Shirofune-Security
e068bd8f52
Merge dev and preserve independent recovery and WEC commands
2026-09-21 18:11:29 +09:00
Shirofune-Security
dd950c7358
Reject boolean coercion in completed recovery evidence
2026-09-21 18:11:21 +09:00
Shirofune-Security
ec21453cf2
Bind strict receipt parser into CAPI2 source evidence
2026-09-21 18:11:13 +09:00
Shirofune-Security
07e3d37265
Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 18:09:42 +09:00
田中ザック Isaac Mathis
9d03a19082
Activate native SMB audit runtime switches explicitly ( #441 )
...
* Add explicit native SMB runtime audit activation
* Select explicit PowerShell workflow shells and link PR changelog
* Clear expected refusal child exit codes after assertions
* Retain native SMB command provenance in capability diagnostics
* Bind SMB command guards to observed native CDXML module identities
2026-09-21 18:09:10 +09:00
Shirofune-Security
6f779a7dd4
Require exact generated certificate DER bytes
2026-09-21 18:06:27 +09:00
Shirofune-Security
d590e8226a
Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 18:04:28 +09:00
Shirofune-Security
1572d2b128
Pin observed CAPI2 XML and require existing running services
2026-09-21 18:03:42 +09:00
Shirofune-Security
e8b018d5c9
Refuse ambiguous Windows path aliases during recovery
2026-09-21 17:56:45 +09:00
Shirofune-Security
a5f674e3f8
Sign public certificate without copying its ephemeral private key
2026-09-21 17:56:04 +09:00
Shirofune-Security
8c6a597425
Cover CIS recovery paths and bound retained native evidence
2026-09-21 17:55:25 +09:00
田中ザック Isaac Mathis
b4fb77da02
Review and apply existing WEC subscription enable/disable ( #440 )
...
* Add reviewed existing WEC subscription state transitions
* Validate WEC destination and retain failed activation state
2026-09-21 17:54:55 +09:00
Shirofune-Security
2e329c7f2f
Preserve policy arrays through Windows PowerShell JSON roundtrips
2026-09-21 17:54:51 +09:00
Shirofune-Security
7184918f66
Create an unnamed CNG key through typed native helper
2026-09-21 17:53:39 +09:00
Shirofune-Security
afc748188d
Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 17:52:42 +09:00
Shirofune-Security
23f88776bf
Add guarded single-profile firewall logging recovery
2026-09-21 17:52:23 +09:00
Shirofune-Security
718ef8c91d
Add fixed offline CAPI2 chain source probe
2026-09-21 17:51:31 +09:00
Shirofune-Security
1ea0687616
Merge dev and preserve recovery and IPsec release guides
2026-09-21 17:49:46 +09:00
Shirofune-Security
63b65e2447
Add reviewed native transcription policy recovery
2026-09-21 17:48:32 +09:00
田中ザック Isaac Mathis
b7e649185b
Gate conditional IPsec auditing on native prerequisite evidence ( #439 )
...
* Gate conditional stronger-profile IPsec auditing on native evidence
* Use supported literal shells in native prerequisite matrix
* Retain native IPsec fixture diagnostics and allow inactive rule omission
* Expose exact native rule fields when prerequisite classification fails
* Recognize native inactive IPsec rules without granting applicability
* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
Shirofune-Security
d1d40b4a25
Add reviewed recovery of completed event-log size and retention changes
2026-09-21 17:42:52 +09:00
田中ザック Isaac Mathis
7cd2eb9dbf
Use precise native UTC for WMI probe event intervals ( #438 )
2026-09-21 17:30:16 +09:00
Shirofune-Security
2973eafb98
Use precise native DNS operation timestamps and nonce-only event reads
2026-09-21 10:47:06 +09:00
Shirofune-Security
cddafd04e3
Bind documented DNS query export exactly and match Microsoft server buffer
2026-09-21 10:41:30 +09:00
Shirofune-Security
58231e61f0
Select the native-layout type overload in ABI fixtures
2026-09-21 10:27:12 +09:00
Shirofune-Security
30ba5bdf07
Verify the observed present-null SACL after sole audit ACE removal
2026-09-21 10:26:57 +09:00
Shirofune-Security
d43352cbd6
Set documented DNS server-array byte size for native requests
2026-09-21 10:26:31 +09:00
Shirofune-Security
f75bb3019b
Retain bounded DNS worker evidence when native validation fails
2026-09-21 10:07:57 +09:00
Shirofune-Security
a4a0a100f3
Use independent ASD file selection in owned recovery fixture
2026-09-21 10:07:33 +09:00
Shirofune-Security
d36203bbe4
Use native zone and wildcard creation for DNS test namespace
2026-09-21 10:03:37 +09:00
Shirofune-Security
2b1a3bce82
Add guarded recovery for one selected leaf-file audit ACE
2026-09-21 10:03:00 +09:00
Shirofune-Security
1759f5a196
Use reserved test namespace for native DNS completion probe
2026-09-21 09:56:40 +09:00
Shirofune-Security
51eda06a6f
Use native module paths and transcript header command formatting
2026-09-21 09:53:50 +09:00
Shirofune-Security
1df3e401ff
Prepare explicit owned DNS zone data for native acceptance
2026-09-21 09:52:31 +09:00
Shirofune-Security
49727ea482
Preserve bounded worker diagnostics and PS5 fixture encoding
2026-09-21 09:45:55 +09:00
Shirofune-Security
480ddea0b4
Add current-account automatic transcription probe
2026-09-21 09:43:39 +09:00
Shirofune-Security
7f9c53329d
Bind native DNS evidence to bounded query status and token intervals
2026-09-21 09:39:02 +09:00
Shirofune-Security
9327d04fc9
Add guarded value-only recovery for named logging DWORDs
2026-09-21 09:34:13 +09:00
Shirofune-Security
5967a6bc1e
Add fixed native DNS Client completion probe and acceptance fixture
2026-09-21 09:33:53 +09:00
Shirofune-Security
a08f3d52f5
Fit disposable account description within Windows limit
2026-09-21 09:33:49 +09:00
Shirofune-Security
2631331406
Verify native EVTX recovery under the actual primary reader token
2026-09-21 09:30:59 +09:00
田中ザック Isaac Mathis
fd7a7924aa
Verify actual current-token access to built-in event channels ( #432 )
...
