Commit Graph
55 Commits
Author SHA1 Message Date
田中ザック Isaac Mathis 83b2ddd526 Support validated custom audit profile files through the shared engine (#416)
* Support validated operator-owned advanced audit profile files

* Reject lenient custom profile JSON and protect report output aliases

* Link custom audit profile changelog to PR 416

* Make custom JSON rejection fixtures portable across PowerShell versions
2026-09-20 18:09:52 +09:00
田中ザック Isaac Mathis 4431533535 Collect native 4688 validation components with a fixed benign probe (#413)
* Add opt-in native 4688 validation component collector

* Link native validation changelog to PR 413

* Reject contradictory native probe context observations

* Resolve probe artifact paths against the PowerShell location
2026-09-20 18:08:34 +09:00
田中ザック Isaac Mathis 7719063f6f Add source-specific Windows audit privilege and integrity controls (#412)
* Add opt-in source-profile audit integrity controls

* Reference PR 412 in audit-integrity changelogs
2026-09-20 14:03:18 +09:00
田中ザック Isaac Mathis 55cc427c61 Report native log retention and collection health evidence (#410)
* Add read-only native retention and collection health evidence reports

* Verify retention HTML evidence across PowerShell JSON serializers

* Reference PR 410 in retention changelogs

* Preserve previous-report arrays on Windows PowerShell and test both server releases
2026-09-20 14:01:43 +09:00
田中ザック Isaac Mathis 14ac8667d4 Gate historical controls and require evidence for Windows defaults (#409)
* Gate historical controls and require provenance for Windows defaults

* Bind default evidence to UTC provenance and native architecture

* Reference PR 409 in applicability changelogs
2026-09-20 14:00:10 +09:00
田中ザック Isaac Mathis d35b1374d0 Add opt-in native DNS and provider audit packs (#411)
* Add selective native provider packs with pinned rule and schema evidence

* Reference PR 411 in provider-pack changelogs

* Fix provider pack service reader export and CI exit propagation
2026-09-20 13:58:49 +09:00
田中ザック Isaac Mathis 35aca8f494 Add OneSettings auditing and Security warning controls (#408)
* Add explicit OneSettings auditing and Security warning controls

