Shirofune-Security
92f2be18de
Merge latest dev before process command-line merge
2026-09-22 18:15:57 +09:00
Shirofune-Security
3f613ea19c
Add scoped Windows PowerShell logging policy and native validation
2026-09-22 14:37:38 +09:00
Shirofune-Security
aa4630dda9
Add scoped native 4688 command-line policy configuration
2026-09-22 14:34:05 +09:00
Shirofune-Security
b162c4e598
feat: configure selected incoming and domain NTLM audit policies
2026-09-22 12:03:11 +09:00
Shirofune-Security
0777a5d0f8
Add scoped outgoing NTLM audit configuration with native acceptance
2026-09-22 10:09:37 +09:00
田中ザック Isaac Mathis
b7e649185b
Gate conditional IPsec auditing on native prerequisite evidence ( #439 )
...
* Gate conditional stronger-profile IPsec auditing on native evidence
* Use supported literal shells in native prerequisite matrix
* Retain native IPsec fixture diagnostics and allow inactive rule omission
* Expose exact native rule fields when prerequisite classification fails
* Recognize native inactive IPsec rules without granting applicability
* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
田中ザック Isaac Mathis
f1ed90d189
Create new disabled, unlinked GPOs from reviewed native audit backups ( #427 )
...
* Add guarded creation of disabled unlinked audit GPOs
* Reference PR 427 in GPO creation changelogs
* Accept only inert native ADM placeholders and fix PS5 JSON fixture
* Preserve fractional UTC strings in existing probe fixtures
2026-09-20 22:53:00 +09:00
田中ザック Isaac Mathis
f1c1f74166
Guard AD CS audit configuration and collect native request evidence ( #421 )
...
* Add guarded native CA auditing and disposable request evidence
* Link AD CS changelog to PR 421
* Retain primary native CA failure before cleanup diagnostics
* Normalize native CA certificate hashes and record pending feature removal
* Emit bounded disposable CA request matching diagnostics
* Match observed version 1 CA request events with exact pending disposition
2026-09-20 19:34:03 +09:00
田中ザック Isaac Mathis
83b2ddd526
Support validated custom audit profile files through the shared engine ( #416 )
...
* Support validated operator-owned advanced audit profile files
* Reject lenient custom profile JSON and protect report output aliases
* Link custom audit profile changelog to PR 416
* Make custom JSON rejection fixtures portable across PowerShell versions
2026-09-20 18:09:52 +09:00
田中ザック Isaac Mathis
7719063f6f
Add source-specific Windows audit privilege and integrity controls ( #412 )
...
* Add opt-in source-profile audit integrity controls
* Reference PR 412 in audit-integrity changelogs
2026-09-20 14:03:18 +09:00
Shirofune-Security
f1b5be8bf2
Merge reviewed PowerShell transcription into WEF integration
2026-09-19 11:45:59 +09:00
Shirofune-Security
9a69600947
Add opt-in native WEF source and collector subscription controls
2026-09-19 07:23:47 +09:00
Shirofune-Security
89253fa812
Add opt-in Windows PowerShell transcription for CIS Level 2
2026-09-19 07:09:33 +09:00
Shirofune-Security
9d993a2a7e
Merge branch 'feat/367-native-channel-access' into feat/371-ad-object-sacl
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# WELA.ps1
# scripts/Configuration.ps1
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 06:54:08 +09:00
Shirofune-Security
0229348963
Merge branch 'feat/381-applocker-readiness' into feat/367-native-channel-access
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# WELA.ps1
# scripts/Configuration.ps1
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 06:53:25 +09:00
Shirofune-Security
c338dae12e
Add opt-in AD directory object SACL profiles and recovery (issue #371 )
2026-09-19 05:42:25 +09:00
Shirofune-Security
1bf6bc26b3
Add opt-in native WEF channel settings and preserved CAPI2 read access
2026-09-19 05:36:29 +09:00
Shirofune-Security
80db17891d
Add opt-in WMI namespace audit SACL workflow
2026-09-19 05:30:12 +09:00
Shirofune-Security
f2325b5e0b
Merge commit 'be3a354' into HEAD
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# WELA.ps1
# scripts/Configuration.ps1
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 04:50:15 +09:00
Shirofune-Security
3507734538
Merge commit '88c84fa' into HEAD
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# WELA.ps1
# scripts/Configuration.ps1
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 04:49:40 +09:00
Shirofune-Security
157fb56bee
Merge commit 'a10e1d6' into HEAD
...
# Conflicts:
# scripts/Configuration.ps1
2026-09-19 04:48:19 +09:00
Shirofune-Security
be3a354f18
Separate SMB policy verification from runtime activation
2026-09-19 04:39:55 +09:00
Shirofune-Security
24a77ee9ce
Read audit precedence provenance from documented RSoP schemas
2026-09-19 02:35:06 +09:00
Shirofune-Security
2ea509700b
Add version-aware opt-in SMB audit policy controls
2026-09-19 02:33:13 +09:00
Shirofune-Security
d29ffdd01b
Unify event-log size and retention profiles with verified configuration
2026-09-19 02:30:41 +09:00
Shirofune-Security
fbe8f95117
Add opt-in native firewall text logging controls
2026-09-19 02:24:38 +09:00
Shirofune-Security
1a12220b51
Verify advanced audit precedence before applying subcategories
2026-09-19 02:21:55 +09:00
Shirofune-Security
7d2117ebba
Fix audit applicability, NTLM value types, and native exit verification
2026-09-19 00:36:38 +09:00
Shirofune-Security
4c2193964e
Keep deferred configuration callbacks in script scope on PowerShell 5.1
2026-09-18 22:13:58 +09:00
Shirofune-Security
fa5141755b
Reject unsupported dry runs and preserve freshly observed NTLM restrictions
2026-09-18 22:10:17 +09:00
Shirofune-Security
d96f04dcef
Integrate profile masks metadata and dry runs with verified execution
2026-09-18 22:05:25 +09:00
Shirofune-Security
d480db5a76
Integrate versioned audit profiles with verified configuration
...
# Conflicts:
# .github/workflows/release.yml
# WELA.ps1
2026-09-18 22:00:30 +09:00
Shirofune-Security
f5a19a45fd
Integrate verified configuration results for review
...
# Conflicts:
# WELA.ps1
2026-09-18 21:56:07 +09:00
Shirofune-Security
eb3232faf5
Read audit masks through Windows API and preserve missing registry parents
2026-09-18 21:53:44 +09:00
Shirofune-Security
1ae4930438
Verify configure changes and propagate per-control failures
2026-09-18 21:48:27 +09:00