田中ザック Isaac Mathis
6d228fedef
Add a native local failed-logon audit probe ( #444 )
...
* Add native local nonexistent-account failed-logon probe
* Match actual MSV1 local authentication event package
* Refuse coerced identity and authentication receipt fields
* Preserve explicit UTC DateTime receipts on older PowerShell7
* Reject unknown failed-logon probe options before dispatch
2026-09-21 22:13:20 +09:00
田中ザック Isaac Mathis
203fdfc942
Add reviewed scoped collector firewall ingress creation ( #442 )
...
* Add reviewed scoped collector firewall ingress creation
* Avoid Windows Clear-Item alias in native ingress fixture
* Handle native nullable package scope and retain bounded filter evidence
* Match native firewall network spelling in collector prerequisites
2026-09-21 18:19:30 +09:00
田中ザック Isaac Mathis
9d03a19082
Activate native SMB audit runtime switches explicitly ( #441 )
...
* Add explicit native SMB runtime audit activation
* Select explicit PowerShell workflow shells and link PR changelog
* Clear expected refusal child exit codes after assertions
* Retain native SMB command provenance in capability diagnostics
* Bind SMB command guards to observed native CDXML module identities
2026-09-21 18:09:10 +09:00
田中ザック Isaac Mathis
b4fb77da02
Review and apply existing WEC subscription enable/disable ( #440 )
...
* Add reviewed existing WEC subscription state transitions
* Validate WEC destination and retain failed activation state
2026-09-21 17:54:55 +09:00
田中ザック Isaac Mathis
b7e649185b
Gate conditional IPsec auditing on native prerequisite evidence ( #439 )
...
* Gate conditional stronger-profile IPsec auditing on native evidence
* Use supported literal shells in native prerequisite matrix
* Retain native IPsec fixture diagnostics and allow inactive rule omission
* Expose exact native rule fields when prerequisite classification fails
* Recognize native inactive IPsec rules without granting applicability
* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
田中ザック Isaac Mathis
7cd2eb9dbf
Use precise native UTC for WMI probe event intervals ( #438 )
2026-09-21 17:30:16 +09:00
田中ザック Isaac Mathis
fd7a7924aa
Verify actual current-token access to built-in event channels ( #432 )
...
* Add actual current-token native channel read evidence
* Use supported workflow shells and link channel-read changelogs
* Handle real event exceptions and bind loaded token helper to source
* Capture query-token interval after evidence and metadata preparation
* Retain native child process exit evidence across PowerShell engines
* Bound native reader fixture pipe draining and child termination
* Preserve native errors from attributed channel query statuses
2026-09-21 09:18:46 +09:00
田中ザック Isaac Mathis
c6da22a2ad
Resume a reviewed pending AD CS auditing restart ( #431 )
...
* Add reviewed recovery for a pending AD CS auditing restart
* Link pending CA restart recovery changelogs to PR 431
2026-09-21 09:16:39 +09:00
田中ザック Isaac Mathis
2fd37d0318
Measure bounded native event delivery and verify exact EVTX samples ( #430 )
...
* Add bounded local delivery measurement and exact EVTX samples
* Link delivery measurement changelog to PR 430
* Reject evidence aliases before Windows path normalization
* Use PowerShell 5.1-compatible record IDs and bound fixture cleanup
* Revalidate the native EVTX artifact before recording final evidence
* Require exact observed local computer identities for sampled events
* Clarify provider scope within shared built-in event channels
* Preserve mixed XML payload ordering in EVTX sample verification
* Bound ordered event XML comparisons for nested UserData
* Dispose observer wait handle when bookmark creation fails
2026-09-21 09:14:48 +09:00
田中ザック Isaac Mathis
bcd4e9717e
Verify reviewed descendant SACL propagation and preservation ( #429 )
...
* Verify reviewed descendant SACL propagation and preservation
* Reference descendant SACL PR429 in release notes
* Prepare protected disposable SACL fixtures through native handles
* Use read-control handles for disposable native SACL protection
2026-09-21 09:12:56 +09:00
田中ザック Isaac Mathis
b84b97b358
Collect local WMI namespace audit evidence with a fixed read probe ( #428 )
...
