Commit Graph
162 Commits
Author SHA1 Message Date
Shirofune-Security 4905f82eb5 Add reviewed WEC listener CLI contract and operator guide 2026-09-21 22:40:05 +09:00
Shirofune-Security 506333c501 Use a fixed native Windows PowerShell 5.1 listener adapter 2026-09-21 22:36:15 +09:00
Shirofune-Security c1aaa693ac Pass explicit held listener XML through the typed native cmdlet 2026-09-21 22:30:13 +09:00
Shirofune-Security 25fa7200a0 Checkpoint native local WSMan create with fixed listener XML 2026-09-21 22:27:05 +09:00
Shirofune-Security 72c2d14046 Merge branch 'feat/375-firewall-log-recovery' into feat/368-reviewed-wec-listener 2026-09-21 22:24:50 +09:00
Shirofune-Security 8fed328442 Integrate the reviewed recovery and native probe batch 2026-09-21 22:23:25 +09:00
Shirofune-Security b018135e73 Use canonical WSMan listener resource URI across PowerShell engines 2026-09-21 22:22:50 +09:00
Shirofune-Security 2f442af4da Integrate reviewed recovery and failed-logon commands 2026-09-21 22:21:35 +09:00
Shirofune-Security c4e9e765ff Integrate reviewed event-log recovery and failed-logon changes 2026-09-21 22:20:02 +09:00
Shirofune-Security 504e36c15e Checkpoint exact-IP WinRM listener creation on native Windows 2026-09-21 22:14:53 +09:00
Shirofune-Security 89f520511b Merge dev after failed-logon probe integration 2026-09-21 22:13:52 +09:00
田中ザック Isaac Mathis 6d228fedef Add a native local failed-logon audit probe (#444)
* Add native local nonexistent-account failed-logon probe

* Match actual MSV1 local authentication event package

* Refuse coerced identity and authentication receipt fields

* Preserve explicit UTC DateTime receipts on older PowerShell7

* Reject unknown failed-logon probe options before dispatch
2026-09-21 22:13:20 +09:00
Shirofune-Security 2d208f457a Refuse unknown recovery options before native restoration 2026-09-21 18:24:06 +09:00
Shirofune-Security dc1e354475 Reject unbound preview and positional probe arguments 2026-09-21 18:23:54 +09:00
Shirofune-Security 6980657337 Reject unbound recovery options before command dispatch 2026-09-21 18:23:53 +09:00
Shirofune-Security 6bf4360362 Merge final dev and verify strict transcription recovery CLI 2026-09-21 18:22:31 +09:00
Shirofune-Security 9bc243a041 Integrate final reviewed development base for CAPI2 probe 2026-09-21 18:21:10 +09:00
Shirofune-Security e61056caba Merge final dev and preserve recovery and ingress command handlers 2026-09-21 18:21:06 +09:00
Shirofune-Security 3abe3018ba Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:20:57 +09:00
Shirofune-Security 22d3a13180 Reject coerced transcription recovery history discriminators 2026-09-21 18:19:57 +09:00
田中ザック Isaac Mathis 203fdfc942 Add reviewed scoped collector firewall ingress creation (#442)
* Add reviewed scoped collector firewall ingress creation

* Avoid Windows Clear-Item alias in native ingress fixture

* Handle native nullable package scope and retain bounded filter evidence

* Match native firewall network spelling in collector prerequisites
2026-09-21 18:19:30 +09:00
Shirofune-Security fa720f1454 Bind the reviewed native host gate and context dependency 2026-09-21 18:17:23 +09:00
Shirofune-Security e4e60684ac Verify stopped providers are refused before connecting 2026-09-21 18:15:30 +09:00
Shirofune-Security 3ee0d7b6bd Require typed completion and identity fields in recovery evidence 2026-09-21 18:14:13 +09:00
Shirofune-Security e068bd8f52 Merge dev and preserve independent recovery and WEC commands 2026-09-21 18:11:29 +09:00
Shirofune-Security dd950c7358 Reject boolean coercion in completed recovery evidence 2026-09-21 18:11:21 +09:00
Shirofune-Security ec21453cf2 Bind strict receipt parser into CAPI2 source evidence 2026-09-21 18:11:13 +09:00
Shirofune-Security 07e3d37265 Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:09:42 +09:00
田中ザック Isaac Mathis 9d03a19082 Activate native SMB audit runtime switches explicitly (#441)
* Add explicit native SMB runtime audit activation

