Commit Graph
61 Commits
Author SHA1 Message Date
Shirofune-Security 7ef29df61f Integrate reviewed native auditing batch and preserve 4703 validation 2026-09-22 14:23:44 +09:00
Shirofune-Security 2fef35da23 Integrate reviewed native auditing commands with OneSettings validation 2026-09-22 14:23:33 +09:00
Shirofune-Security 005b249c3b Integrate reviewed filesystem and WEF query changes with scoped NTLM auditing 2026-09-22 14:23:24 +09:00
Shirofune-Security 34b7a775c4 Merge dev and preserve filesystem lifecycle and WEF query changes 2026-09-22 14:23:10 +09:00
Shirofune-Security 160b573a99 test: bind native 4703 attribution to installed schema and exact restored context 2026-09-22 12:34:43 +09:00
Shirofune-Security f27238ebd5 Validate typed source inputs and preserve caller scope in query reader 2026-09-22 12:10:03 +09:00
Shirofune-Security 353159615e fix: preserve omitted notification selection and document native OneSettings acceptance 2026-09-22 12:06:07 +09:00
Shirofune-Security b162c4e598 feat: configure selected incoming and domain NTLM audit policies 2026-09-22 12:03:11 +09:00
Shirofune-Security 6feb0d8a33 test: complete filesystem lifecycle fixture dependencies and evidence guide 2026-09-22 11:59:29 +09:00
Shirofune-Security 70a812556d Merge commit '29f03e352823af81b35869659928a94e70df4cf9' into feat/373-registry-sacl-recovery
# Conflicts:
#	.gitattributes
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 11:43:28 +09:00
Shirofune-Security 559a9d1b82 Merge commit '008a8c80b9820318be8d9f833c6adf31c2dbf9a9' into feat/362-scoped-outgoing-ntlm
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 11:42:30 +09:00
Shirofune-Security 008a8c80b9 Merge remote-tracking branch 'origin/dev' into fix/368-native-collector-observation
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 11:42:00 +09:00
Shirofune-Security 494f9c2f93 fix: accept exact native empty catalog representations and document recovery 2026-09-22 11:01:38 +09:00
Shirofune-Security 0777a5d0f8 Add scoped outgoing NTLM audit configuration with native acceptance 2026-09-22 10:09:37 +09:00
Shirofune-Security af88b87e01 Fix native collector subscription inventory and Unicode readback 2026-09-22 09:46:28 +09:00
Shirofune-Security f403521068 Merge commit '03039cb1c653f75cc0052ed93c7699290873058e' into test/386-native-provider-configure
# Conflicts:
#	.gitattributes
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 09:41:21 +09:00
Shirofune-Security 8af856ffa6 Validate public provider pack configuration on native Windows 2026-09-22 09:40:56 +09:00
Shirofune-Security ac45e8f72f Merge commit 'dc7867b6bc1193e3b5d54a9c7368c0647c39b663' into test/373-native-registry-sacl-lifecycle
# Conflicts:
#	.gitattributes
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 09:35:07 +09:00
Shirofune-Security dc7867b6bc Merge commit 'ffe4ed473414438d5465156e15b62796393daf80' into feat/368-reviewed-wec-authorization
# Conflicts:
#	.gitattributes
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 09:35:07 +09:00
Shirofune-Security 9238633041 test: run registry fixtures in explicit native shells and document evidence 2026-09-22 08:06:51 +09:00
Shirofune-Security 0ff81052e6 Merge commit '39e8ce1' into feat/367-reviewed-channel-recovery
# Conflicts:
#	.gitattributes
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-22 07:53:01 +09:00
Shirofune-Security 0c51232a40 Add reviewed recovery of one completed native channel operation 2026-09-22 07:52:16 +09:00
Shirofune-Security 0051f8c662 Review and update only source SID authorization on disabled WEC subscriptions 2026-09-22 07:50:50 +09:00
Shirofune-Security 0d1adfb442 Integrate reviewed CLI, channel and native probe changes 2026-09-22 07:25:37 +09:00
Shirofune-Security c89a21f81b Integrate reviewed CLI, channels and AppLocker Script probe 2026-09-22 07:24:32 +09:00
Shirofune-Security ce7b49a5ac Bind observed native file paths and document exact read evidence 2026-09-21 22:40:50 +09:00
Shirofune-Security 4905f82eb5 Add reviewed WEC listener CLI contract and operator guide 2026-09-21 22:40:05 +09:00
Shirofune-Security 019f13b566 Merge branch 'feat/375-firewall-log-recovery' into feat/381-native-applocker-script-probe
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 22:27:49 +09:00
Shirofune-Security ef64b08bd2 Document Script evidence boundaries and retain bounded startup diagnostics 2026-09-21 22:26:34 +09:00
Shirofune-Security 8fed328442 Integrate the reviewed recovery and native probe batch 2026-09-21 22:23:25 +09:00
Shirofune-Security 2f442af4da Integrate reviewed recovery and failed-logon commands 2026-09-21 22:21:35 +09:00
Shirofune-Security c4e9e765ff Integrate reviewed event-log recovery and failed-logon changes 2026-09-21 22:20:02 +09:00
Shirofune-Security 89f520511b Merge dev after failed-logon probe integration 2026-09-21 22:13:52 +09:00
田中ザック Isaac Mathis 6d228fedef Add a native local failed-logon audit probe (#444)
* Add native local nonexistent-account failed-logon probe