* Collect bounded local WMI namespace access evidence
* Reference PR428 and preserve UTC worker query timestamps
* Observe equivalent runtime self tokens without reverting caller context
* Test native token equivalence against restricted caller changes
* Diagnose native token differences and package WMI probe guidance
* Limit WMI connections to the explicitly scoped security privilege
* Document verified native WMI events and privilege preservation
* Require an already-running WMI service before namespace reads
2026-09-21 09:08:20 +09:00
田中ザック Isaac Mathis
f1ed90d189
Create new disabled, unlinked GPOs from reviewed native audit backups ( #427 )
...
* Add guarded creation of disabled unlinked audit GPOs
* Reference PR 427 in GPO creation changelogs
* Accept only inert native ADM placeholders and fix PS5 JSON fixture
* Preserve fractional UTC strings in existing probe fixtures
2026-09-20 22:53:00 +09:00
田中ザック Isaac Mathis
610d27e8ff
Review and apply query updates to existing disabled WEC subscriptions ( #426 )
...
* Add reviewed existing-only updates for disabled WEC subscriptions
* Pin loaded updater and flush locked recovery artifacts; reference PR 426
* Compare formatted WEC queries semantically before pinning raw native state
* Read native WEC subscription XML with bounded explicit Unicode pipes
* Use explicit Unicode reads for reviewed update and native cleanup
* Keep timestamp strings exact in inherited native evidence fixtures
* Reject XML-invalid descriptions before any native save
* Decode native WEC XML BOMs without unsupported Unicode switch
* Describe native XML byte decoding accurately
* Reference System.Xml explicitly when compiling under Windows PowerShell
2026-09-20 22:51:01 +09:00
田中ザック Isaac Mathis
c12e49213f
Add guarded DNS analytical logging and stopped-trace archives ( #425 )
...
* Add guarded DNS analytical channel lifecycle and trace archives
* Link DNS analytical changelogs to PR425
* Fix native DNS archive inspection and guard artifact paths
* Diagnose exact DNS event envelope from stopped native trace
* Verify DNS ETL event provenance without inventing XML channel
* Preserve exact UTC timestamp strings in shared evidence fixtures
2026-09-20 22:49:52 +09:00
田中ザック Isaac Mathis
913b1dfaee
Add typed native WEC runtime observations ( #424 )
...
* Observe typed native WEC subscription runtime status
* Link typed WEC runtime changelog to PR 424
* Pass a native null source for subscription runtime queries
* Ignore unused count storage for native null WEC variants
* Keep unavailable WEC source inventories unknown and diagnose native XML reads
* Read native WEC subscription XML with bounded explicit Unicode pipes
* Use bounded Unicode subscription reads in runtime observations and cleanup
* Decode native WEC XML BOMs without unsupported Unicode switch
* Describe strict native WEC XML byte decoding
* Reference System.Xml explicitly when compiling under Windows PowerShell
* Regenerate website changelog snapshots with their proper headers
2026-09-20 22:48:32 +09:00
田中ザック Isaac Mathis
5ba53fbcfb
Validate native AppLocker EXE event generation with an opt-in probe ( #423 )
...
* Add native AppLocker EXE event validation probe
* Reference PR 423 in changelogs
* Isolate AppLocker native fixture and preserve prerequisite diagnostics
* Report an integer zero for an empty AppLocker policy
* Prepare disposable AppLocker probe policy without bypassing production importer guards
* Retain bounded native AppLocker channel diagnostics on probe failure
* Require native policy application before the disposable AppLocker probe
* Preserve exact timestamp strings in native evidence fixtures
* Record actual runner session and AppLocker publication diagnostics
* Activate and restore the native policy converter on disposable AppLocker hosts
* Compare native task freshness without guessing its timestamp timezone
* Verify effective policy and borrowed converter inactivity during fixture cleanup
* Track the actual native policy-converter task instance instead of cached timestamps
2026-09-20 22:46:56 +09:00
田中ザック Isaac Mathis
ff0e5c1890
Apply reviewed SACL plans to explicitly selected local targets ( #422 )
...
* Add reviewed configuration for selected native SACL targets
* Link selected SACL changelog to PR 422
* Identify native full-descriptor read failures without partial fallback
* Fix diagnostic variable scope in native C# helper
* Read explicit descriptor sections and retain observation scope
2026-09-20 19:36:05 +09:00
田中ザック Isaac Mathis
f1c1f74166
Guard AD CS audit configuration and collect native request evidence ( #421 )
...
