Shirofune-Security
7ef29df61f
Integrate reviewed native auditing batch and preserve 4703 validation
2026-09-22 14:23:44 +09:00
Shirofune-Security
2fef35da23
Integrate reviewed native auditing commands with OneSettings validation
2026-09-22 14:23:33 +09:00
Shirofune-Security
005b249c3b
Integrate reviewed filesystem and WEF query changes with scoped NTLM auditing
2026-09-22 14:23:24 +09:00
Shirofune-Security
34b7a775c4
Merge dev and preserve filesystem lifecycle and WEF query changes
2026-09-22 14:23:10 +09:00
Shirofune-Security
160b573a99
test: bind native 4703 attribution to installed schema and exact restored context
2026-09-22 12:34:43 +09:00
Shirofune-Security
9692edcec6
fix: normalize native WEF reader tokens before strict validation
2026-09-22 12:30:51 +09:00
Shirofune-Security
353159615e
fix: preserve omitted notification selection and document native OneSettings acceptance
2026-09-22 12:06:07 +09:00
Shirofune-Security
b162c4e598
feat: configure selected incoming and domain NTLM audit policies
2026-09-22 12:03:11 +09:00
Shirofune-Security
0f95115908
test: establish owned redirected-profile native SACL fixture
2026-09-22 11:49:31 +09:00
Shirofune-Security
70a812556d
Merge commit '29f03e352823af81b35869659928a94e70df4cf9' into feat/373-registry-sacl-recovery
...
# Conflicts:
# .gitattributes
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 11:43:28 +09:00
Shirofune-Security
008a8c80b9
Merge remote-tracking branch 'origin/dev' into fix/368-native-collector-observation
...
# Conflicts:
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 11:42:00 +09:00
Shirofune-Security
530b49f26b
feat: checkpoint reviewed native registry SACL recovery
2026-09-22 10:11:02 +09:00
Shirofune-Security
af88b87e01
Fix native collector subscription inventory and Unicode readback
2026-09-22 09:46:28 +09:00
Shirofune-Security
f403521068
Merge commit '03039cb1c653f75cc0052ed93c7699290873058e' into test/386-native-provider-configure
...
# Conflicts:
# .gitattributes
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 09:41:21 +09:00
Shirofune-Security
8af856ffa6
Validate public provider pack configuration on native Windows
2026-09-22 09:40:56 +09:00
Shirofune-Security
ac45e8f72f
Merge commit 'dc7867b6bc1193e3b5d54a9c7368c0647c39b663' into test/373-native-registry-sacl-lifecycle
...
# Conflicts:
# .gitattributes
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 09:35:07 +09:00
Shirofune-Security
dc7867b6bc
Merge commit 'ffe4ed473414438d5465156e15b62796393daf80' into feat/368-reviewed-wec-authorization
...
# Conflicts:
# .gitattributes
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 09:35:07 +09:00
Shirofune-Security
a62c3b7def
test: exercise public registry SACL lifecycle and native4657
2026-09-22 08:01:48 +09:00
Shirofune-Security
0ff81052e6
Merge commit '39e8ce1' into feat/367-reviewed-channel-recovery
...
# Conflicts:
# .gitattributes
# .github/workflows/release.yml
# CHANGELOG-Japanese.md
# CHANGELOG.md
# website/docs/resources/changelog.ja.md
# website/docs/resources/changelog.md
2026-09-22 07:53:01 +09:00
Shirofune-Security
0c51232a40
Add reviewed recovery of one completed native channel operation
2026-09-22 07:52:16 +09:00
Shirofune-Security
0051f8c662
Review and update only source SID authorization on disabled WEC subscriptions
2026-09-22 07:50:50 +09:00
Shirofune-Security
39e8ce1d70
Resolve combined native source line-ending attributes
2026-09-22 07:25:54 +09:00
Shirofune-Security
0d1adfb442
Integrate reviewed CLI, channel and native probe changes
2026-09-22 07:25:37 +09:00
Shirofune-Security
3e9ba8c403
Create one reviewed exact-IP collector listener through a bounded native adapter
2026-09-21 22:58:08 +09:00
Shirofune-Security
ce7b49a5ac
Bind observed native file paths and document exact read evidence
2026-09-21 22:40:50 +09:00
Shirofune-Security
9bc243a041
Integrate final reviewed development base for CAPI2 probe
2026-09-21 18:21:10 +09:00
Shirofune-Security
ec21453cf2
Bind strict receipt parser into CAPI2 source evidence
2026-09-21 18:11:13 +09:00
田中ザック Isaac Mathis
b4fb77da02
Review and apply existing WEC subscription enable/disable ( #440 )
...
