- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system
drive no longer skips every file target.
- Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*.
- WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows.
- reg unload is now checked (retry once, then error) so a failed unload no longer leaves the
user's NTUSER.DAT mounted under the temp alias while reporting success.
- A failed auditpol subcategory is tracked; the final message warns (instead of claiming success)
that SACLs for that class will not produce events.
- configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned.
Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with
SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
Fills the remaining gaps so 'configure' + 'configure-sacl' cover a full detection
baseline out of the box (no manual auditpol/registry needed downstream):
- Detailed Tracking > Process Termination (4689)
- Object Access > Detailed File Share (5145)
- Directory Service LDAP query logging (1644) via NTDS "15 Field Engineering"=5,
applied only on domain controllers (BloodHound/LDAP recon).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
Live-tested on Windows Server 2019; three bugs fixed found during testing:
- TOKEN_PRIVILEGES had a `long Luid` after a `uint Count`, which is 8-byte aligned on x64
and inserted padding, so AdjustTokenPrivileges failed with ERROR_NOT_ALL_ASSIGNED and the
new privilege guard aborted. Split the LUID into LuidLow(uint)+LuidHigh(int) to match the
native layout.
- Get-Acl/Set-Acl -Audit is unreliable on the registry provider (returns/throws "path does
not exist" and null). Registry SACLs now use the .NET RegistryKey API
(OpenSubKey with ReadPermissions,ChangePermissions -> GetAccessControl(Audit) ->
AddAuditRule -> SetAccessControl), which honors the enabled SeSecurityPrivilege. Absent
ASEP keys are provisioned via CreateSubKey then reopened.
- Tamper-protected keys (e.g. Defender Exclusions) that deny even admin are reported as
SKIPPED, not ERROR.
Verified: File System/Registry/Handle subcategories enabled; HKLM Run carries the Everyone
Success+Failure ContainerInherit SACL; a test autorun write produced EventID 4657 - with no
global registry auditing.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
- Enable-WelaPrivilege now validates ERROR_NOT_ALL_ASSIGNED per privilege; Set-AuditSacl
aborts if SeSecurityPrivilege cannot be enabled (was silently proceeding).
- Idempotency (Test-WelaAuditRulePresent) translates IdentityReference to SID before
comparing (Get-Acl returns NTAccount, not S-1-1-0) and also compares InheritanceFlags,
so reruns no longer re-add rules and a non-inheriting rule no longer satisfies an
inheriting target.
- Absent registry ASEP keys (RunOnceEx, Policies\Explorer\Run, ...) are now provisioned
(created) before the SACL is applied, so a later attacker write is audited via the
inheritable ACE instead of being missed.
- Services SACL is now inherited (SetValue,CreateSubKey,Delete) so 4657 on child-service
ImagePath/ServiceDLL/Start edits and service deletion are captured (4697/7045 only cover
install).
- update-rules now downloads config/audit_sacl_targets.json, matching the recovery message.
- Dropped the non-functional -WhatIf/-Confirm advertising (the script param block has a
custom -Debug that precludes CmdletBinding); configure-sacl now uses a single -Auto-skippable
confirmation prompt, consistent with 'configure'.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
Enumerate every user profile from ProfileList (plus C:\Users\Default so future
users inherit the SACL) and apply per-user SACLs:
- user_files: file SACL under each profile dir (Startup folder, Signal AppData).
- user_registry: registry SACL on each user hive - loaded hives via
HKEY_USERS\<SID> directly, offline/Default hives by reg-load/unload of
NTUSER.DAT (HKCU Run/RunOnce, User Shell Folders, StartupApproved, Load/Run,
Command Processor AutoRun, Control Panel\Desktop screensaver, Environment
logon script, LangBarAddin, Outlook Addins).
Handles are released ([gc]) before reg unload; objects/hives absent on the host
are skipped. Not covered: folder-redirected AppData on network shares, mandatory
profiles.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7