Shirofune-Security
|
f180ca72ae
|
Merge latest dev before registry probe merge
|
2026-09-22 18:16:38 +09:00 |
|
田中ザック Isaac Mathis
|
50448ae19a
|
Merge pull request #471 from Shirofune-Security/feat/364-scoped-process-commandline
Add scoped process command-line audit policy configuration
|
2026-09-22 18:16:10 +09:00 |
|
Shirofune-Security
|
92f2be18de
|
Merge latest dev before process command-line merge
|
2026-09-22 18:15:57 +09:00 |
|
田中ザック Isaac Mathis
|
91932c74c7
|
Merge pull request #470 from Shirofune-Security/feat/376-scoped-powershell-logging
Add scoped Windows PowerShell module and script-block logging
|
2026-09-22 18:14:38 +09:00 |
|
Shirofune-Security
|
d20be8ff51
|
Merge latest dev before registry probe merge
|
2026-09-22 18:14:25 +09:00 |
|
Shirofune-Security
|
f73c96e44c
|
Merge latest dev before process command-line merge
|
2026-09-22 18:14:15 +09:00 |
|
Shirofune-Security
|
c56a6f14d6
|
Merge latest dev before PowerShell logging merge
|
2026-09-22 18:14:07 +09:00 |
|
田中ザック Isaac Mathis
|
4af844bea2
|
Merge pull request #469 from Shirofune-Security/feat/372-reviewed-wmi-descendants
Guard explicit WMI inheritance with reviewed descendant evidence
|
2026-09-22 18:13:51 +09:00 |
|
Shirofune-Security
|
3db5d73180
|
Merge latest dev before process command-line integration
|
2026-09-22 18:13:26 +09:00 |
|
Shirofune-Security
|
dee12fa965
|
Merge latest dev before PowerShell logging integration
|
2026-09-22 18:13:17 +09:00 |
|
Shirofune-Security
|
7966529cc5
|
Merge latest dev before WMI descendants integration
|
2026-09-22 18:13:07 +09:00 |
|
Shirofune-Security
|
ea8b4f152c
|
Merge latest dev before registry probe integration
|
2026-09-22 18:12:57 +09:00 |
|
田中ザック Isaac Mathis
|
46b88daa3c
|
Merge pull request #468 from Shirofune-Security/feat/372-reviewed-wmi-recovery
Recover one proven parent-only WMI namespace audit ACE
|
2026-09-22 18:12:25 +09:00 |
|
Shirofune-Security
|
53d9eddb86
|
Preserve literal registry types when projecting logging capacity
|
2026-09-22 15:44:16 +09:00 |
|
Shirofune-Security
|
32cfb460a2
|
Accept native UInt16 CIM domain roles in registry probe preflight
|
2026-09-22 15:32:00 +09:00 |
|
Shirofune-Security
|
fb0a424da8
|
Reject scoped logging changes that overflow bounded policy inventories
|
2026-09-22 15:19:20 +09:00 |
|
田中ザック Isaac Mathis
|
4eabfe329c
|
Merge pull request #436 from Shirofune-Security/feat/376-current-token-transcript
Verify current-account automatic PowerShell transcripts
|
2026-09-22 15:14:12 +09:00 |
|
田中ザック Isaac Mathis
|
bbedaab966
|
Merge pull request #437 from Shirofune-Security/feat/373-file-sacl-recovery
Add guarded recovery of one selected leaf-file audit ACE
|
2026-09-22 15:14:06 +09:00 |
|
田中ザック Isaac Mathis
|
fcb57f1887
|
Merge pull request #435 from Shirofune-Security/feat/365-named-registry-recovery
Recover named logging DWORDs from completed configuration journals
|
2026-09-22 15:14:00 +09:00 |
|
田中ザック Isaac Mathis
|
9bc98d4439
|
Merge pull request #434 from Shirofune-Security/feat/386-native-dns-client-probe
Add fixed native DNS Client event3008 probe
|
2026-09-22 15:13:54 +09:00 |
|
田中ザック Isaac Mathis
|
e9dc90e39a
|
Merge pull request #433 from Shirofune-Security/feat/382-native-evtx-reader
Verify exact EVTX recovery under the intended reader token
|
2026-09-22 15:11:59 +09:00 |
|
田中ザック Isaac Mathis
|
e93ea3e7ea
|
Merge pull request #467 from Shirofune-Security/feat/380-native-token-right-probe
Verify native Security4703 audit attribution on Windows Server
|
2026-09-22 15:11:28 +09:00 |
|
田中ザック Isaac Mathis
|
a4c17bb814
|
Merge pull request #466 from Shirofune-Security/test/378-native-onesettings-configure
Fix notification defaults and verify OneSettings configuration on Windows
