Commit Graph
902 Commits
Author SHA1 Message Date
Shirofune-Security 7d2117ebba Fix audit applicability, NTLM value types, and native exit verification 2026-09-19 00:36:38 +09:00
Shirofune-Security 71215ab498 Merge main and preserve NTLM output regression coverage 2026-09-19 00:28:55 +09:00
Zach Mathis (田中ザック) 6fd86f21ce Merge pull request #389 from Shirofune-Security/fix/363-domain-ntlm-audit
Enable full domain NTLM auditing only on domain controllers
2026-09-19 13:13:01 +09:00
Shirofune-Security e574dcde60 Document verified configuration and recovery features in changelogs 2026-09-19 00:23:17 +09:00
Shirofune-Security bf69494bd9 Report configuration-only audit states without rule coverage inference 2026-09-18 22:59:25 +09:00
Shirofune-Security 571f9ff51f Document domain NTLM audit correction in changelogs 2026-09-18 22:53:31 +09:00
Shirofune-Security 9bd56a0840 Scope integration test doubles alongside script-local helpers 2026-09-18 22:16:11 +09:00
Shirofune-Security 4c2193964e Keep deferred configuration callbacks in script scope on PowerShell 5.1 2026-09-18 22:13:58 +09:00
Shirofune-Security 595f123327 Test unsupported dry-run rejection and NTLM policy races safely 2026-09-18 22:12:30 +09:00
Shirofune-Security 60e6552823 Integrate standalone outgoing NTLM fresh-state safeguards 2026-09-18 22:10:17 +09:00
Shirofune-Security fa5141755b Reject unsupported dry runs and preserve freshly observed NTLM restrictions 2026-09-18 22:10:17 +09:00
Shirofune-Security bc9e098c81 Recheck outgoing NTLM enforcement after confirmation 2026-09-18 22:09:37 +09:00
Shirofune-Security ebd8d14d04 Include read-only Windows CLI profile smoke checks 2026-09-18 22:06:06 +09:00
Shirofune-Security 6392c9bd58 Merge commit 'f4f9c33' into feat/369-missing-audit-controls 2026-09-18 22:05:30 +09:00
Shirofune-Security aa34a0360b Integrate minimum-policy and role-detection safeguards 2026-09-18 22:05:29 +09:00
Shirofune-Security d96f04dcef Integrate profile masks metadata and dry runs with verified execution 2026-09-18 22:05:25 +09:00
Shirofune-Security f4f9c33de2 Exercise real audit CLI export in Windows read-only smoke 2026-09-18 22:05:13 +09:00
Shirofune-Security c7b4e47925 Merge commit 'd3160a2' into feat/369-missing-audit-controls 2026-09-18 22:05:01 +09:00
Shirofune-Security d3160a2033 Preserve additional minimum audit flags and reject unknown CA roles 2026-09-18 22:04:43 +09:00
Shirofune-Security 24dcbdd852 Refresh native audit control evidence assertions for integration 2026-09-18 22:01:53 +09:00
Shirofune-Security 7fc5c0034f Retain profile evidence and prerequisites in integration results
# Conflicts:
#	WELA.ps1
2026-09-18 22:01:04 +09:00
Shirofune-Security a6cef75c12 Verify source attribution and prerequisites in native control results 2026-09-18 22:00:52 +09:00
Shirofune-Security 4432090a6f Merge commit '98d37fb' into feat/369-missing-audit-controls 2026-09-18 22:00:40 +09:00
Shirofune-Security 4a192d7a13 Integrate six missing native audit controls with profile execution 2026-09-18 22:00:30 +09:00
Shirofune-Security d480db5a76 Integrate versioned audit profiles with verified configuration
# Conflicts:
#	.github/workflows/release.yml
#	WELA.ps1
2026-09-18 22:00:30 +09:00
Shirofune-Security 98d37fbf37 Retain policy prerequisites and evidence in apply results 2026-09-18 21:59:59 +09:00
Shirofune-Security 5be186f952 Add six missing native audit subcategories with source-specific masks 2026-09-18 21:58:33 +09:00
Shirofune-Security f2dc28a66b Test composed NTLM policy journaling dry runs and failures 2026-09-18 21:58:06 +09:00
Shirofune-Security e0518b41ed Refresh configuration regression harness for integration 2026-09-18 21:57:42 +09:00
Shirofune-Security f5a19a45fd Integrate verified configuration results for review