* Match actual MSV1 local authentication event package

* Refuse coerced identity and authentication receipt fields

* Preserve explicit UTC DateTime receipts on older PowerShell7

* Reject unknown failed-logon probe options before dispatch
2026-09-21 22:13:20 +09:00
Shirofune-Security 6bf4360362 Merge final dev and verify strict transcription recovery CLI 2026-09-21 18:22:31 +09:00
Shirofune-Security 9bc243a041 Integrate final reviewed development base for CAPI2 probe 2026-09-21 18:21:10 +09:00
Shirofune-Security e61056caba Merge final dev and preserve recovery and ingress command handlers 2026-09-21 18:21:06 +09:00
Shirofune-Security 3abe3018ba Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:20:57 +09:00
田中ザック Isaac Mathis 203fdfc942 Add reviewed scoped collector firewall ingress creation (#442)
* Add reviewed scoped collector firewall ingress creation

* Avoid Windows Clear-Item alias in native ingress fixture

* Handle native nullable package scope and retain bounded filter evidence

* Match native firewall network spelling in collector prerequisites
2026-09-21 18:19:30 +09:00
Shirofune-Security e068bd8f52 Merge dev and preserve independent recovery and WEC commands 2026-09-21 18:11:29 +09:00
Shirofune-Security 07e3d37265 Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:09:42 +09:00
田中ザック Isaac Mathis 9d03a19082 Activate native SMB audit runtime switches explicitly (#441)
* Add explicit native SMB runtime audit activation

* Select explicit PowerShell workflow shells and link PR changelog

* Clear expected refusal child exit codes after assertions

* Retain native SMB command provenance in capability diagnostics

* Bind SMB command guards to observed native CDXML module identities
2026-09-21 18:09:10 +09:00
Shirofune-Security d590e8226a Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:04:28 +09:00
田中ザック Isaac Mathis b4fb77da02 Review and apply existing WEC subscription enable/disable (#440)
* Add reviewed existing WEC subscription state transitions

* Validate WEC destination and retain failed activation state
2026-09-21 17:54:55 +09:00
Shirofune-Security afc748188d Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 17:52:42 +09:00
Shirofune-Security 23f88776bf Add guarded single-profile firewall logging recovery 2026-09-21 17:52:23 +09:00
Shirofune-Security 718ef8c91d Add fixed offline CAPI2 chain source probe 2026-09-21 17:51:31 +09:00
Shirofune-Security 1ea0687616 Merge dev and preserve recovery and IPsec release guides 2026-09-21 17:49:46 +09:00
Shirofune-Security 63b65e2447 Add reviewed native transcription policy recovery 2026-09-21 17:48:32 +09:00
田中ザック Isaac Mathis b7e649185b Gate conditional IPsec auditing on native prerequisite evidence (#439)
* Gate conditional stronger-profile IPsec auditing on native evidence

* Use supported literal shells in native prerequisite matrix

* Retain native IPsec fixture diagnostics and allow inactive rule omission

* Expose exact native rule fields when prerequisite classification fails

* Recognize native inactive IPsec rules without granting applicability

* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00