* Add actual current-token native channel read evidence
* Use supported workflow shells and link channel-read changelogs
* Handle real event exceptions and bind loaded token helper to source
* Capture query-token interval after evidence and metadata preparation
* Retain native child process exit evidence across PowerShell engines
* Bound native reader fixture pipe draining and child termination
* Preserve native errors from attributed channel query statuses
2026-09-21 09:18:46 +09:00
田中ザック Isaac Mathis
c6da22a2ad
Resume a reviewed pending AD CS auditing restart ( #431 )
...
* Add reviewed recovery for a pending AD CS auditing restart
* Link pending CA restart recovery changelogs to PR 431
2026-09-21 09:16:39 +09:00
田中ザック Isaac Mathis
2fd37d0318
Measure bounded native event delivery and verify exact EVTX samples ( #430 )
...
* Add bounded local delivery measurement and exact EVTX samples
* Link delivery measurement changelog to PR 430
* Reject evidence aliases before Windows path normalization
* Use PowerShell 5.1-compatible record IDs and bound fixture cleanup
* Revalidate the native EVTX artifact before recording final evidence
* Require exact observed local computer identities for sampled events
* Clarify provider scope within shared built-in event channels
* Preserve mixed XML payload ordering in EVTX sample verification
* Bound ordered event XML comparisons for nested UserData
* Dispose observer wait handle when bookmark creation fails
2026-09-21 09:14:48 +09:00
田中ザック Isaac Mathis
bcd4e9717e
Verify reviewed descendant SACL propagation and preservation ( #429 )
...
* Verify reviewed descendant SACL propagation and preservation
* Reference descendant SACL PR429 in release notes
* Prepare protected disposable SACL fixtures through native handles
* Use read-control handles for disposable native SACL protection
2026-09-21 09:12:56 +09:00
田中ザック Isaac Mathis
b84b97b358
Collect local WMI namespace audit evidence with a fixed read probe ( #428 )
...
* Collect bounded local WMI namespace access evidence
* Reference PR428 and preserve UTC worker query timestamps
* Observe equivalent runtime self tokens without reverting caller context
* Test native token equivalence against restricted caller changes
* Diagnose native token differences and package WMI probe guidance
* Limit WMI connections to the explicitly scoped security privilege
* Document verified native WMI events and privilege preservation
* Require an already-running WMI service before namespace reads
2026-09-21 09:08:20 +09:00
田中ザック Isaac Mathis
f1ed90d189
Create new disabled, unlinked GPOs from reviewed native audit backups ( #427 )
...
* Add guarded creation of disabled unlinked audit GPOs
* Reference PR 427 in GPO creation changelogs
* Accept only inert native ADM placeholders and fix PS5 JSON fixture
* Preserve fractional UTC strings in existing probe fixtures
2026-09-20 22:53:00 +09:00
田中ザック Isaac Mathis
610d27e8ff
Review and apply query updates to existing disabled WEC subscriptions ( #426 )
...
* Add reviewed existing-only updates for disabled WEC subscriptions
* Pin loaded updater and flush locked recovery artifacts; reference PR 426
* Compare formatted WEC queries semantically before pinning raw native state
* Read native WEC subscription XML with bounded explicit Unicode pipes
* Use explicit Unicode reads for reviewed update and native cleanup
* Keep timestamp strings exact in inherited native evidence fixtures
* Reject XML-invalid descriptions before any native save
* Decode native WEC XML BOMs without unsupported Unicode switch
* Describe native XML byte decoding accurately
* Reference System.Xml explicitly when compiling under Windows PowerShell
2026-09-20 22:51:01 +09:00
田中ザック Isaac Mathis
c12e49213f
Add guarded DNS analytical logging and stopped-trace archives ( #425 )
...
* Add guarded DNS analytical channel lifecycle and trace archives
* Link DNS analytical changelogs to PR425
* Fix native DNS archive inspection and guard artifact paths
* Diagnose exact DNS event envelope from stopped native trace
* Verify DNS ETL event provenance without inventing XML channel
* Preserve exact UTC timestamp strings in shared evidence fixtures
2026-09-20 22:49:52 +09:00
田中ザック Isaac Mathis
913b1dfaee
Add typed native WEC runtime observations ( #424 )
...
* Observe typed native WEC subscription runtime status
* Link typed WEC runtime changelog to PR 424
* Pass a native null source for subscription runtime queries
* Ignore unused count storage for native null WEC variants
* Keep unavailable WEC source inventories unknown and diagnose native XML reads
* Read native WEC subscription XML with bounded explicit Unicode pipes
* Use bounded Unicode subscription reads in runtime observations and cleanup
* Decode native WEC XML BOMs without unsupported Unicode switch
* Describe strict native WEC XML byte decoding
* Reference System.Xml explicitly when compiling under Windows PowerShell
* Regenerate website changelog snapshots with their proper headers
2026-09-20 22:48:32 +09:00