* Add guarded native CA auditing and disposable request evidence
* Link AD CS changelog to PR 421
* Retain primary native CA failure before cleanup diagnostics
* Normalize native CA certificate hashes and record pending feature removal
* Emit bounded disposable CA request matching diagnostics
* Match observed version 1 CA request events with exact pending disposition
2026-09-20 19:34:03 +09:00
田中ザック Isaac Mathis
38a392f3d6
Export and verify recovery of native probe events from EVTX ( #420 )
...
* Export and recover exact native probe events from EVTX
* Link changelog to PR 420
* Make EVTX duplicate JSON fixture portable to PowerShell 5.1
2026-09-20 19:33:20 +09:00
田中ザック Isaac Mathis
60006531be
Restore selected audit changes from reviewed recovery evidence ( #419 )
...
* Add guarded restoration of selected completed audit writes
* Link changelog to PR 419
* Read recovery host name from Windows instead of environment overrides
* Require local fixed-drive recovery output paths
2026-09-20 19:30:49 +09:00
田中ザック Isaac Mathis
e5557df038
Verify native probe arrival in the local WEF collector ( #418 )
...
* Verify native probe presence in the local WEF collector
* Link WEF arrival changelog to PR 418
* Make duplicate JSON fixture independent of PowerShell formatting
2026-09-20 19:26:57 +09:00
田中ザック Isaac Mathis
f21a9f30e4
Add transparent configuration and native rule readiness scores ( #417 )
...
* Add transparent native audit compliance and evidence readiness scores
* Link transparent audit scoring changelog to PR 417
* Resolve scoring outputs against the PowerShell filesystem location
2026-09-20 18:15:04 +09:00
田中ザック Isaac Mathis
3a80ef5e67
Add reviewable GPO audit-policy deployment packages ( #415 )
...
* Add reviewable GPO audit-policy deployment components
* Link GPO audit package changelog to PR 415
* Check GPO verification exit code from a real CLI process
2026-09-20 18:13:34 +09:00
田中ザック Isaac Mathis
ec6a6df68a
Export native audit profiles for reviewed Intune client policies ( #414 )
...
* Add offline Intune Audit CSP exports from shared client profiles
* Link Intune audit export changelog to PR 414
2026-09-20 18:10:52 +09:00
田中ザック Isaac Mathis
83b2ddd526
Support validated custom audit profile files through the shared engine ( #416 )
...
* Support validated operator-owned advanced audit profile files
* Reject lenient custom profile JSON and protect report output aliases
* Link custom audit profile changelog to PR 416
* Make custom JSON rejection fixtures portable across PowerShell versions
2026-09-20 18:09:52 +09:00
田中ザック Isaac Mathis
4431533535
Collect native 4688 validation components with a fixed benign probe ( #413 )
...
* Add opt-in native 4688 validation component collector
* Link native validation changelog to PR 413
* Reject contradictory native probe context observations
* Resolve probe artifact paths against the PowerShell location
2026-09-20 18:08:34 +09:00
田中ザック Isaac Mathis
7719063f6f
Add source-specific Windows audit privilege and integrity controls ( #412 )
...
* Add opt-in source-profile audit integrity controls
* Reference PR 412 in audit-integrity changelogs
2026-09-20 14:03:18 +09:00
田中ザック Isaac Mathis
55cc427c61
Report native log retention and collection health evidence ( #410 )
...
* Add read-only native retention and collection health evidence reports
* Verify retention HTML evidence across PowerShell JSON serializers
* Reference PR 410 in retention changelogs
* Preserve previous-report arrays on Windows PowerShell and test both server releases
2026-09-20 14:01:43 +09:00
田中ザック Isaac Mathis
14ac8667d4
Gate historical controls and require evidence for Windows defaults ( #409 )
...
* Gate historical controls and require provenance for Windows defaults
* Bind default evidence to UTC provenance and native architecture
* Reference PR 409 in applicability changelogs
2026-09-20 14:00:10 +09:00
田中ザック Isaac Mathis
d35b1374d0
Add opt-in native DNS and provider audit packs ( #411 )
...
* Add selective native provider packs with pinned rule and schema evidence
* Reference PR 411 in provider-pack changelogs
* Fix provider pack service reader export and CI exit propagation
2026-09-20 13:58:49 +09:00
田中ザック Isaac Mathis
35aca8f494
Add OneSettings auditing and Security warning controls ( #408 )
...
