205 Commits
Author SHA1 Message Date
Shirofune-Security 6f779a7dd4 Require exact generated certificate DER bytes 2026-09-21 18:06:27 +09:00
Shirofune-Security d590e8226a Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:04:28 +09:00
Shirofune-Security 1572d2b128 Pin observed CAPI2 XML and require existing running services 2026-09-21 18:03:42 +09:00
Shirofune-Security e8b018d5c9 Refuse ambiguous Windows path aliases during recovery 2026-09-21 17:56:45 +09:00
Shirofune-Security a5f674e3f8 Sign public certificate without copying its ephemeral private key 2026-09-21 17:56:04 +09:00
田中ザック Isaac Mathis b4fb77da02 Review and apply existing WEC subscription enable/disable (#440)
* Add reviewed existing WEC subscription state transitions

* Validate WEC destination and retain failed activation state
2026-09-21 17:54:55 +09:00
Shirofune-Security 2e329c7f2f Preserve policy arrays through Windows PowerShell JSON roundtrips 2026-09-21 17:54:51 +09:00
Shirofune-Security 7184918f66 Create an unnamed CNG key through typed native helper 2026-09-21 17:53:39 +09:00
Shirofune-Security afc748188d Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 17:52:42 +09:00
Shirofune-Security 23f88776bf Add guarded single-profile firewall logging recovery 2026-09-21 17:52:23 +09:00
Shirofune-Security 718ef8c91d Add fixed offline CAPI2 chain source probe 2026-09-21 17:51:31 +09:00
Shirofune-Security 1ea0687616 Merge dev and preserve recovery and IPsec release guides 2026-09-21 17:49:46 +09:00
Shirofune-Security 63b65e2447 Add reviewed native transcription policy recovery 2026-09-21 17:48:32 +09:00
Shirofune-Security e88d8ec85d Select 64-bit size comparison on Windows PowerShell 5.1 2026-09-21 17:45:17 +09:00
田中ザック Isaac Mathis b7e649185b Gate conditional IPsec auditing on native prerequisite evidence (#439)
* Gate conditional stronger-profile IPsec auditing on native evidence

* Use supported literal shells in native prerequisite matrix

* Retain native IPsec fixture diagnostics and allow inactive rule omission

* Expose exact native rule fields when prerequisite classification fails

* Recognize native inactive IPsec rules without granting applicability

* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
Shirofune-Security d1d40b4a25 Add reviewed recovery of completed event-log size and retention changes 2026-09-21 17:42:52 +09:00
田中ザック Isaac Mathis 7cd2eb9dbf Use precise native UTC for WMI probe event intervals (#438) 2026-09-21 17:30:16 +09:00
Shirofune-Security 2973eafb98 Use precise native DNS operation timestamps and nonce-only event reads 2026-09-21 10:47:06 +09:00
Shirofune-Security cddafd04e3 Bind documented DNS query export exactly and match Microsoft server buffer 2026-09-21 10:41:30 +09:00
Shirofune-Security 30ba5bdf07 Verify the observed present-null SACL after sole audit ACE removal 2026-09-21 10:26:57 +09:00
Shirofune-Security d43352cbd6 Set documented DNS server-array byte size for native requests 2026-09-21 10:26:31 +09:00
Shirofune-Security f75bb3019b Retain bounded DNS worker evidence when native validation fails 2026-09-21 10:07:57 +09:00
Shirofune-Security 2b1a3bce82 Add guarded recovery for one selected leaf-file audit ACE 2026-09-21 10:03:00 +09:00
Shirofune-Security 1759f5a196 Use reserved test namespace for native DNS completion probe 2026-09-21 09:56:40 +09:00
Shirofune-Security 51eda06a6f Use native module paths and transcript header command formatting 2026-09-21 09:53:50 +09:00
Shirofune-Security 1df3e401ff Prepare explicit owned DNS zone data for native acceptance 2026-09-21 09:52:31 +09:00
Shirofune-Security 49727ea482 Preserve bounded worker diagnostics and PS5 fixture encoding 2026-09-21 09:45:55 +09:00
Shirofune-Security 480ddea0b4 Add current-account automatic transcription probe 2026-09-21 09:43:39 +09:00
Shirofune-Security 7f9c53329d Bind native DNS evidence to bounded query status and token intervals 2026-09-21 09:39:02 +09:00
Shirofune-Security 9327d04fc9 Add guarded value-only recovery for named logging DWORDs 2026-09-21 09:34:13 +09:00
Shirofune-Security 5967a6bc1e Add fixed native DNS Client completion probe and acceptance fixture 2026-09-21 09:33:53 +09:00
Shirofune-Security 2631331406 Verify native EVTX recovery under the actual primary reader token 2026-09-21 09:30:59 +09:00
田中ザック Isaac Mathis fd7a7924aa Verify actual current-token access to built-in event channels (#432)
* Add actual current-token native channel read evidence

