Commit Graph
39 Commits
Author SHA1 Message Date
Shirofune-Security 8af856ffa6 Validate public provider pack configuration on native Windows 2026-09-22 09:40:56 +09:00
Shirofune-Security 0d1adfb442 Integrate reviewed CLI, channel and native probe changes 2026-09-22 07:25:37 +09:00
Shirofune-Security c89a21f81b Integrate reviewed CLI, channels and AppLocker Script probe 2026-09-22 07:24:32 +09:00
Shirofune-Security ce7b49a5ac Bind observed native file paths and document exact read evidence 2026-09-21 22:40:50 +09:00
Shirofune-Security 4905f82eb5 Add reviewed WEC listener CLI contract and operator guide 2026-09-21 22:40:05 +09:00
Shirofune-Security 019f13b566 Merge branch 'feat/375-firewall-log-recovery' into feat/381-native-applocker-script-probe
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 22:27:49 +09:00
Shirofune-Security ef64b08bd2 Document Script evidence boundaries and retain bounded startup diagnostics 2026-09-21 22:26:34 +09:00
Shirofune-Security 8fed328442 Integrate the reviewed recovery and native probe batch 2026-09-21 22:23:25 +09:00
Shirofune-Security 2f442af4da Integrate reviewed recovery and failed-logon commands 2026-09-21 22:21:35 +09:00
Shirofune-Security c4e9e765ff Integrate reviewed event-log recovery and failed-logon changes 2026-09-21 22:20:02 +09:00
Shirofune-Security 89f520511b Merge dev after failed-logon probe integration 2026-09-21 22:13:52 +09:00
田中ザック Isaac Mathis 6d228fedef Add a native local failed-logon audit probe (#444)
* Add native local nonexistent-account failed-logon probe

* Match actual MSV1 local authentication event package

* Refuse coerced identity and authentication receipt fields

* Preserve explicit UTC DateTime receipts on older PowerShell7

* Reject unknown failed-logon probe options before dispatch
2026-09-21 22:13:20 +09:00
Shirofune-Security 6bf4360362 Merge final dev and verify strict transcription recovery CLI 2026-09-21 18:22:31 +09:00
Shirofune-Security 9bc243a041 Integrate final reviewed development base for CAPI2 probe 2026-09-21 18:21:10 +09:00
Shirofune-Security e61056caba Merge final dev and preserve recovery and ingress command handlers 2026-09-21 18:21:06 +09:00
Shirofune-Security 3abe3018ba Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:20:57 +09:00
田中ザック Isaac Mathis 203fdfc942 Add reviewed scoped collector firewall ingress creation (#442)
* Add reviewed scoped collector firewall ingress creation

* Avoid Windows Clear-Item alias in native ingress fixture

* Handle native nullable package scope and retain bounded filter evidence

* Match native firewall network spelling in collector prerequisites
2026-09-21 18:19:30 +09:00
Shirofune-Security e068bd8f52 Merge dev and preserve independent recovery and WEC commands 2026-09-21 18:11:29 +09:00
Shirofune-Security 07e3d37265 Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:09:42 +09:00
田中ザック Isaac Mathis 9d03a19082 Activate native SMB audit runtime switches explicitly (#441)
* Add explicit native SMB runtime audit activation

* Select explicit PowerShell workflow shells and link PR changelog

* Clear expected refusal child exit codes after assertions

* Retain native SMB command provenance in capability diagnostics

* Bind SMB command guards to observed native CDXML module identities
2026-09-21 18:09:10 +09:00
Shirofune-Security d590e8226a Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:04:28 +09:00
田中ザック Isaac Mathis b4fb77da02 Review and apply existing WEC subscription enable/disable (#440)
* Add reviewed existing WEC subscription state transitions

* Validate WEC destination and retain failed activation state
2026-09-21 17:54:55 +09:00
Shirofune-Security afc748188d Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 17:52:42 +09:00
Shirofune-Security 23f88776bf Add guarded single-profile firewall logging recovery 2026-09-21 17:52:23 +09:00
Shirofune-Security 718ef8c91d Add fixed offline CAPI2 chain source probe 2026-09-21 17:51:31 +09:00
Shirofune-Security 1ea0687616 Merge dev and preserve recovery and IPsec release guides 2026-09-21 17:49:46 +09:00
Shirofune-Security 63b65e2447 Add reviewed native transcription policy recovery 2026-09-21 17:48:32 +09:00
田中ザック Isaac Mathis b7e649185b Gate conditional IPsec auditing on native prerequisite evidence (#439)
* Gate conditional stronger-profile IPsec auditing on native evidence

* Use supported literal shells in native prerequisite matrix

* Retain native IPsec fixture diagnostics and allow inactive rule omission

* Expose exact native rule fields when prerequisite classification fails

* Recognize native inactive IPsec rules without granting applicability

* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
Shirofune-Security d1d40b4a25 Add reviewed recovery of completed event-log size and retention changes 2026-09-21 17:42:52 +09:00
田中ザック Isaac Mathis b84b97b358 Collect local WMI namespace audit evidence with a fixed read probe (#428)
* Collect bounded local WMI namespace access evidence

* Reference PR428 and preserve UTC worker query timestamps

* Observe equivalent runtime self tokens without reverting caller context

* Test native token equivalence against restricted caller changes

* Diagnose native token differences and package WMI probe guidance

* Limit WMI connections to the explicitly scoped security privilege

* Document verified native WMI events and privilege preservation

* Require an already-running WMI service before namespace reads
2026-09-21 09:08:20 +09:00
田中ザック Isaac Mathis f1ed90d189 Create new disabled, unlinked GPOs from reviewed native audit backups (#427)
* Add guarded creation of disabled unlinked audit GPOs

* Reference PR 427 in GPO creation changelogs

* Accept only inert native ADM placeholders and fix PS5 JSON fixture

* Preserve fractional UTC strings in existing probe fixtures
2026-09-20 22:53:00 +09:00
田中ザック Isaac Mathis 3a80ef5e67 Add reviewable GPO audit-policy deployment packages (#415)
* Add reviewable GPO audit-policy deployment components

* Link GPO audit package changelog to PR 415

* Check GPO verification exit code from a real CLI process
2026-09-20 18:13:34 +09:00
Shirofune-Security d480db5a76 Integrate versioned audit profiles with verified configuration
# Conflicts:
#	.github/workflows/release.yml
#	WELA.ps1
2026-09-18 22:00:30 +09:00
Shirofune-Security ee7a0e2216 Unify advanced audit policy audit, plan and configure profiles 2026-09-18 21:54:38 +09:00
Shirofune-Security 1ae4930438 Verify configure changes and propagate per-control failures 2026-09-18 21:48:27 +09:00
fukusuket dcf29e4a59 fix: update .gitignore and release workflows for new output files and README changes 2026-08-30 21:08:16 +09:00
fukusuket 590cb807c0 fix: update actions/checkout and permissions in workflow YAML files 2026-05-03 14:05:17 +09:00
Fukusuke TakahashiandCopilot 72667822f5 Update .github/workflows/release.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-05-11 08:35:55 +09:00
fukusuket 02f88cb309 feat: release action 2025-05-11 08:30:35 +09:00