* Add explicit OneSettings auditing and Security warning controls
* Reference PR 408 in notification changelogs
* Handle expected child CLI failure under Windows PowerShell 5.1
* Block dependent Privacy channel changes when OneSettings policy drifts
* Recheck notification producer prerequisites at channel write boundaries
2026-09-20 13:55:24 +09:00
田中ザック Isaac Mathis
e4a6f67ab3
Merge pull request #407 from Shirofune-Security/feat/387-native-rule-eligibility
...
Report native rule eligibility with pinned inputs and evidence gates
2026-09-20 08:47:15 +09:00
田中ザック Isaac Mathis
c34fcc2774
Merge pull request #406 from Shirofune-Security/feat/368-wef-deployment
...
Add opt-in native WEF source and collector provisioning
2026-09-20 08:42:42 +09:00
田中ザック Isaac Mathis
39c82dcf00
Merge pull request #405 from Shirofune-Security/feat/376-powershell-transcription
...
Add opt-in Windows PowerShell transcription for CIS Level 2
2026-09-20 08:39:53 +09:00
田中ザック Isaac Mathis
3172ea1101
Merge pull request #404 from Shirofune-Security/feat/383-ldap-diagnostics
...
Make LDAP 1644 diagnostics explicit and preserve existing DC settings
2026-09-20 08:39:13 +09:00
田中ザック Isaac Mathis
72704d4780
Merge pull request #403 from Shirofune-Security/fix/380-audit-catalog-mappings
...
Correct token audit GUID and validate catalog mapping uncertainty
2026-09-20 08:36:22 +09:00
田中ザック Isaac Mathis
3f6fe32ce7
Merge pull request #402 from Shirofune-Security/feat/371-ad-object-sacl
...
Add opt-in AD object and Configuration partition audit SACLs
2026-09-19 19:49:50 +09:00
田中ザック Isaac Mathis
5665fd2f0f
Merge pull request #401 from Shirofune-Security/feat/367-native-channel-access
...
Configure native WEF channel prerequisites and CAPI2 read access
2026-09-19 19:49:07 +09:00
田中ザック Isaac Mathis
f0444aedef
Merge pull request #400 from Shirofune-Security/feat/381-applocker-readiness
...
Assess native AppLocker readiness and guard audit-only imports
2026-09-19 19:48:26 +09:00
田中ザック Isaac Mathis
423277428a
Merge pull request #399 from Shirofune-Security/feat/372-wmi-namespace-auditing
...
Add opt-in WMI namespace audit SACL configuration
2026-09-19 19:45:11 +09:00
田中ザック Isaac Mathis
ded0b9c375
Merge pull request #398 from Shirofune-Security/feat/373-targeted-sacl-planning
...
Plan targeted SACL prerequisites alongside audit profiles
2026-09-19 19:41:51 +09:00
Shirofune-Security
ab70ec740a
Integrate completed native logging stack into rule eligibility
2026-09-19 11:50:48 +09:00
Shirofune-Security
9815e609d8
Integrate reviewed catalog and LDAP commands into WEF branch
2026-09-19 11:48:11 +09:00
Shirofune-Security
8834dba4e6
Merge commit '45b6be91a8a35e1f08f6138fff70e0c6fafc58d1' into feat/387-native-rule-eligibility
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# WELA.ps1
# tests/AuditProfileOutput.Tests.ps1
# tests/NativeProviders.Tests.ps1
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 11:46:07 +09:00
Shirofune-Security
f1b5be8bf2
Merge reviewed PowerShell transcription into WEF integration
2026-09-19 11:45:59 +09:00
Shirofune-Security
03265a0940
Merge commit '26d7f8b09df915c0f2b3dc837112f5f963b437a7' into feat/376-powershell-transcription
2026-09-19 11:45:34 +09:00
Shirofune-Security
273af05e36
Merge reviewed LDAP diagnostics into transcription branch
2026-09-19 11:45:34 +09:00
Shirofune-Security
26d7f8b09d
Merge remote-tracking branch 'origin/dev' into feat/383-ldap-diagnostics
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 11:45:13 +09:00
Shirofune-Security
852de965a6
Merge commit 'f9303313148c80ad1d26376b943459d38598547b' into feat/387-native-rule-eligibility
...
# Conflicts:
# CHANGELOG-Japanese.md
# CHANGELOG.md
# WELA.ps1
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-19 11:45:05 +09:00
Shirofune-Security
2df9715dc1
Use explicit canonical framing for portable metadata hashes
2026-09-19 07:39:47 +09:00