Commit Graph
307 Commits
Author SHA1 Message Date
Shirofune-Security f180ca72ae Merge latest dev before registry probe merge 2026-09-22 18:16:38 +09:00
Shirofune-Security 92f2be18de Merge latest dev before process command-line merge 2026-09-22 18:15:57 +09:00
Shirofune-Security d20be8ff51 Merge latest dev before registry probe merge 2026-09-22 18:14:25 +09:00
Shirofune-Security f73c96e44c Merge latest dev before process command-line merge 2026-09-22 18:14:15 +09:00
Shirofune-Security c56a6f14d6 Merge latest dev before PowerShell logging merge 2026-09-22 18:14:07 +09:00
Shirofune-Security 3db5d73180 Merge latest dev before process command-line integration 2026-09-22 18:13:26 +09:00
Shirofune-Security dee12fa965 Merge latest dev before PowerShell logging integration 2026-09-22 18:13:17 +09:00
Shirofune-Security 7966529cc5 Merge latest dev before WMI descendants integration 2026-09-22 18:13:07 +09:00
Shirofune-Security ea8b4f152c Merge latest dev before registry probe integration 2026-09-22 18:12:57 +09:00
Shirofune-Security 53d9eddb86 Preserve literal registry types when projecting logging capacity 2026-09-22 15:44:16 +09:00
Shirofune-Security 32cfb460a2 Accept native UInt16 CIM domain roles in registry probe preflight 2026-09-22 15:32:00 +09:00
Shirofune-Security fb0a424da8 Reject scoped logging changes that overflow bounded policy inventories 2026-09-22 15:19:20 +09:00
Shirofune-Security 66162232b6 Integrate reviewed logging and recovery base for WMI tree safeguards 2026-09-22 15:08:52 +09:00
Shirofune-Security 81c01330b8 Merge final reviewed dev sources and preserve literal CLI arguments 2026-09-22 15:08:26 +09:00
Shirofune-Security 7e1b076254 Integrate approved dev command and recovery additions 2026-09-22 15:07:44 +09:00
Shirofune-Security 2b992f06e6 Integrate approved dev command and recovery additions 2026-09-22 15:07:20 +09:00
Shirofune-Security bfa286bf7d Integrate reviewed WMI recovery with combined dev auditing batch 2026-09-22 15:06:51 +09:00
Shirofune-Security e584345df3 Integrate approved native recovery PRs before dev merge 2026-09-22 15:05:40 +09:00
Shirofune-Security 2b270042e7 Stack leaf-file recovery and preserve scoped NTLM dry-run integration 2026-09-22 15:03:17 +09:00
Shirofune-Security 3c47442634 Stack named registry recovery on reviewed logging integration 2026-09-22 15:01:03 +09:00
Shirofune-Security 16f9e69844 Stack native DNS probe on intended-reader recovery and approved dev 2026-09-22 14:59:41 +09:00
Shirofune-Security d72bf939a7 Reserve registry probe capacity and isolate exact-value cleanup 2026-09-22 14:59:21 +09:00
Shirofune-Security d5de556f74 Retain partial WMI tree observations after a parent write 2026-09-22 14:58:07 +09:00
Shirofune-Security 4ab4c275a5 Preserve positional bindings and propagate native fixture failures 2026-09-22 14:57:47 +09:00
Shirofune-Security 1dfd3a92b9 Stack intended-reader EVTX recovery on the approved native auditing batch 2026-09-22 14:56:09 +09:00
Shirofune-Security 9575c8204d Add fixed current-user registry value audit probe 2026-09-22 14:55:12 +09:00
Shirofune-Security 488d179f09 Count the root in bounded WMI descriptor evidence 2026-09-22 14:49:07 +09:00
Shirofune-Security adaf3f9681 Retain actual process identity for scoped logging and native attribution 2026-09-22 14:48:45 +09:00
Shirofune-Security e34ede7c38 Require exact native inherited and protected subtree outcomes 2026-09-22 14:46:26 +09:00
Shirofune-Security 8546d319eb Reject unexplained descendant changes and unrelated WMI command arguments 2026-09-22 14:45:06 +09:00
Shirofune-Security e419b073fe Document scoped PowerShell controls and align native evidence boundaries 2026-09-22 14:43:40 +09:00
Shirofune-Security ab45d03f15 Add reviewed removal of one proven parent-only WMI audit ACE 2026-09-22 14:43:33 +09:00
Shirofune-Security ddcdd8e2b8 Document bounded WMI tree guarantees and record native protection behavior 2026-09-22 14:40:25 +09:00
Shirofune-Security 3f613ea19c Add scoped Windows PowerShell logging policy and native validation 2026-09-22 14:37:38 +09:00
Shirofune-Security 036f51886a Exercise descendant drift and use supported workflow shell dispatch 2026-09-22 14:36:48 +09:00
Shirofune-Security aa4630dda9 Add scoped native 4688 command-line policy configuration 2026-09-22 14:34:05 +09:00
Shirofune-Security ea184e5e95 Guard WMI inheritance with bounded descendant observations 2026-09-22 14:33:54 +09:00
Shirofune-Security b556b82ebc Integrate native DNS probe with current dev commands and release guides 2026-09-22 14:25:44 +09:00
Shirofune-Security 3ba8a45d80 Integrate current native auditing commands with transcript verification 2026-09-22 14:24:29 +09:00
Shirofune-Security 0ef22f20fa Merge dev and preserve leaf-file SACL recovery integration 2026-09-22 14:24:24 +09:00
Shirofune-Security 4598bb36f7 Integrate current dev with intended-reader EVTX verification 2026-09-22 14:24:04 +09:00
Shirofune-Security 397dfbf006 Merge dev and preserve named registry recovery integration 2026-09-22 14:23:55 +09:00
Shirofune-Security 7ef29df61f Integrate reviewed native auditing batch and preserve 4703 validation 2026-09-22 14:23:44 +09:00
Shirofune-Security 2fef35da23 Integrate reviewed native auditing commands with OneSettings validation 2026-09-22 14:23:33 +09:00
Shirofune-Security 005b249c3b Integrate reviewed filesystem and WEF query changes with scoped NTLM auditing 2026-09-22 14:23:24 +09:00
Shirofune-Security 34b7a775c4 Merge dev and preserve filesystem lifecycle and WEF query changes 2026-09-22 14:23:10 +09:00
Shirofune-Security 4d34305097 test: bind token task metadata to the native publisher XML namespace 2026-09-22 12:44:51 +09:00
Shirofune-Security 10c50b9a74 test: corroborate runtime token task and measure full native verification 2026-09-22 12:43:31 +09:00
Shirofune-Security b5e244bb68 test: retain exact native publisher task metadata for attribution diagnosis 2026-09-22 12:40:04 +09:00
Shirofune-Security 3fb0f8aa6c fix: decode native WEF XML independently of property count 2026-09-22 12:37:37 +09:00