* Reference PR 408 in notification changelogs

* Handle expected child CLI failure under Windows PowerShell 5.1

* Block dependent Privacy channel changes when OneSettings policy drifts

* Recheck notification producer prerequisites at channel write boundaries
2026-09-20 13:55:24 +09:00
Shirofune-Security 9815e609d8 Integrate reviewed catalog and LDAP commands into WEF branch 2026-09-19 11:48:11 +09:00
Shirofune-Security f1b5be8bf2 Merge reviewed PowerShell transcription into WEF integration 2026-09-19 11:45:59 +09:00
Shirofune-Security 03265a0940 Merge commit '26d7f8b09df915c0f2b3dc837112f5f963b437a7' into feat/376-powershell-transcription 2026-09-19 11:45:34 +09:00
Shirofune-Security 273af05e36 Merge reviewed LDAP diagnostics into transcription branch 2026-09-19 11:45:34 +09:00
Shirofune-Security 26d7f8b09d Merge remote-tracking branch 'origin/dev' into feat/383-ldap-diagnostics
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 11:45:13 +09:00
Shirofune-Security 787c66e009 Normalize WEF XML evidence before PowerShell 5.1 JSON serialization 2026-09-19 07:31:23 +09:00
Shirofune-Security 9a69600947 Add opt-in native WEF source and collector subscription controls 2026-09-19 07:23:47 +09:00
Shirofune-Security 89253fa812 Add opt-in Windows PowerShell transcription for CIS Level 2 2026-09-19 07:09:33 +09:00
Shirofune-Security 9e2b4b5b43 Make LDAP 1644 diagnostics explicit and preserve existing DC settings 2026-09-19 07:09:07 +09:00
Shirofune-Security b2b7e0a9f7 Correct legacy token audit GUID and validate catalog mapping uncertainty 2026-09-19 07:01:50 +09:00
Shirofune-Security 9d993a2a7e Merge branch 'feat/367-native-channel-access' into feat/371-ad-object-sacl
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 06:54:08 +09:00
Shirofune-Security 0229348963 Merge branch 'feat/381-applocker-readiness' into feat/367-native-channel-access
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 06:53:25 +09:00
Shirofune-Security aff422bf99 Merge remote-tracking branch 'origin/dev' into feat/381-applocker-readiness
# Conflicts:
#	WELA.ps1
2026-09-19 06:52:50 +09:00
Shirofune-Security 86ac6e7bd6 Merge dev targeted SACL planning into AppLocker readiness branch 2026-09-19 06:51:13 +09:00
Shirofune-Security d83c2419b0 Merge remote-tracking branch 'origin/dev' into feat/367-native-channel-access
# Conflicts:
#	WELA.ps1
2026-09-19 06:51:10 +09:00
Shirofune-Security 47302ef9ae Merge remote-tracking branch 'origin/dev' into feat/371-ad-object-sacl 2026-09-19 06:50:32 +09:00
Shirofune-Security 2c0bbfae0b Merge remote-tracking branch 'origin/dev' into feat/372-wmi-namespace-auditing 2026-09-19 06:49:04 +09:00
Shirofune-Security a74a3e79f0 Handle unused AppLocker placeholders without weakening merge enforcement guards 2026-09-19 06:25:36 +09:00
Shirofune-Security 521fe3b826 Preserve configured user-file suffixes in SACL plans 2026-09-19 06:21:18 +09:00
Shirofune-Security 92bf29ec22 Isolate unknown dMSA prerequisites from other AD audit classes 2026-09-19 06:20:41 +09:00
Shirofune-Security cbd1c0643b Confirm AD SACL receipt ownership and validate exact PKI parent 2026-09-19 05:47:54 +09:00
Shirofune-Security c338dae12e Add opt-in AD directory object SACL profiles and recovery (issue #371) 2026-09-19 05:42:25 +09:00
Shirofune-Security d7f710c9ad Restrict native WMI writes to SACL and verify privilege cleanup 2026-09-19 05:41:08 +09:00
Shirofune-Security 5f240d8062 Verify locked AppLocker import bytes and reject ignored options 2026-09-19 05:40:08 +09:00
Shirofune-Security 1acfec66a3 Read unexpanded ProfileList paths before validation 2026-09-19 05:36:43 +09:00
Shirofune-Security 1bf6bc26b3 Add opt-in native WEF channel settings and preserved CAPI2 read access 2026-09-19 05:36:29 +09:00
Shirofune-Security acde16f149 Guard targeted SACL planning paths and ignored skip options 2026-09-19 05:35:23 +09:00
Shirofune-Security 9ffd2bd758 Assess native AppLocker readiness and guard audit-only imports 2026-09-19 05:34:12 +09:00
Shirofune-Security 80db17891d Add opt-in WMI namespace audit SACL workflow 2026-09-19 05:30:12 +09:00
Shirofune-Security b861e86d3a Plan targeted SACL prerequisites alongside audit profiles 2026-09-19 05:25:38 +09:00
Shirofune-Security f2325b5e0b Merge commit 'be3a354' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:50:15 +09:00
Shirofune-Security 3507734538 Merge commit '88c84fa' into HEAD
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	scripts/Configuration.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 04:49:40 +09:00
Shirofune-Security 157fb56bee Merge commit 'a10e1d6' into HEAD
# Conflicts:
#	scripts/Configuration.ps1
2026-09-19 04:48:19 +09:00
Shirofune-Security be3a354f18 Separate SMB policy verification from runtime activation 2026-09-19 04:39:55 +09:00
Shirofune-Security 24a77ee9ce Read audit precedence provenance from documented RSoP schemas 2026-09-19 02:35:06 +09:00
Shirofune-Security a10e1d6e84 Reject firewall log path drift before configuration 2026-09-19 02:33:53 +09:00
Shirofune-Security 2ea509700b Add version-aware opt-in SMB audit policy controls 2026-09-19 02:33:13 +09:00
Shirofune-Security d29ffdd01b Unify event-log size and retention profiles with verified configuration 2026-09-19 02:30:41 +09:00
Shirofune-Security fbe8f95117 Add opt-in native firewall text logging controls 2026-09-19 02:24:38 +09:00
Shirofune-Security 1a12220b51 Verify advanced audit precedence before applying subcategories 2026-09-19 02:21:55 +09:00
Shirofune-Security 7d2117ebba Fix audit applicability, NTLM value types, and native exit verification 2026-09-19 00:36:38 +09:00
Shirofune-Security 4c2193964e Keep deferred configuration callbacks in script scope on PowerShell 5.1 2026-09-18 22:13:58 +09:00
Shirofune-Security fa5141755b Reject unsupported dry runs and preserve freshly observed NTLM restrictions 2026-09-18 22:10:17 +09:00