Commit Graph

641 Commits

Author SHA1 Message Date
fukusuket
b64f3b4a00 fix: correct spelling of 'Baseline' in command examples in README files 2025-11-22 15:59:08 +09:00
github-actions[bot]
0c97a719e8 Sigma Rule Update (2025-11-21 20:16:04) (#164)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-21 20:16:10 +00:00
github-actions[bot]
7eea4d0f3c Sigma Rule Update (2025-11-20 20:16:39) (#163)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-20 20:16:47 +00:00
Zach Mathis (田中ザック)
86b3aa56b0 Merge pull request #157 from Yamato-Security/156-fix-default-value
fix: update default auditing values in WELA.ps1
2025-11-20 12:06:02 +09:00
github-actions[bot]
a0d1601004 Sigma Rule Update (2025-11-19 20:14:24) (#162)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-19 20:14:31 +00:00
github-actions[bot]
ed5bee2152 Sigma Rule Update (2025-11-18 20:16:48) (#160)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-18 20:16:54 +00:00
github-actions[bot]
bf87c13a45 Sigma Rule Update (2025-11-17 20:16:34) (#159)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-17 20:16:41 +00:00
github-actions[bot]
0c669fe15c Sigma Rule Update (2025-11-16 20:14:39) (#158)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-16 20:14:47 +00:00
fukusuket
7a8ce70e16 fix: update default auditing values in WELA.ps1 2025-11-16 19:05:38 +09:00
fukusuket
9d2d60a77a fix: adjust default value for PowerShell operational logging 2025-11-16 17:26:38 +09:00
fukusuket
b8b591f41e fix: update default auditing values in WELA.ps1 2025-11-16 17:14:22 +09:00
github-actions[bot]
d266e336da Sigma Rule Update (2025-11-15 20:14:02) (#155)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-15 20:14:09 +00:00
Zach Mathis (田中ザック)
deac995b50 Merge pull request #154 from Yamato-Security/add-badge
add badge
2025-11-15 18:57:12 +09:00
YamatoSecurity
935045d715 add badge 2025-11-15 14:23:39 +09:00
Zach Mathis (田中ザック)
1f9c3c98e2 Merge pull request #153 from Yamato-Security/141-adcs-attack-update
feat: support for adcs audit
v2.0.0
2025-11-15 14:17:14 +09:00
fukusuket
d5bb686439 docs: add Mitre Attack Navigator section to README files 2025-11-15 13:20:42 +09:00
fukusuket
f23af771ea docs: add Mitre Attack Navigator section to README files 2025-11-15 13:13:32 +09:00
fukusuket
061fb8dc9c fix: update attack and navigator versions in WELA.ps1 2025-11-15 13:06:48 +09:00
fukusuket
87aa4ca3f3 chore: update WELA.ps1 to display release version in output 2025-11-15 13:04:29 +09:00
fukusuket
ec7be1ea3a feat: add configure command to set recommended Windows event log audit policy and file size 2025-11-15 12:57:09 +09:00
fukusuket
ea8ae2ba07 chore: update WELA.ps1 header for CODE BLUE release v2.0.0 2025-11-15 12:43:10 +09:00
fukusuket
288feca218 fix: remove service restart from AuditFilter setting command in WELA.ps1 2025-11-15 10:41:55 +09:00
fukusuket
f07fbfbe2c fix: remove redundant output for AuditFilter setting in WELA.ps1 2025-11-15 10:38:04 +09:00
fukusuket
34ce48c886 fix: remove unnecessary output for AD CS AuditFilter configuration in WELA.ps1 2025-11-15 10:36:38 +09:00
fukusuket
08da2a2d59 fix: remove redundant registry output for AuditFilter check in WELA.ps1 2025-11-15 10:35:06 +09:00
fukusuket
775a716c90 fix: update AuditFilter setting command for improved error handling in WELA.ps1 2025-11-15 10:34:07 +09:00
fukusuket
4d93de3bb5 fix: enhance auditing setup with new auditpol configurations and batch script for event log management 2025-11-15 10:27:34 +09:00
fukusuket
7559cfea84 fix: add AD CS AuditFilter configuration to streamline auditing setup in WELA.ps1 2025-11-15 10:22:36 +09:00
github-actions[bot]
13a601caba Sigma Rule Update (2025-11-14 20:16:08) (#152)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-14 20:16:16 +00:00
github-actions[bot]
0bb55a3090 Sigma Rule Update (2025-11-13 20:16:46) (#151)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-13 20:16:53 +00:00
github-actions[bot]
8f7628a129 Sigma Rule Update (2025-11-12 20:16:11) (#150)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-12 20:16:18 +00:00
github-actions[bot]
6db5596886 Sigma Rule Update (2025-11-11 20:15:20) (#149)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-11 20:15:27 +00:00
github-actions[bot]
bb9d02ea40 Sigma Rule Update (2025-11-10 20:17:03) (#148)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-10 20:17:10 +00:00
github-actions[bot]
2cf7e3bade Sigma Rule Update (2025-11-09 20:13:57) (#147)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-09 20:14:02 +00:00
github-actions[bot]
d188c67857 Sigma Rule Update (2025-11-08 20:13:46) (#146)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-08 20:13:51 +00:00
Zach Mathis (田中ザック)
5db55e0d1d Merge pull request #145 from Yamato-Security/Support-Defender-for-Identity-required-logs
feat: Support Defender for Identity required logs
2025-11-08 09:14:27 +08:00
YamatoSecurity
6042536d07 update changelog 2025-11-08 10:13:10 +09:00
fukusuket
22b469cb5e fix: add Set-RegistryConfig function for streamlined registry configuration in WELA.ps1 2025-11-08 09:15:46 +09:00
github-actions[bot]
a6b07b5f1a Sigma Rule Update (2025-11-07 20:14:51) (#144)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-07 20:14:58 +00:00
github-actions[bot]
0afd2fb27e Sigma Rule Update (2025-11-06 20:15:43) (#143)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-06 20:15:50 +00:00
github-actions[bot]
c983c5355c Sigma Rule Update (2025-11-05 20:16:13) (#142)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-05 20:16:20 +00:00
Zach Mathis (田中ザック)
4aacbbf5cb Merge pull request #136 from Yamato-Security/support-crypto-dpapi
feat: support crypto dpapi log
2025-11-05 14:42:04 +08:00
github-actions[bot]
afc9966bfe Sigma Rule Update (2025-11-04 20:16:16) (#140)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-04 20:16:23 +00:00
github-actions[bot]
9938656134 Sigma Rule Update (2025-11-03 20:16:24) (#139)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-03 20:16:30 +00:00
github-actions[bot]
1b24da737a Sigma Rule Update (2025-11-02 20:13:49) (#138)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-02 20:13:56 +00:00
github-actions[bot]
84e21e43cd Sigma Rule Update (2025-11-01 20:13:20) (#137)
Co-authored-by: YamatoSecurity <YamatoSecurity@users.noreply.github.com>
2025-11-01 20:13:26 +00:00
fukusuket
eb81232e7e fix: optimize rule counting logic in WELA.ps1 for improved performance 2025-11-02 02:05:30 +09:00
fukusuket
4fdf712dbf fix: update auditing logic in WELA.ps1 to differentiate between 'No Auditing' and 'Disabled' settings 2025-11-02 00:48:05 +09:00
fukusuket
f30868aa10 fix: add Crypto-DPAPI Debug log size configuration to WELA.ps1 2025-11-02 00:27:00 +09:00
fukusuket
b4db197218 fix: add Crypto-DPAPI Debug logging support to WELA.ps1 2025-11-02 00:26:06 +09:00