|
2026-09-22 15:11:24 +09:00 |
|
田中ザック Isaac Mathis
|
65831b747b
|
Merge pull request #465 from Shirofune-Security/feat/363-scoped-ntlm-auditing
Add scoped incoming and domain NTLM audit configuration
|
2026-09-22 15:09:31 +09:00 |
|
Shirofune-Security
|
66162232b6
|
Integrate reviewed logging and recovery base for WMI tree safeguards
|
2026-09-22 15:08:52 +09:00 |
|
Shirofune-Security
|
81c01330b8
|
Merge final reviewed dev sources and preserve literal CLI arguments
|
2026-09-22 15:08:26 +09:00 |
|
Shirofune-Security
|
7e1b076254
|
Integrate approved dev command and recovery additions
|
2026-09-22 15:07:44 +09:00 |
|
Shirofune-Security
|
2b992f06e6
|
Integrate approved dev command and recovery additions
|
2026-09-22 15:07:20 +09:00 |
|
Shirofune-Security
|
bfa286bf7d
|
Integrate reviewed WMI recovery with combined dev auditing batch
|
2026-09-22 15:06:51 +09:00 |
|
Shirofune-Security
|
e584345df3
|
Integrate approved native recovery PRs before dev merge
|
2026-09-22 15:05:40 +09:00 |
|
Shirofune-Security
|
2b270042e7
|
Stack leaf-file recovery and preserve scoped NTLM dry-run integration
|
2026-09-22 15:03:17 +09:00 |
|
Shirofune-Security
|
3c47442634
|
Stack named registry recovery on reviewed logging integration
|
2026-09-22 15:01:03 +09:00 |
|
Shirofune-Security
|
16f9e69844
|
Stack native DNS probe on intended-reader recovery and approved dev
|
2026-09-22 14:59:41 +09:00 |
|
Shirofune-Security
|
d72bf939a7
|
Reserve registry probe capacity and isolate exact-value cleanup
|
2026-09-22 14:59:21 +09:00 |
|
Shirofune-Security
|
d5de556f74
|
Retain partial WMI tree observations after a parent write
|
2026-09-22 14:58:07 +09:00 |
|
Shirofune-Security
|
4ab4c275a5
|
Preserve positional bindings and propagate native fixture failures
|
2026-09-22 14:57:47 +09:00 |
|
Shirofune-Security
|
1dfd3a92b9
|
Stack intended-reader EVTX recovery on the approved native auditing batch
|
2026-09-22 14:56:09 +09:00 |
|
Shirofune-Security
|
9575c8204d
|
Add fixed current-user registry value audit probe
|
2026-09-22 14:55:12 +09:00 |
|
Shirofune-Security
|
75c978b9a2
|
Preserve legacy positional CLI parameter bindings
|
2026-09-22 14:54:58 +09:00 |
|
田中ザック Isaac Mathis
|
5978665580
|
Merge pull request #464 from Shirofune-Security/feat/368-native-wef-query
Add exact native WEF source query preflight
|
2026-09-22 14:54:19 +09:00 |
|
Shirofune-Security
|
488d179f09
|
Count the root in bounded WMI descriptor evidence
|
2026-09-22 14:49:07 +09:00 |
|
Shirofune-Security
|
adaf3f9681
|
Retain actual process identity for scoped logging and native attribution
|
2026-09-22 14:48:45 +09:00 |
|
Shirofune-Security
|
e34ede7c38
|
Require exact native inherited and protected subtree outcomes
|
2026-09-22 14:46:26 +09:00 |
|
Shirofune-Security
|
8aee77cfea
|
Bound unrelated command-line policy inventory
|
2026-09-22 14:46:25 +09:00 |
|
Shirofune-Security
|
8546d319eb
|
Reject unexplained descendant changes and unrelated WMI command arguments
|
2026-09-22 14:45:06 +09:00 |
|
Shirofune-Security
|
e419b073fe
|
Document scoped PowerShell controls and align native evidence boundaries
|
2026-09-22 14:43:40 +09:00 |
|
Shirofune-Security
|
ab45d03f15
|
Add reviewed removal of one proven parent-only WMI audit ACE
|
2026-09-22 14:43:33 +09:00 |
|
Shirofune-Security
|
ddcdd8e2b8
|
Document bounded WMI tree guarantees and record native protection behavior
|
2026-09-22 14:40:25 +09:00 |
|
Shirofune-Security
|
3f613ea19c
|
Add scoped Windows PowerShell logging policy and native validation
|
2026-09-22 14:37:38 +09:00 |
|
Shirofune-Security
|
036f51886a
|
Exercise descendant drift and use supported workflow shell dispatch
|
2026-09-22 14:36:48 +09:00 |
|