田中ザック Isaac Mathis
9d03a19082
Activate native SMB audit runtime switches explicitly ( #441 )
...
* Add explicit native SMB runtime audit activation
* Select explicit PowerShell workflow shells and link PR changelog
* Clear expected refusal child exit codes after assertions
* Retain native SMB command provenance in capability diagnostics
* Bind SMB command guards to observed native CDXML module identities
2026-09-21 18:09:10 +09:00
田中ザック Isaac Mathis
b4fb77da02
Review and apply existing WEC subscription enable/disable ( #440 )
...
* Add reviewed existing WEC subscription state transitions
* Validate WEC destination and retain failed activation state
2026-09-21 17:54:55 +09:00
田中ザック Isaac Mathis
b7e649185b
Gate conditional IPsec auditing on native prerequisite evidence ( #439 )
...
* Gate conditional stronger-profile IPsec auditing on native evidence
* Use supported literal shells in native prerequisite matrix
* Retain native IPsec fixture diagnostics and allow inactive rule omission
* Expose exact native rule fields when prerequisite classification fails
* Recognize native inactive IPsec rules without granting applicability
* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
田中ザック Isaac Mathis
b84b97b358
Collect local WMI namespace audit evidence with a fixed read probe ( #428 )
...
* Collect bounded local WMI namespace access evidence
* Reference PR428 and preserve UTC worker query timestamps
* Observe equivalent runtime self tokens without reverting caller context
* Test native token equivalence against restricted caller changes
* Diagnose native token differences and package WMI probe guidance
* Limit WMI connections to the explicitly scoped security privilege
* Document verified native WMI events and privilege preservation
* Require an already-running WMI service before namespace reads
2026-09-21 09:08:20 +09:00
田中ザック Isaac Mathis
f1ed90d189
Create new disabled, unlinked GPOs from reviewed native audit backups ( #427 )
...
* Add guarded creation of disabled unlinked audit GPOs
* Reference PR 427 in GPO creation changelogs
* Accept only inert native ADM placeholders and fix PS5 JSON fixture
* Preserve fractional UTC strings in existing probe fixtures
2026-09-20 22:53:00 +09:00
田中ザック Isaac Mathis
3a80ef5e67
Add reviewable GPO audit-policy deployment packages ( #415 )
...
* Add reviewable GPO audit-policy deployment components
* Link GPO audit package changelog to PR 415
* Check GPO verification exit code from a real CLI process
2026-09-20 18:13:34 +09:00
Shirofune-Security
d480db5a76
Integrate versioned audit profiles with verified configuration
...
# Conflicts:
# .github/workflows/release.yml
# WELA.ps1
2026-09-18 22:00:30 +09:00
Shirofune-Security
ee7a0e2216
Unify advanced audit policy audit, plan and configure profiles
2026-09-18 21:54:38 +09:00
Shirofune-Security
1ae4930438
Verify configure changes and propagate per-control failures
2026-09-18 21:48:27 +09:00
fukusuket
dcf29e4a59
fix: update .gitignore and release workflows for new output files and README changes
2026-08-30 21:08:16 +09:00
fukusuket
590cb807c0
fix: update actions/checkout and permissions in workflow YAML files
2026-05-03 14:05:17 +09:00
Fukusuke Takahashi and Copilot
72667822f5
Update .github/workflows/release.yml
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2025-05-11 08:35:55 +09:00
fukusuket
02f88cb309
feat: release action
2025-05-11 08:30:35 +09:00