Shirofune-Security
0d1adfb442
Integrate reviewed CLI, channel and native probe changes
2026-09-22 07:25:37 +09:00
Shirofune-Security
c89a21f81b
Integrate reviewed CLI, channels and AppLocker Script probe
2026-09-22 07:24:32 +09:00
Shirofune-Security
ce7b49a5ac
Bind observed native file paths and document exact read evidence
2026-09-21 22:40:50 +09:00
Shirofune-Security
4905f82eb5
Add reviewed WEC listener CLI contract and operator guide
2026-09-21 22:40:05 +09:00
Shirofune-Security
019f13b566
Merge branch 'feat/375-firewall-log-recovery' into feat/381-native-applocker-script-probe
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 22:27:49 +09:00
Shirofune-Security
ef64b08bd2
Document Script evidence boundaries and retain bounded startup diagnostics
2026-09-21 22:26:34 +09:00
Shirofune-Security
8fed328442
Integrate the reviewed recovery and native probe batch
2026-09-21 22:23:25 +09:00
Shirofune-Security
2f442af4da
Integrate reviewed recovery and failed-logon commands
2026-09-21 22:21:35 +09:00
Shirofune-Security
c4e9e765ff
Integrate reviewed event-log recovery and failed-logon changes
2026-09-21 22:20:02 +09:00
Shirofune-Security
89f520511b
Merge dev after failed-logon probe integration
2026-09-21 22:13:52 +09:00
田中ザック Isaac Mathis
6d228fedef
Add a native local failed-logon audit probe ( #444 )
...
* Add native local nonexistent-account failed-logon probe
* Match actual MSV1 local authentication event package
* Refuse coerced identity and authentication receipt fields
* Preserve explicit UTC DateTime receipts on older PowerShell7
* Reject unknown failed-logon probe options before dispatch
2026-09-21 22:13:20 +09:00
Shirofune-Security
6bf4360362
Merge final dev and verify strict transcription recovery CLI
2026-09-21 18:22:31 +09:00
Shirofune-Security
9bc243a041
Integrate final reviewed development base for CAPI2 probe
2026-09-21 18:21:10 +09:00
Shirofune-Security
e61056caba
Merge final dev and preserve recovery and ingress command handlers
2026-09-21 18:21:06 +09:00
Shirofune-Security
3abe3018ba
Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 18:20:57 +09:00
田中ザック Isaac Mathis
203fdfc942
Add reviewed scoped collector firewall ingress creation ( #442 )
...
* Add reviewed scoped collector firewall ingress creation
* Avoid Windows Clear-Item alias in native ingress fixture
* Handle native nullable package scope and retain bounded filter evidence
* Match native firewall network spelling in collector prerequisites
2026-09-21 18:19:30 +09:00
Shirofune-Security
e068bd8f52
Merge dev and preserve independent recovery and WEC commands
2026-09-21 18:11:29 +09:00
Shirofune-Security
07e3d37265
Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 18:09:42 +09:00
田中ザック Isaac Mathis
9d03a19082
Activate native SMB audit runtime switches explicitly ( #441 )
...
* Add explicit native SMB runtime audit activation
* Select explicit PowerShell workflow shells and link PR changelog
* Clear expected refusal child exit codes after assertions
* Retain native SMB command provenance in capability diagnostics
* Bind SMB command guards to observed native CDXML module identities
2026-09-21 18:09:10 +09:00
Shirofune-Security
d590e8226a
Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 18:04:28 +09:00
田中ザック Isaac Mathis
b4fb77da02
Review and apply existing WEC subscription enable/disable ( #440 )
...
* Add reviewed existing WEC subscription state transitions
* Validate WEC destination and retain failed activation state
2026-09-21 17:54:55 +09:00
Shirofune-Security
afc748188d
Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-21 17:52:42 +09:00
Shirofune-Security
23f88776bf
Add guarded single-profile firewall logging recovery
2026-09-21 17:52:23 +09:00
Shirofune-Security
718ef8c91d
Add fixed offline CAPI2 chain source probe
2026-09-21 17:51:31 +09:00
Shirofune-Security
1ea0687616
Merge dev and preserve recovery and IPsec release guides
2026-09-21 17:49:46 +09:00
Shirofune-Security
63b65e2447
Add reviewed native transcription policy recovery
2026-09-21 17:48:32 +09:00
田中ザック Isaac Mathis
b7e649185b
Gate conditional IPsec auditing on native prerequisite evidence ( #439 )
...
* Gate conditional stronger-profile IPsec auditing on native evidence
* Use supported literal shells in native prerequisite matrix
* Retain native IPsec fixture diagnostics and allow inactive rule omission
* Expose exact native rule fields when prerequisite classification fails
* Recognize native inactive IPsec rules without granting applicability
* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
Shirofune-Security
d1d40b4a25
Add reviewed recovery of completed event-log size and retention changes
2026-09-21 17:42:52 +09:00
田中ザック Isaac Mathis
b84b97b358
Collect local WMI namespace audit evidence with a fixed read probe ( #428 )
...
* Collect bounded local WMI namespace access evidence
* Reference PR428 and preserve UTC worker query timestamps
* Observe equivalent runtime self tokens without reverting caller context
* Test native token equivalence against restricted caller changes
* Diagnose native token differences and package WMI probe guidance
* Limit WMI connections to the explicitly scoped security privilege
* Document verified native WMI events and privilege preservation
* Require an already-running WMI service before namespace reads
2026-09-21 09:08:20 +09:00
田中ザック Isaac Mathis
f1ed90d189
Create new disabled, unlinked GPOs from reviewed native audit backups ( #427 )
...
* Add guarded creation of disabled unlinked audit GPOs
* Reference PR 427 in GPO creation changelogs
* Accept only inert native ADM placeholders and fix PS5 JSON fixture
* Preserve fractional UTC strings in existing probe fixtures
2026-09-20 22:53:00 +09:00
田中ザック Isaac Mathis
3a80ef5e67
Add reviewable GPO audit-policy deployment packages ( #415 )
...
* Add reviewable GPO audit-policy deployment components
* Link GPO audit package changelog to PR 415
* Check GPO verification exit code from a real CLI process
2026-09-20 18:13:34 +09:00
Shirofune-Security
d480db5a76
Integrate versioned audit profiles with verified configuration
...
# Conflicts:
# .github/workflows/release.yml
# WELA.ps1
2026-09-18 22:00:30 +09:00
Shirofune-Security
ee7a0e2216
Unify advanced audit policy audit, plan and configure profiles
2026-09-18 21:54:38 +09:00
Shirofune-Security
1ae4930438
Verify configure changes and propagate per-control failures
2026-09-18 21:48:27 +09:00
fukusuket
dcf29e4a59
fix: update .gitignore and release workflows for new output files and README changes
2026-08-30 21:08:16 +09:00
fukusuket
590cb807c0
fix: update actions/checkout and permissions in workflow YAML files
2026-05-03 14:05:17 +09:00
Fukusuke Takahashi and Copilot
72667822f5
Update .github/workflows/release.yml
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-05-11 08:35:55 +09:00
fukusuket
02f88cb309
feat: release action
2025-05-11 08:30:35 +09:00