Shirofune-Security
|
d5de556f74
|
Retain partial WMI tree observations after a parent write
|
2026-09-22 14:58:07 +09:00 |
|
Shirofune-Security
|
ddcdd8e2b8
|
Document bounded WMI tree guarantees and record native protection behavior
|
2026-09-22 14:40:25 +09:00 |
|
Shirofune-Security
|
ea184e5e95
|
Guard WMI inheritance with bounded descendant observations
|
2026-09-22 14:33:54 +09:00 |
|
田中ザック Isaac Mathis
|
b84b97b358
|
Collect local WMI namespace audit evidence with a fixed read probe (#428)
* Collect bounded local WMI namespace access evidence
* Reference PR428 and preserve UTC worker query timestamps
* Observe equivalent runtime self tokens without reverting caller context
* Test native token equivalence against restricted caller changes
* Diagnose native token differences and package WMI probe guidance
* Limit WMI connections to the explicitly scoped security privilege
* Document verified native WMI events and privilege preservation
* Require an already-running WMI service before namespace reads
|
2026-09-21 09:08:20 +09:00 |
|
Shirofune-Security
|
d7f710c9ad
|
Restrict native WMI writes to SACL and verify privilege cleanup
|
2026-09-19 05:41:08 +09:00 |
|
Shirofune-Security
|
80db17891d
|
Add opt-in WMI namespace audit SACL workflow
|
2026-09-19 05:30:12 +09:00 |
|