* Add reviewed existing WEC subscription state transitions
* Validate WEC destination and retain failed activation state
2026-09-21 17:54:55 +09:00
Shirofune-Security
718ef8c91d
Add fixed offline CAPI2 chain source probe
2026-09-21 17:51:31 +09:00
田中ザック Isaac Mathis
fd7a7924aa
Verify actual current-token access to built-in event channels ( #432 )
...
* Add actual current-token native channel read evidence
* Use supported workflow shells and link channel-read changelogs
* Handle real event exceptions and bind loaded token helper to source
* Capture query-token interval after evidence and metadata preparation
* Retain native child process exit evidence across PowerShell engines
* Bound native reader fixture pipe draining and child termination
* Preserve native errors from attributed channel query statuses
2026-09-21 09:18:46 +09:00
田中ザック Isaac Mathis
c6da22a2ad
Resume a reviewed pending AD CS auditing restart ( #431 )
...
* Add reviewed recovery for a pending AD CS auditing restart
* Link pending CA restart recovery changelogs to PR 431
2026-09-21 09:16:39 +09:00
田中ザック Isaac Mathis
2fd37d0318
Measure bounded native event delivery and verify exact EVTX samples ( #430 )
...
* Add bounded local delivery measurement and exact EVTX samples
* Link delivery measurement changelog to PR 430
* Reject evidence aliases before Windows path normalization
* Use PowerShell 5.1-compatible record IDs and bound fixture cleanup
* Revalidate the native EVTX artifact before recording final evidence
* Require exact observed local computer identities for sampled events
* Clarify provider scope within shared built-in event channels
* Preserve mixed XML payload ordering in EVTX sample verification
* Bound ordered event XML comparisons for nested UserData
* Dispose observer wait handle when bookmark creation fails
2026-09-21 09:14:48 +09:00
田中ザック Isaac Mathis
bcd4e9717e
Verify reviewed descendant SACL propagation and preservation ( #429 )
...
* Verify reviewed descendant SACL propagation and preservation
* Reference descendant SACL PR429 in release notes
* Prepare protected disposable SACL fixtures through native handles
* Use read-control handles for disposable native SACL protection
2026-09-21 09:12:56 +09:00
田中ザック Isaac Mathis
b84b97b358
Collect local WMI namespace audit evidence with a fixed read probe ( #428 )
...
* Collect bounded local WMI namespace access evidence
* Reference PR428 and preserve UTC worker query timestamps
* Observe equivalent runtime self tokens without reverting caller context
* Test native token equivalence against restricted caller changes
* Diagnose native token differences and package WMI probe guidance
* Limit WMI connections to the explicitly scoped security privilege
* Document verified native WMI events and privilege preservation
* Require an already-running WMI service before namespace reads
2026-09-21 09:08:20 +09:00
田中ザック Isaac Mathis
610d27e8ff
Review and apply query updates to existing disabled WEC subscriptions ( #426 )
...
* Add reviewed existing-only updates for disabled WEC subscriptions
* Pin loaded updater and flush locked recovery artifacts; reference PR 426
* Compare formatted WEC queries semantically before pinning raw native state
* Read native WEC subscription XML with bounded explicit Unicode pipes
* Use explicit Unicode reads for reviewed update and native cleanup
* Keep timestamp strings exact in inherited native evidence fixtures
* Reject XML-invalid descriptions before any native save
* Decode native WEC XML BOMs without unsupported Unicode switch
* Describe native XML byte decoding accurately
* Reference System.Xml explicitly when compiling under Windows PowerShell
2026-09-20 22:51:01 +09:00
田中ザック Isaac Mathis
c12e49213f
Add guarded DNS analytical logging and stopped-trace archives ( #425 )
...
