- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system
drive no longer skips every file target.
- Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*.
- WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows.
- reg unload is now checked (retry once, then error) so a failed unload no longer leaves the
user's NTUSER.DAT mounted under the temp alias while reporting success.
- A failed auditpol subcategory is tracked; the final message warns (instead of claiming success)
that SACLs for that class will not produce events.
- configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned.
Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with
SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
Fills the remaining gaps so 'configure' + 'configure-sacl' cover a full detection
baseline out of the box (no manual auditpol/registry needed downstream):
- Detailed Tracking > Process Termination (4689)
- Object Access > Detailed File Share (5145)
- Directory Service LDAP query logging (1644) via NTDS "15 Field Engineering"=5,
applied only on domain controllers (BloodHound/LDAP recon).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
Live-tested on Windows Server 2019; three bugs fixed found during testing:
- TOKEN_PRIVILEGES had a `long Luid` after a `uint Count`, which is 8-byte aligned on x64
and inserted padding, so AdjustTokenPrivileges failed with ERROR_NOT_ALL_ASSIGNED and the
new privilege guard aborted. Split the LUID into LuidLow(uint)+LuidHigh(int) to match the
native layout.
- Get-Acl/Set-Acl -Audit is unreliable on the registry provider (returns/throws "path does
not exist" and null). Registry SACLs now use the .NET RegistryKey API
(OpenSubKey with ReadPermissions,ChangePermissions -> GetAccessControl(Audit) ->
AddAuditRule -> SetAccessControl), which honors the enabled SeSecurityPrivilege. Absent
ASEP keys are provisioned via CreateSubKey then reopened.
- Tamper-protected keys (e.g. Defender Exclusions) that deny even admin are reported as
SKIPPED, not ERROR.
Verified: File System/Registry/Handle subcategories enabled; HKLM Run carries the Everyone
Success+Failure ContainerInherit SACL; a test autorun write produced EventID 4657 - with no
global registry auditing.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
- Enable-WelaPrivilege now validates ERROR_NOT_ALL_ASSIGNED per privilege; Set-AuditSacl
aborts if SeSecurityPrivilege cannot be enabled (was silently proceeding).
- Idempotency (Test-WelaAuditRulePresent) translates IdentityReference to SID before
comparing (Get-Acl returns NTAccount, not S-1-1-0) and also compares InheritanceFlags,
so reruns no longer re-add rules and a non-inheriting rule no longer satisfies an
inheriting target.
- Absent registry ASEP keys (RunOnceEx, Policies\Explorer\Run, ...) are now provisioned
(created) before the SACL is applied, so a later attacker write is audited via the
inheritable ACE instead of being missed.
- Services SACL is now inherited (SetValue,CreateSubKey,Delete) so 4657 on child-service
ImagePath/ServiceDLL/Start edits and service deletion are captured (4697/7045 only cover
install).
- update-rules now downloads config/audit_sacl_targets.json, matching the recovery message.
- Dropped the non-functional -WhatIf/-Confirm advertising (the script param block has a
custom -Debug that precludes CmdletBinding); configure-sacl now uses a single -Auto-skippable
confirmation prompt, consistent with 'configure'.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
Enumerate every user profile from ProfileList (plus C:\Users\Default so future
users inherit the SACL) and apply per-user SACLs:
- user_files: file SACL under each profile dir (Startup folder, Signal AppData).
- user_registry: registry SACL on each user hive - loaded hives via
HKEY_USERS\<SID> directly, offline/Default hives by reg-load/unload of
NTUSER.DAT (HKCU Run/RunOnce, User Shell Folders, StartupApproved, Load/Run,
Command Processor AutoRun, Control Panel\Desktop screensaver, Environment
logon script, LangBarAddin, Outlook Addins).
Handles are released ([gc]) before reg unload; objects/hives absent on the host
are skipped. Not covered: folder-redirected AppData on network shares, mandatory
profiles.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
'configure' already enables Object Access subcategories such as File Share, SAM
and Certification Services, but File System (4663), Registry (4657) and Handle
Manipulation (4656) auditing produce no events without SACLs on the audited
objects - and enabling them globally floods the log. This adds targeted SACLs on
only the autostart/persistence registry keys (ASEPs) and sensitive files that the
Hayabusa/Sigma Security-channel rules actually watch, so those rules can fire
without global object auditing.
- config/audit_sacl_targets.json: curated, commented list of 30 registry keys
(Run/RunOnce, Winlogon, IFEO, AppInit, Explorer shell extensions, Active Setup,
Command Processor AutoRun, Session Manager, LSA packages, Winsock LSP, protocol
handlers, logon scripts, Defender exclusions, service create/delete, ...) and 7
files (NTDS dir, SAM/SECURITY/SYSTEM hives, lsass.exe, ntdsutil, vssadmin),
each tagged with the ATT&CK technique / rule class it serves.
- WELA.ps1: new 'configure-sacl' command. Enables the File System / Registry /
Handle Manipulation subcategories (by GUID) and applies the SACLs from the
config (principal Everyone, Success+Failure, ContainerInherit on registry keys),
idempotently, honoring -Auto / -WhatIf / -Confirm. Enables SeSecurityPrivilege
first; skips objects absent on the host.
Per-user objects (HKCU / profile AppData) and live LSASS memory/handle access are
intentionally out of scope (need a per-user mechanism / Sysmon EID 10) and are
documented as such.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
The WELA documentation now lives on a dedicated docs site
(https://yamato-security.github.io/WELA/). Replace the long single-page README
with a short landing page that points there, and preserve the originals.
- README.md / README-Japanese.md -> OLD-README.md / OLD-README-Japanese.md
(their language-switcher cross-links updated to point at each other)
- New README.md: logo, badges, a prominent link to the docs site and its main
sections, downloads, links to the archived READMEs, and the MIT license
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add machine-translated content for Traditional Chinese (zh-TW), Korean, German,
Turkish, French, Spanish, Brazilian Portuguese (pt-BR), Ukrainian, Hindi,
Indonesian, Burmese, Thai and Arabic. Japanese keeps its official translation.
Only prose is translated; code, commands, paths, links and anchors preserved.
Translated navigation labels added to mkdocs.yml for every language.
Builds clean with mkdocs --strict (15 languages).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Add a documentation website under website/, built from README.md and
README-Japanese.md and laid out with top-tab topics and a left sidebar (same
style as the Hayabusa docs). Designed to be hosted free on GitHub Pages.
- Pages: Overview (About, Features, Screenshots), Getting Started, Commands
(Command List, Command Usage), Resources (Companion Projects, Other
Resources, Changelog, Contributing)
- Custom landing page, theme, click-to-zoom screenshots
- Changelog synced from CHANGELOG.md at build time
- 15-language switcher via mkdocs-static-i18n: English + Japanese full content;
the other 13 localize the UI and fall back to English until translated
- .github/workflows/docs.yml builds (mkdocs --strict) + deploys to GitHub Pages
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>