Commit Graph
29 Commits
Author SHA1 Message Date
田中ザック Isaac Mathis f1ed90d189 Create new disabled, unlinked GPOs from reviewed native audit backups (#427)
* Add guarded creation of disabled unlinked audit GPOs

* Reference PR 427 in GPO creation changelogs

* Accept only inert native ADM placeholders and fix PS5 JSON fixture

* Preserve fractional UTC strings in existing probe fixtures
2026-09-20 22:53:00 +09:00
田中ザック Isaac Mathis f1c1f74166 Guard AD CS audit configuration and collect native request evidence (#421)
* Add guarded native CA auditing and disposable request evidence

* Link AD CS changelog to PR 421

* Retain primary native CA failure before cleanup diagnostics

* Normalize native CA certificate hashes and record pending feature removal

* Emit bounded disposable CA request matching diagnostics

* Match observed version 1 CA request events with exact pending disposition
2026-09-20 19:34:03 +09:00
田中ザック Isaac Mathis 83b2ddd526 Support validated custom audit profile files through the shared engine (#416)
* Support validated operator-owned advanced audit profile files

* Reject lenient custom profile JSON and protect report output aliases

* Link custom audit profile changelog to PR 416

* Make custom JSON rejection fixtures portable across PowerShell versions
2026-09-20 18:09:52 +09:00
田中ザック Isaac Mathis 7719063f6f Add source-specific Windows audit privilege and integrity controls (#412)
* Add opt-in source-profile audit integrity controls

* Reference PR 412 in audit-integrity changelogs
2026-09-20 14:03:18 +09:00
Shirofune-Security f1b5be8bf2 Merge reviewed PowerShell transcription into WEF integration 2026-09-19 11:45:59 +09:00
Shirofune-Security 9a69600947 Add opt-in native WEF source and collector subscription controls 2026-09-19 07:23:47 +09:00
Shirofune-Security 89253fa812 Add opt-in Windows PowerShell transcription for CIS Level 2 2026-09-19 07:09:33 +09:00
Shirofune-Security 9d993a2a7e Merge branch 'feat/367-native-channel-access' into feat/371-ad-object-sacl
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 06:54:08 +09:00
Shirofune-Security 0229348963 Merge branch 'feat/381-applocker-readiness' into feat/367-native-channel-access
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 06:53:25 +09:00
Shirofune-Security c338dae12e Add opt-in AD directory object SACL profiles and recovery (issue #371) 2026-09-19 05:42:25 +09:00
Shirofune-Security 1bf6bc26b3 Add opt-in native WEF channel settings and preserved CAPI2 read access 2026-09-19 05:36:29 +09:00
Shirofune-Security 80db17891d Add opt-in WMI namespace audit SACL workflow 2026-09-19 05:30:12 +09:00
Shirofune-Security f2325b5e0b Merge commit 'be3a354' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:50:15 +09:00
Shirofune-Security 3507734538 Merge commit '88c84fa' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:49:40 +09:00
Shirofune-Security 157fb56bee Merge commit 'a10e1d6' into HEAD
# Conflicts:
#	scripts/Configuration.ps1
2026-09-19 04:48:19 +09:00
Shirofune-Security be3a354f18 Separate SMB policy verification from runtime activation 2026-09-19 04:39:55 +09:00
Shirofune-Security 24a77ee9ce Read audit precedence provenance from documented RSoP schemas 2026-09-19 02:35:06 +09:00
Shirofune-Security 2ea509700b Add version-aware opt-in SMB audit policy controls 2026-09-19 02:33:13 +09:00
Shirofune-Security d29ffdd01b Unify event-log size and retention profiles with verified configuration 2026-09-19 02:30:41 +09:00
Shirofune-Security fbe8f95117 Add opt-in native firewall text logging controls 2026-09-19 02:24:38 +09:00
Shirofune-Security 1a12220b51 Verify advanced audit precedence before applying subcategories 2026-09-19 02:21:55 +09:00
Shirofune-Security 7d2117ebba Fix audit applicability, NTLM value types, and native exit verification 2026-09-19 00:36:38 +09:00
Shirofune-Security 4c2193964e Keep deferred configuration callbacks in script scope on PowerShell 5.1 2026-09-18 22:13:58 +09:00
Shirofune-Security fa5141755b Reject unsupported dry runs and preserve freshly observed NTLM restrictions 2026-09-18 22:10:17 +09:00
Shirofune-Security d96f04dcef Integrate profile masks metadata and dry runs with verified execution 2026-09-18 22:05:25 +09:00
Shirofune-Security d480db5a76 Integrate versioned audit profiles with verified configuration
# Conflicts:
#	.github/workflows/release.yml
#	WELA.ps1
2026-09-18 22:00:30 +09:00
Shirofune-Security f5a19a45fd Integrate verified configuration results for review
# Conflicts:
#	WELA.ps1
2026-09-18 21:56:07 +09:00
Shirofune-Security eb3232faf5 Read audit masks through Windows API and preserve missing registry parents 2026-09-18 21:53:44 +09:00
Shirofune-Security 1ae4930438 Verify configure changes and propagate per-control failures 2026-09-18 21:48:27 +09:00