Commit Graph
966 Commits
Author SHA1 Message Date
Shirofune-Security 0403f14446 Clear expected child failure exit status after CLI assertions 2026-09-19 07:33:32 +09:00
Shirofune-Security 787c66e009 Normalize WEF XML evidence before PowerShell 5.1 JSON serialization 2026-09-19 07:31:23 +09:00
Shirofune-Security 9b93473904 Link WEF provisioning changelog to PR 406 2026-09-19 07:24:31 +09:00
Shirofune-Security 9a69600947 Add opt-in native WEF source and collector subscription controls 2026-09-19 07:23:47 +09:00
Shirofune-Security 9d993a2a7e Merge branch 'feat/367-native-channel-access' into feat/371-ad-object-sacl
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 06:54:08 +09:00
Shirofune-Security 0229348963 Merge branch 'feat/381-applocker-readiness' into feat/367-native-channel-access
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 06:53:25 +09:00
Shirofune-Security aff422bf99 Merge remote-tracking branch 'origin/dev' into feat/381-applocker-readiness
# Conflicts:
#	WELA.ps1
2026-09-19 06:52:50 +09:00
田中ザック Isaac Mathis 423277428a Merge pull request #399 from Shirofune-Security/feat/372-wmi-namespace-auditing
Add opt-in WMI namespace audit SACL configuration
2026-09-19 19:45:11 +09:00
田中ザック Isaac Mathis ded0b9c375 Merge pull request #398 from Shirofune-Security/feat/373-targeted-sacl-planning
Plan targeted SACL prerequisites alongside audit profiles
2026-09-19 19:41:51 +09:00
Shirofune-Security 86ac6e7bd6 Merge dev targeted SACL planning into AppLocker readiness branch 2026-09-19 06:51:13 +09:00
Shirofune-Security d83c2419b0 Merge remote-tracking branch 'origin/dev' into feat/367-native-channel-access
# Conflicts:
#	WELA.ps1
2026-09-19 06:51:10 +09:00
Shirofune-Security 47302ef9ae Merge remote-tracking branch 'origin/dev' into feat/371-ad-object-sacl 2026-09-19 06:50:32 +09:00
Shirofune-Security 2c0bbfae0b Merge remote-tracking branch 'origin/dev' into feat/372-wmi-namespace-auditing 2026-09-19 06:49:04 +09:00
Shirofune-Security a74a3e79f0 Handle unused AppLocker placeholders without weakening merge enforcement guards 2026-09-19 06:25:36 +09:00
Shirofune-Security bf12f186fb Record verified WMI control flags and disposable test scope 2026-09-19 06:23:14 +09:00
Shirofune-Security 521fe3b826 Preserve configured user-file suffixes in SACL plans 2026-09-19 06:21:18 +09:00
Shirofune-Security 92bf29ec22 Isolate unknown dMSA prerequisites from other AD audit classes 2026-09-19 06:20:41 +09:00
Shirofune-Security 072bcdf6af Verify native WMI SACL flags on disposable Windows namespaces 2026-09-19 06:20:32 +09:00
Shirofune-Security cbd1c0643b Confirm AD SACL receipt ownership and validate exact PKI parent 2026-09-19 05:47:54 +09:00
Shirofune-Security 496423bb8c Reference PR 402 in bilingual changelogs 2026-09-19 05:44:21 +09:00
Shirofune-Security c338dae12e Add opt-in AD directory object SACL profiles and recovery (issue #371) 2026-09-19 05:42:25 +09:00
Shirofune-Security 38bceb3de1 Construct unknown ACE fixture without PowerShell enum validation 2026-09-19 05:42:06 +09:00
Shirofune-Security d7f710c9ad Restrict native WMI writes to SACL and verify privilege cleanup 2026-09-19 05:41:08 +09:00
Shirofune-Security 5f240d8062 Verify locked AppLocker import bytes and reject ignored options 2026-09-19 05:40:08 +09:00