# Conflicts:
#	WELA.ps1
2026-09-18 21:56:07 +09:00
Shirofune-Security bf82f2c458 Clear expected child failure codes after regression assertions 2026-09-18 21:56:01 +09:00
Shirofune-Security ee7a0e2216 Unify advanced audit policy audit, plan and configure profiles 2026-09-18 21:54:38 +09:00
Shirofune-Security eb3232faf5 Read audit masks through Windows API and preserve missing registry parents 2026-09-18 21:53:44 +09:00
Shirofune-Security 7979019ef0 Integrate domain NTLM audit role scoping for review
# Conflicts:
#	WELA.ps1
2026-09-18 21:51:44 +09:00
Shirofune-Security 8cb4804334 Integrate outgoing NTLM audit-only behavior for review 2026-09-18 21:51:29 +09:00
Shirofune-Security d51c37258f Use explicit PowerShell shells in regression workflow 2026-09-18 21:49:46 +09:00
Shirofune-Security ca54b5cf74 Use explicit PowerShell shells in regression workflow 2026-09-18 21:49:46 +09:00
Shirofune-Security 36c4b4018f Run configuration checks with explicit PowerShell shells 2026-09-18 21:49:46 +09:00
Shirofune-Security 1ae4930438 Verify configure changes and propagate per-control failures 2026-09-18 21:48:27 +09:00
Shirofune-Security 16d88a6f1e Enable full domain NTLM auditing only on domain controllers 2026-09-18 21:46:28 +09:00
Shirofune-Security ade681ff1b Make outgoing NTLM configuration audit-only by default 2026-09-18 21:46:06 +09:00
Zach Mathis (田中ザック) 8ef938f096 Merge pull request #361 from Shirofune-Security/feat/targeted-object-audit-sacls
Add 'configure-sacl': targeted File System/Registry audit SACLs for detection (no global auditing)
2026-09-14 20:32:50 +09:00
Shirofune-SecurityandClaude Opus 4.8 10c1bcaac7 Address Copilot re-review: %SystemRoot%, Entra SIDs, WOW64 gate, reg-unload check, subcategory-failure, help
- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system
  drive no longer skips every file target.
- Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*.
- WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows.
- reg unload is now checked (retry once, then error) so a failed unload no longer leaves the
  user's NTUSER.DAT mounted under the temp alias while reporting success.
- A failed auditpol subcategory is tracked; the final message warns (instead of claiming success)
  that SACLs for that class will not produce events.
- configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned.

Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with
SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:49:42 +09:00
Shirofune-SecurityandClaude Opus 4.8 570b9565d1 CHANGELOG: note configure additions (#361)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:32:51 +09:00
Shirofune-SecurityandClaude Opus 4.8 35e5329f74 configure: add Process Termination, Detailed File Share, and DC LDAP 1644 logging
Fills the remaining gaps so 'configure' + 'configure-sacl' cover a full detection
baseline out of the box (no manual auditpol/registry needed downstream):
- Detailed Tracking > Process Termination (4689)
- Object Access > Detailed File Share (5145)
- Directory Service LDAP query logging (1644) via NTDS "15 Field Engineering"=5,
  applied only on domain controllers (BloodHound/LDAP recon).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:31:54 +09:00
Shirofune-SecurityandClaude Opus 4.8 d9bef96e0d configure-sacl: use .NET RegistryKey API for SACLs (Get-Acl -Audit is unreliable on the registry)
Live-tested on Windows Server 2019; three bugs fixed found during testing:
- TOKEN_PRIVILEGES had a `long Luid` after a `uint Count`, which is 8-byte aligned on x64
  and inserted padding, so AdjustTokenPrivileges failed with ERROR_NOT_ALL_ASSIGNED and the
  new privilege guard aborted. Split the LUID into LuidLow(uint)+LuidHigh(int) to match the
  native layout.
