307 Commits
Author SHA1 Message Date
Shirofune-Security 38bceb3de1 Construct unknown ACE fixture without PowerShell enum validation 2026-09-19 05:42:06 +09:00
Shirofune-Security d7f710c9ad Restrict native WMI writes to SACL and verify privilege cleanup 2026-09-19 05:41:08 +09:00
Shirofune-Security 5f240d8062 Verify locked AppLocker import bytes and reject ignored options 2026-09-19 05:40:08 +09:00
Shirofune-Security 1acfec66a3 Read unexpanded ProfileList paths before validation 2026-09-19 05:36:43 +09:00
Shirofune-Security 1bf6bc26b3 Add opt-in native WEF channel settings and preserved CAPI2 read access 2026-09-19 05:36:29 +09:00
Shirofune-Security acde16f149 Guard targeted SACL planning paths and ignored skip options 2026-09-19 05:35:23 +09:00
Shirofune-Security 9ffd2bd758 Assess native AppLocker readiness and guard audit-only imports 2026-09-19 05:34:12 +09:00
Shirofune-Security 80db17891d Add opt-in WMI namespace audit SACL workflow 2026-09-19 05:30:12 +09:00
Shirofune-Security b861e86d3a Plan targeted SACL prerequisites alongside audit profiles 2026-09-19 05:25:38 +09:00
Shirofune-Security f2325b5e0b Merge commit 'be3a354' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:50:15 +09:00
Shirofune-Security 3507734538 Merge commit '88c84fa' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:49:40 +09:00
Shirofune-Security e43a43bf34 Merge commit '966aa21' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:48:54 +09:00
Shirofune-Security 157fb56bee Merge commit 'a10e1d6' into HEAD
# Conflicts:
#	scripts/Configuration.ps1
2026-09-19 04:48:19 +09:00
Shirofune-Security 966aa21a46 Enumerate corpus rules explicitly in PowerShell 5.1 fixtures 2026-09-19 04:40:13 +09:00
Shirofune-Security be3a354f18 Separate SMB policy verification from runtime activation 2026-09-19 04:39:55 +09:00
Shirofune-Security 70e6207a84 Match rule channel patterns consistently against concrete sources 2026-09-19 04:37:02 +09:00
Shirofune-Security 24a77ee9ce Read audit precedence provenance from documented RSoP schemas 2026-09-19 02:35:06 +09:00
Shirofune-Security a10e1d6e84 Reject firewall log path drift before configuration 2026-09-19 02:33:53 +09:00
Shirofune-Security 2ea509700b Add version-aware opt-in SMB audit policy controls 2026-09-19 02:33:13 +09:00
Shirofune-Security 6f1ad9d93b Verify safe HTML evidence across PowerShell JSON encoders 2026-09-19 02:33:12 +09:00
Shirofune-Security d29ffdd01b Unify event-log size and retention profiles with verified configuration 2026-09-19 02:30:41 +09:00
Shirofune-Security c4c7a33962 Assess native channels and provider prerequisites without static enabled claims 2026-09-19 02:29:56 +09:00
Shirofune-Security fbe8f95117 Add opt-in native firewall text logging controls 2026-09-19 02:24:38 +09:00
Shirofune-Security 1a12220b51 Verify advanced audit precedence before applying subcategories 2026-09-19 02:21:55 +09:00
Shirofune-Security 7d2117ebba Fix audit applicability, NTLM value types, and native exit verification 2026-09-19 00:36:38 +09:00
Shirofune-Security 71215ab498 Merge main and preserve NTLM output regression coverage 2026-09-19 00:28:55 +09:00
Shirofune-Security bf69494bd9 Report configuration-only audit states without rule coverage inference 2026-09-18 22:59:25 +09:00
Shirofune-Security 9bd56a0840 Scope integration test doubles alongside script-local helpers 2026-09-18 22:16:11 +09:00
Shirofune-Security 4c2193964e Keep deferred configuration callbacks in script scope on PowerShell 5.1 2026-09-18 22:13:58 +09:00
Shirofune-Security 595f123327 Test unsupported dry-run rejection and NTLM policy races safely 2026-09-18 22:12:30 +09:00
Shirofune-Security 60e6552823 Integrate standalone outgoing NTLM fresh-state safeguards 2026-09-18 22:10:17 +09:00
Shirofune-Security bc9e098c81 Recheck outgoing NTLM enforcement after confirmation 2026-09-18 22:09:37 +09:00
Shirofune-Security ebd8d14d04 Include read-only Windows CLI profile smoke checks 2026-09-18 22:06:06 +09:00
Shirofune-Security 6392c9bd58 Merge commit 'f4f9c33' into feat/369-missing-audit-controls 2026-09-18 22:05:30 +09:00
Shirofune-Security aa34a0360b Integrate minimum-policy and role-detection safeguards 2026-09-18 22:05:29 +09:00
Shirofune-Security d96f04dcef Integrate profile masks metadata and dry runs with verified execution 2026-09-18 22:05:25 +09:00
Shirofune-Security f4f9c33de2 Exercise real audit CLI export in Windows read-only smoke 2026-09-18 22:05:13 +09:00
Shirofune-Security c7b4e47925 Merge commit 'd3160a2' into feat/369-missing-audit-controls 2026-09-18 22:05:01 +09:00
Shirofune-Security d3160a2033 Preserve additional minimum audit flags and reject unknown CA roles 2026-09-18 22:04:43 +09:00
Shirofune-Security 24dcbdd852 Refresh native audit control evidence assertions for integration 2026-09-18 22:01:53 +09:00
Shirofune-Security 7fc5c0034f Retain profile evidence and prerequisites in integration results
# Conflicts:
#	WELA.ps1
2026-09-18 22:01:04 +09:00
Shirofune-Security a6cef75c12 Verify source attribution and prerequisites in native control results 2026-09-18 22:00:52 +09:00
Shirofune-Security 4432090a6f Merge commit '98d37fb' into feat/369-missing-audit-controls 2026-09-18 22:00:40 +09:00
Shirofune-Security 4a192d7a13 Integrate six missing native audit controls with profile execution 2026-09-18 22:00:30 +09:00
Shirofune-Security d480db5a76 Integrate versioned audit profiles with verified configuration
# Conflicts:
#	.github/workflows/release.yml
#	WELA.ps1
2026-09-18 22:00:30 +09:00
Shirofune-Security 98d37fbf37 Retain policy prerequisites and evidence in apply results 2026-09-18 21:59:59 +09:00
Shirofune-Security 5be186f952 Add six missing native audit subcategories with source-specific masks 2026-09-18 21:58:33 +09:00
Shirofune-Security f2dc28a66b Test composed NTLM policy journaling dry runs and failures 2026-09-18 21:58:06 +09:00
Shirofune-Security e0518b41ed Refresh configuration regression harness for integration 2026-09-18 21:57:42 +09:00
Shirofune-Security f5a19a45fd Integrate verified configuration results for review
# Conflicts:
#	WELA.ps1
2026-09-18 21:56:07 +09:00