* Use supported workflow shells and link channel-read changelogs

* Handle real event exceptions and bind loaded token helper to source

* Capture query-token interval after evidence and metadata preparation

* Retain native child process exit evidence across PowerShell engines

* Bound native reader fixture pipe draining and child termination

* Preserve native errors from attributed channel query statuses
2026-09-21 09:18:46 +09:00
田中ザック Isaac Mathis c6da22a2ad Resume a reviewed pending AD CS auditing restart (#431)
* Add reviewed recovery for a pending AD CS auditing restart

* Link pending CA restart recovery changelogs to PR 431
2026-09-21 09:16:39 +09:00
田中ザック Isaac Mathis 2fd37d0318 Measure bounded native event delivery and verify exact EVTX samples (#430)
* Add bounded local delivery measurement and exact EVTX samples

* Link delivery measurement changelog to PR 430

* Reject evidence aliases before Windows path normalization

* Use PowerShell 5.1-compatible record IDs and bound fixture cleanup

* Revalidate the native EVTX artifact before recording final evidence

* Require exact observed local computer identities for sampled events

* Clarify provider scope within shared built-in event channels

* Preserve mixed XML payload ordering in EVTX sample verification

* Bound ordered event XML comparisons for nested UserData

* Dispose observer wait handle when bookmark creation fails
2026-09-21 09:14:48 +09:00
田中ザック Isaac Mathis bcd4e9717e Verify reviewed descendant SACL propagation and preservation (#429)
* Verify reviewed descendant SACL propagation and preservation

* Reference descendant SACL PR429 in release notes

* Prepare protected disposable SACL fixtures through native handles

* Use read-control handles for disposable native SACL protection
2026-09-21 09:12:56 +09:00
田中ザック Isaac Mathis b84b97b358 Collect local WMI namespace audit evidence with a fixed read probe (#428)
* Collect bounded local WMI namespace access evidence

* Reference PR428 and preserve UTC worker query timestamps

* Observe equivalent runtime self tokens without reverting caller context

* Test native token equivalence against restricted caller changes

* Diagnose native token differences and package WMI probe guidance

* Limit WMI connections to the explicitly scoped security privilege

* Document verified native WMI events and privilege preservation

* Require an already-running WMI service before namespace reads
2026-09-21 09:08:20 +09:00
田中ザック Isaac Mathis f1ed90d189 Create new disabled, unlinked GPOs from reviewed native audit backups (#427)
* Add guarded creation of disabled unlinked audit GPOs

* Reference PR 427 in GPO creation changelogs

* Accept only inert native ADM placeholders and fix PS5 JSON fixture

* Preserve fractional UTC strings in existing probe fixtures
2026-09-20 22:53:00 +09:00
田中ザック Isaac Mathis 610d27e8ff Review and apply query updates to existing disabled WEC subscriptions (#426)
* Add reviewed existing-only updates for disabled WEC subscriptions

* Pin loaded updater and flush locked recovery artifacts; reference PR 426

* Compare formatted WEC queries semantically before pinning raw native state

* Read native WEC subscription XML with bounded explicit Unicode pipes

* Use explicit Unicode reads for reviewed update and native cleanup

* Keep timestamp strings exact in inherited native evidence fixtures

* Reject XML-invalid descriptions before any native save

* Decode native WEC XML BOMs without unsupported Unicode switch

* Describe native XML byte decoding accurately

* Reference System.Xml explicitly when compiling under Windows PowerShell
2026-09-20 22:51:01 +09:00
田中ザック Isaac Mathis c12e49213f Add guarded DNS analytical logging and stopped-trace archives (#425)
* Add guarded DNS analytical channel lifecycle and trace archives

* Link DNS analytical changelogs to PR425

* Fix native DNS archive inspection and guard artifact paths

* Diagnose exact DNS event envelope from stopped native trace

* Verify DNS ETL event provenance without inventing XML channel

* Preserve exact UTC timestamp strings in shared evidence fixtures
2026-09-20 22:49:52 +09:00
田中ザック Isaac Mathis 913b1dfaee Add typed native WEC runtime observations (#424)
* Observe typed native WEC subscription runtime status

