3 Commits
Author SHA1 Message Date
Shirofune-Security 2631331406 Verify native EVTX recovery under the actual primary reader token 2026-09-21 09:30:59 +09:00
田中ザック Isaac Mathis 5ba53fbcfb Validate native AppLocker EXE event generation with an opt-in probe (#423)
* Add native AppLocker EXE event validation probe

* Reference PR 423 in changelogs

* Isolate AppLocker native fixture and preserve prerequisite diagnostics

* Report an integer zero for an empty AppLocker policy

* Prepare disposable AppLocker probe policy without bypassing production importer guards

* Retain bounded native AppLocker channel diagnostics on probe failure

* Require native policy application before the disposable AppLocker probe

* Preserve exact timestamp strings in native evidence fixtures

* Record actual runner session and AppLocker publication diagnostics

* Activate and restore the native policy converter on disposable AppLocker hosts

* Compare native task freshness without guessing its timestamp timezone

* Verify effective policy and borrowed converter inactivity during fixture cleanup

* Track the actual native policy-converter task instance instead of cached timestamps
2026-09-20 22:46:56 +09:00
田中ザック Isaac Mathis 38a392f3d6 Export and verify recovery of native probe events from EVTX (#420)
* Export and recover exact native probe events from EVTX

* Link changelog to PR 420

* Make EVTX duplicate JSON fixture portable to PowerShell 5.1
2026-09-20 19:33:20 +09:00