* Add guarded DNS analytical channel lifecycle and trace archives
* Link DNS analytical changelogs to PR425
* Fix native DNS archive inspection and guard artifact paths
* Diagnose exact DNS event envelope from stopped native trace
* Verify DNS ETL event provenance without inventing XML channel
* Preserve exact UTC timestamp strings in shared evidence fixtures
2026-09-20 22:49:52 +09:00
田中ザック Isaac Mathis
913b1dfaee
Add typed native WEC runtime observations ( #424 )
...
* Observe typed native WEC subscription runtime status
* Link typed WEC runtime changelog to PR 424
* Pass a native null source for subscription runtime queries
* Ignore unused count storage for native null WEC variants
* Keep unavailable WEC source inventories unknown and diagnose native XML reads
* Read native WEC subscription XML with bounded explicit Unicode pipes
* Use bounded Unicode subscription reads in runtime observations and cleanup
* Decode native WEC XML BOMs without unsupported Unicode switch
* Describe strict native WEC XML byte decoding
* Reference System.Xml explicitly when compiling under Windows PowerShell
* Regenerate website changelog snapshots with their proper headers
2026-09-20 22:48:32 +09:00
田中ザック Isaac Mathis
5ba53fbcfb
Validate native AppLocker EXE event generation with an opt-in probe ( #423 )
...
* Add native AppLocker EXE event validation probe
* Reference PR 423 in changelogs
* Isolate AppLocker native fixture and preserve prerequisite diagnostics
* Report an integer zero for an empty AppLocker policy
* Prepare disposable AppLocker probe policy without bypassing production importer guards
* Retain bounded native AppLocker channel diagnostics on probe failure
* Require native policy application before the disposable AppLocker probe
* Preserve exact timestamp strings in native evidence fixtures
* Record actual runner session and AppLocker publication diagnostics
* Activate and restore the native policy converter on disposable AppLocker hosts
* Compare native task freshness without guessing its timestamp timezone
* Verify effective policy and borrowed converter inactivity during fixture cleanup
* Track the actual native policy-converter task instance instead of cached timestamps
2026-09-20 22:46:56 +09:00
田中ザック Isaac Mathis
ff0e5c1890
Apply reviewed SACL plans to explicitly selected local targets ( #422 )
...
* Add reviewed configuration for selected native SACL targets
* Link selected SACL changelog to PR 422
* Identify native full-descriptor read failures without partial fallback
* Fix diagnostic variable scope in native C# helper
* Read explicit descriptor sections and retain observation scope
2026-09-20 19:36:05 +09:00
田中ザック Isaac Mathis
f1c1f74166
Guard AD CS audit configuration and collect native request evidence ( #421 )
...
* Add guarded native CA auditing and disposable request evidence
* Link AD CS changelog to PR 421
* Retain primary native CA failure before cleanup diagnostics
* Normalize native CA certificate hashes and record pending feature removal
* Emit bounded disposable CA request matching diagnostics
* Match observed version 1 CA request events with exact pending disposition
2026-09-20 19:34:03 +09:00
田中ザック Isaac Mathis
f21a9f30e4
Add transparent configuration and native rule readiness scores ( #417 )
...
* Add transparent native audit compliance and evidence readiness scores
* Link transparent audit scoring changelog to PR 417
* Resolve scoring outputs against the PowerShell filesystem location
2026-09-20 18:15:04 +09:00
田中ザック Isaac Mathis
14ac8667d4
Gate historical controls and require evidence for Windows defaults ( #409 )
...
* Gate historical controls and require provenance for Windows defaults
* Bind default evidence to UTC provenance and native architecture
* Reference PR 409 in applicability changelogs
2026-09-20 14:00:10 +09:00
田中ザック Isaac Mathis
d35b1374d0
Add opt-in native DNS and provider audit packs ( #411 )
...
* Add selective native provider packs with pinned rule and schema evidence
* Reference PR 411 in provider-pack changelogs
* Fix provider pack service reader export and CI exit propagation
2026-09-20 13:58:49 +09:00
Shirofune-Security
e8a0aeb59b
Keep rule evidence identities stable across Windows checkouts and shells
2026-09-19 07:34:10 +09:00