* Link typed WEC runtime changelog to PR 424

* Pass a native null source for subscription runtime queries

* Ignore unused count storage for native null WEC variants

* Keep unavailable WEC source inventories unknown and diagnose native XML reads

* Read native WEC subscription XML with bounded explicit Unicode pipes

* Use bounded Unicode subscription reads in runtime observations and cleanup

* Decode native WEC XML BOMs without unsupported Unicode switch

* Describe strict native WEC XML byte decoding

* Reference System.Xml explicitly when compiling under Windows PowerShell

* Regenerate website changelog snapshots with their proper headers
2026-09-20 22:48:32 +09:00
田中ザック Isaac Mathis 5ba53fbcfb Validate native AppLocker EXE event generation with an opt-in probe (#423)
* Add native AppLocker EXE event validation probe

* Reference PR 423 in changelogs

* Isolate AppLocker native fixture and preserve prerequisite diagnostics

* Report an integer zero for an empty AppLocker policy

* Prepare disposable AppLocker probe policy without bypassing production importer guards

* Retain bounded native AppLocker channel diagnostics on probe failure

* Require native policy application before the disposable AppLocker probe

* Preserve exact timestamp strings in native evidence fixtures

* Record actual runner session and AppLocker publication diagnostics

* Activate and restore the native policy converter on disposable AppLocker hosts

* Compare native task freshness without guessing its timestamp timezone

* Verify effective policy and borrowed converter inactivity during fixture cleanup

* Track the actual native policy-converter task instance instead of cached timestamps
2026-09-20 22:46:56 +09:00
田中ザック Isaac Mathis ff0e5c1890 Apply reviewed SACL plans to explicitly selected local targets (#422)
* Add reviewed configuration for selected native SACL targets

* Link selected SACL changelog to PR 422

* Identify native full-descriptor read failures without partial fallback

* Fix diagnostic variable scope in native C# helper

* Read explicit descriptor sections and retain observation scope
2026-09-20 19:36:05 +09:00
田中ザック Isaac Mathis f1c1f74166 Guard AD CS audit configuration and collect native request evidence (#421)
* Add guarded native CA auditing and disposable request evidence

* Link AD CS changelog to PR 421

* Retain primary native CA failure before cleanup diagnostics

* Normalize native CA certificate hashes and record pending feature removal

* Emit bounded disposable CA request matching diagnostics

* Match observed version 1 CA request events with exact pending disposition
2026-09-20 19:34:03 +09:00
田中ザック Isaac Mathis 38a392f3d6 Export and verify recovery of native probe events from EVTX (#420)
* Export and recover exact native probe events from EVTX

* Link changelog to PR 420

* Make EVTX duplicate JSON fixture portable to PowerShell 5.1
2026-09-20 19:33:20 +09:00
田中ザック Isaac Mathis 60006531be Restore selected audit changes from reviewed recovery evidence (#419)
* Add guarded restoration of selected completed audit writes

* Link changelog to PR 419

* Read recovery host name from Windows instead of environment overrides

* Require local fixed-drive recovery output paths
2026-09-20 19:30:49 +09:00
田中ザック Isaac Mathis e5557df038 Verify native probe arrival in the local WEF collector (#418)
* Verify native probe presence in the local WEF collector

* Link WEF arrival changelog to PR 418

* Make duplicate JSON fixture independent of PowerShell formatting
2026-09-20 19:26:57 +09:00
田中ザック Isaac Mathis f21a9f30e4 Add transparent configuration and native rule readiness scores (#417)
* Add transparent native audit compliance and evidence readiness scores

* Link transparent audit scoring changelog to PR 417

* Resolve scoring outputs against the PowerShell filesystem location
2026-09-20 18:15:04 +09:00
田中ザック Isaac Mathis 3a80ef5e67 Add reviewable GPO audit-policy deployment packages (#415)
* Add reviewable GPO audit-policy deployment components

* Link GPO audit package changelog to PR 415

* Check GPO verification exit code from a real CLI process
2026-09-20 18:13:34 +09:00
田中ザック Isaac Mathis ec6a6df68a Export native audit profiles for reviewed Intune client policies (#414)
* Add offline Intune Audit CSP exports from shared client profiles

* Link Intune audit export changelog to PR 414
2026-09-20 18:10:52 +09:00