Shirofune-Security 75fd28a3d5 Use integer masks for byte-backed ACE flags on PowerShell 5.1 2026-09-19 05:40:00 +09:00
Shirofune-Security c89a28190a Bind Windows descriptor byte overload explicitly and link PR 401 2026-09-19 05:38:28 +09:00
Shirofune-Security 1acfec66a3 Read unexpanded ProfileList paths before validation 2026-09-19 05:36:43 +09:00
Shirofune-Security 1bf6bc26b3 Add opt-in native WEF channel settings and preserved CAPI2 read access 2026-09-19 05:36:29 +09:00
Shirofune-Security acde16f149 Guard targeted SACL planning paths and ignored skip options 2026-09-19 05:35:23 +09:00
Shirofune-Security 6fbef0ff6b Reference PR 400 in bilingual changelogs 2026-09-19 05:35:09 +09:00
Shirofune-Security 45ab6bcc8c Reference PR 399 in bilingual changelogs 2026-09-19 05:34:58 +09:00
Shirofune-Security 9ffd2bd758 Assess native AppLocker readiness and guard audit-only imports 2026-09-19 05:34:12 +09:00
Shirofune-Security 6489775d30 Reference PR 398 in bilingual changelogs 2026-09-19 05:30:50 +09:00
Shirofune-Security 80db17891d Add opt-in WMI namespace audit SACL workflow 2026-09-19 05:30:12 +09:00
Shirofune-Security b861e86d3a Plan targeted SACL prerequisites alongside audit profiles 2026-09-19 05:25:38 +09:00
Shirofune-Security 385f367ae5 Provision DFS Namespace for full configuration CI 2026-09-19 05:05:47 +09:00
Shirofune-Security f2325b5e0b Merge commit 'be3a354' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:50:15 +09:00
Shirofune-Security 3507734538 Merge commit '88c84fa' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:49:40 +09:00
Shirofune-Security e43a43bf34 Merge commit '966aa21' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:48:54 +09:00
Shirofune-Security 157fb56bee Merge commit 'a10e1d6' into HEAD
# Conflicts:
#	scripts/Configuration.ps1
2026-09-19 04:48:19 +09:00
Shirofune-Security 810bbb61ec Merge commit '24a77ee' into HEAD 2026-09-19 04:46:00 +09:00
Zach Mathis (田中ザック) c45f7a1319 Merge pull request #388 from Shirofune-Security/fix/362-outgoing-ntlm-audit
Document outgoing NTLM audit behavior in changelogs
2026-09-19 15:05:37 +09:00
Zach Mathis (田中ザック) 6efda1e018 Merge pull request #390 from Shirofune-Security/feat/364-shared-audit-profiles
Document shared versioned audit-policy profiles in changelogs
2026-09-19 14:55:51 +09:00
Zach Mathis (田中ザック) fbb84dc998 Merge pull request #391 from Shirofune-Security/feat/369-missing-audit-controls
Document six native audit controls in changelogs
2026-09-19 14:35:41 +09:00
田中ザック Isaac Mathis 27957e859f Merge pull request #392 from Shirofune-Security/fix/365-configuration-results
Verify configuration outcomes with dry-run and recovery journaling
2026-09-19 14:06:12 +09:00
Zach Mathis (田中ザック) 6fd86f21ce Merge pull request #389 from Shirofune-Security/fix/363-domain-ntlm-audit
Enable full domain NTLM auditing only on domain controllers
2026-09-19 13:13:01 +09:00
Shirofune-Security 966aa21a46 Enumerate corpus rules explicitly in PowerShell 5.1 fixtures 2026-09-19 04:40:13 +09:00
Shirofune-Security be3a354f18 Separate SMB policy verification from runtime activation 2026-09-19 04:39:55 +09:00
Shirofune-Security 70e6207a84 Match rule channel patterns consistently against concrete sources 2026-09-19 04:37:02 +09:00
Shirofune-Security 24a77ee9ce Read audit precedence provenance from documented RSoP schemas 2026-09-19 02:35:06 +09:00