after assertions
* Retain native SMB command provenance in capability diagnostics
* Bind SMB command guards to observed native CDXML module identities
2026-09-21 18:09:10 +09:00