- Get-Acl/Set-Acl -Audit is unreliable on the registry provider (returns/throws "path does
  not exist" and null). Registry SACLs now use the .NET RegistryKey API
  (OpenSubKey with ReadPermissions,ChangePermissions -> GetAccessControl(Audit) ->
  AddAuditRule -> SetAccessControl), which honors the enabled SeSecurityPrivilege. Absent
  ASEP keys are provisioned via CreateSubKey then reopened.
- Tamper-protected keys (e.g. Defender Exclusions) that deny even admin are reported as
  SKIPPED, not ERROR.

Verified: File System/Registry/Handle subcategories enabled; HKLM Run carries the Everyone
Success+Failure ContainerInherit SACL; a test autorun write produced EventID 4657 - with no
global registry auditing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:24:27 +09:00
Shirofune-SecurityandClaude Opus 4.8 1308bc003d Address Copilot review: privilege check, idempotency, ASEP provisioning, service inheritance, update-rules, CLI
- Enable-WelaPrivilege now validates ERROR_NOT_ALL_ASSIGNED per privilege; Set-AuditSacl
  aborts if SeSecurityPrivilege cannot be enabled (was silently proceeding).
- Idempotency (Test-WelaAuditRulePresent) translates IdentityReference to SID before
  comparing (Get-Acl returns NTAccount, not S-1-1-0) and also compares InheritanceFlags,
  so reruns no longer re-add rules and a non-inheriting rule no longer satisfies an
  inheriting target.
- Absent registry ASEP keys (RunOnceEx, Policies\Explorer\Run, ...) are now provisioned
  (created) before the SACL is applied, so a later attacker write is audited via the
  inheritable ACE instead of being missed.
- Services SACL is now inherited (SetValue,CreateSubKey,Delete) so 4657 on child-service
  ImagePath/ServiceDLL/Start edits and service deletion are captured (4697/7045 only cover
  install).
- update-rules now downloads config/audit_sacl_targets.json, matching the recovery message.
- Dropped the non-functional -WhatIf/-Confirm advertising (the script param block has a
  custom -Debug that precludes CmdletBinding); configure-sacl now uses a single -Auto-skippable
  confirmation prompt, consistent with 'configure'.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:11:03 +09:00
Shirofune-SecurityandClaude Opus 4.8 917037a679 CHANGELOG: note per-user coverage for configure-sacl (#361)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:03:47 +09:00
Shirofune-SecurityandClaude Opus 4.8 31aeeda768 configure-sacl: cover per-user objects across all profiles + Default
Enumerate every user profile from ProfileList (plus C:\Users\Default so future
users inherit the SACL) and apply per-user SACLs:
- user_files: file SACL under each profile dir (Startup folder, Signal AppData).
- user_registry: registry SACL on each user hive - loaded hives via
  HKEY_USERS\<SID> directly, offline/Default hives by reg-load/unload of
  NTUSER.DAT (HKCU Run/RunOnce, User Shell Folders, StartupApproved, Load/Run,
  Command Processor AutoRun, Control Panel\Desktop screensaver, Environment
  logon script, LangBarAddin, Outlook Addins).
Handles are released ([gc]) before reg unload; objects/hives absent on the host
are skipped. Not covered: folder-redirected AppData on network shares, mandatory
profiles.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:03:24 +09:00
Shirofune-SecurityandClaude Opus 4.8 6aef4c0f7b Add CHANGELOG entry for configure-sacl (#361)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 21:51:14 +09:00