* Select explicit PowerShell workflow shells and link PR changelog

* Clear expected refusal child exit codes after assertions

* Retain native SMB command provenance in capability diagnostics

* Bind SMB command guards to observed native CDXML module identities
2026-09-21 18:09:10 +09:00
Shirofune-Security 6f779a7dd4 Require exact generated certificate DER bytes 2026-09-21 18:06:27 +09:00
Shirofune-Security d590e8226a Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 18:04:28 +09:00
Shirofune-Security 1572d2b128 Pin observed CAPI2 XML and require existing running services 2026-09-21 18:03:42 +09:00
Shirofune-Security e8b018d5c9 Refuse ambiguous Windows path aliases during recovery 2026-09-21 17:56:45 +09:00
Shirofune-Security a5f674e3f8 Sign public certificate without copying its ephemeral private key 2026-09-21 17:56:04 +09:00
Shirofune-Security 8c6a597425 Cover CIS recovery paths and bound retained native evidence 2026-09-21 17:55:25 +09:00
田中ザック Isaac Mathis b4fb77da02 Review and apply existing WEC subscription enable/disable (#440)
* Add reviewed existing WEC subscription state transitions

* Validate WEC destination and retain failed activation state
2026-09-21 17:54:55 +09:00
Shirofune-Security 2e329c7f2f Preserve policy arrays through Windows PowerShell JSON roundtrips 2026-09-21 17:54:51 +09:00
Shirofune-Security 7184918f66 Create an unnamed CNG key through typed native helper 2026-09-21 17:53:39 +09:00
Shirofune-Security afc748188d Merge branch 'dev' of https://github.com/Yamato-Security/WELA into feat/375-firewall-log-recovery
# Conflicts:
#	.github/workflows/release.yml
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-21 17:52:42 +09:00
Shirofune-Security 23f88776bf Add guarded single-profile firewall logging recovery 2026-09-21 17:52:23 +09:00
Shirofune-Security 718ef8c91d Add fixed offline CAPI2 chain source probe 2026-09-21 17:51:31 +09:00
Shirofune-Security 1ea0687616 Merge dev and preserve recovery and IPsec release guides 2026-09-21 17:49:46 +09:00
Shirofune-Security 63b65e2447 Add reviewed native transcription policy recovery 2026-09-21 17:48:32 +09:00
田中ザック Isaac Mathis b7e649185b Gate conditional IPsec auditing on native prerequisite evidence (#439)
* Gate conditional stronger-profile IPsec auditing on native evidence

* Use supported literal shells in native prerequisite matrix

* Retain native IPsec fixture diagnostics and allow inactive rule omission

* Expose exact native rule fields when prerequisite classification fails

* Recognize native inactive IPsec rules without granting applicability

* Restore standalone regression loading and valid owned IPsec auth defaults
2026-09-21 17:42:53 +09:00
Shirofune-Security d1d40b4a25 Add reviewed recovery of completed event-log size and retention changes 2026-09-21 17:42:52 +09:00
田中ザック Isaac Mathis 7cd2eb9dbf Use precise native UTC for WMI probe event intervals (#438) 2026-09-21 17:30:16 +09:00
田中ザック Isaac Mathis fd7a7924aa Verify actual current-token access to built-in event channels (#432)
* Add actual current-token native channel read evidence

* Use supported workflow shells and link channel-read changelogs

* Handle real event exceptions and bind loaded token helper to source

* Capture query-token interval after evidence and metadata preparation

* Retain native child process exit evidence across PowerShell engines

* Bound native reader fixture pipe draining and child termination

* Preserve native errors from attributed channel query statuses
2026-09-21 09:18:46 +09:00
田中ザック Isaac Mathis c6da22a2ad Resume a reviewed pending AD CS auditing restart (#431)
* Add reviewed recovery for a pending AD CS auditing restart

* Link pending CA restart recovery changelogs to PR 431
2026-09-21 09:16:39 +09:00
田中ザック Isaac Mathis 2fd37d0318 Measure bounded native event delivery and verify exact EVTX samples (#430)
* Add bounded local delivery measurement and exact EVTX samples

* Link delivery measurement changelog to PR 430

* Reject evidence aliases before Windows path normalization

* Use PowerShell 5.1-compatible record IDs and bound fixture cleanup

* Revalidate the native EVTX artifact before recording final evidence

* Require exact observed local computer identities for sampled events

* Clarify provider scope within shared built-in event channels

* Preserve mixed XML payload ordering in EVTX sample verification

* Bound ordered event XML comparisons for nested UserData

* Dispose observer wait handle when bookmark creation fails
2026-09-21 09:14:48 +09:00
田中ザック Isaac Mathis bcd4e9717e Verify reviewed descendant SACL propagation and preservation (#429)
* Verify reviewed descendant SACL propagation and preservation

* Reference descendant SACL PR429 in release notes

* Prepare protected disposable SACL fixtures through native handles

* Use read-control handles for disposable native SACL protection
2026-09-21 09:12:56 +09:00