Commit Graph
232 Commits
Author SHA1 Message Date
Shirofune-Security f5a19a45fd Integrate verified configuration results for review
# Conflicts:
#	WELA.ps1
2026-09-18 21:56:07 +09:00
Shirofune-Security 7979019ef0 Integrate domain NTLM audit role scoping for review
# Conflicts:
#	WELA.ps1
2026-09-18 21:51:44 +09:00
Shirofune-Security 1ae4930438 Verify configure changes and propagate per-control failures 2026-09-18 21:48:27 +09:00
Shirofune-Security 16d88a6f1e Enable full domain NTLM auditing only on domain controllers 2026-09-18 21:46:28 +09:00
Shirofune-Security ade681ff1b Make outgoing NTLM configuration audit-only by default 2026-09-18 21:46:06 +09:00
Zach Mathis (田中ザック) 8ef938f096 Merge pull request #361 from Shirofune-Security/feat/targeted-object-audit-sacls
Add 'configure-sacl': targeted File System/Registry audit SACLs for detection (no global auditing)
2026-09-14 20:32:50 +09:00
Shirofune-SecurityandClaude Opus 4.8 10c1bcaac7 Address Copilot re-review: %SystemRoot%, Entra SIDs, WOW64 gate, reg-unload check, subcategory-failure, help
- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system
  drive no longer skips every file target.
- Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*.
- WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows.
- reg unload is now checked (retry once, then error) so a failed unload no longer leaves the
  user's NTUSER.DAT mounted under the temp alias while reporting success.
- A failed auditpol subcategory is tracked; the final message warns (instead of claiming success)
  that SACLs for that class will not produce events.
- configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned.

Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with
SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:49:42 +09:00
Shirofune-SecurityandClaude Opus 4.8 35e5329f74 configure: add Process Termination, Detailed File Share, and DC LDAP 1644 logging
Fills the remaining gaps so 'configure' + 'configure-sacl' cover a full detection
baseline out of the box (no manual auditpol/registry needed downstream):
- Detailed Tracking > Process Termination (4689)
- Object Access > Detailed File Share (5145)
- Directory Service LDAP query logging (1644) via NTDS "15 Field Engineering"=5,
  applied only on domain controllers (BloodHound/LDAP recon).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:31:54 +09:00
Shirofune-SecurityandClaude Opus 4.8 d9bef96e0d configure-sacl: use .NET RegistryKey API for SACLs (Get-Acl -Audit is unreliable on the registry)
Live-tested on Windows Server 2019; three bugs fixed found during testing:
- TOKEN_PRIVILEGES had a `long Luid` after a `uint Count`, which is 8-byte aligned on x64
  and inserted padding, so AdjustTokenPrivileges failed with ERROR_NOT_ALL_ASSIGNED and the
  new privilege guard aborted. Split the LUID into LuidLow(uint)+LuidHigh(int) to match the
  native layout.
- Get-Acl/Set-Acl -Audit is unreliable on the registry provider (returns/throws "path does
  not exist" and null). Registry SACLs now use the .NET RegistryKey API
  (OpenSubKey with ReadPermissions,ChangePermissions -> GetAccessControl(Audit) ->
  AddAuditRule -> SetAccessControl), which honors the enabled SeSecurityPrivilege. Absent
  ASEP keys are provisioned via CreateSubKey then reopened.
- Tamper-protected keys (e.g. Defender Exclusions) that deny even admin are reported as
  SKIPPED, not ERROR.

Verified: File System/Registry/Handle subcategories enabled; HKLM Run carries the Everyone
Success+Failure ContainerInherit SACL; a test autorun write produced EventID 4657 - with no
global registry auditing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:24:27 +09:00
Shirofune-SecurityandClaude Opus 4.8 1308bc003d Address Copilot review: privilege check, idempotency, ASEP provisioning, service inheritance, update-rules, CLI
- Enable-WelaPrivilege now validates ERROR_NOT_ALL_ASSIGNED per privilege; Set-AuditSacl
  aborts if SeSecurityPrivilege cannot be enabled (was silently proceeding).
- Idempotency (Test-WelaAuditRulePresent) translates IdentityReference to SID before
  comparing (Get-Acl returns NTAccount, not S-1-1-0) and also compares InheritanceFlags,
  so reruns no longer re-add rules and a non-inheriting rule no longer satisfies an
  inheriting target.
- Absent registry ASEP keys (RunOnceEx, Policies\Explorer\Run, ...) are now provisioned
  (created) before the SACL is applied, so a later attacker write is audited via the
  inheritable ACE instead of being missed.
- Services SACL is now inherited (SetValue,CreateSubKey,Delete) so 4657 on child-service
  ImagePath/ServiceDLL/Start edits and service deletion are captured (4697/7045 only cover
  install).
- update-rules now downloads config/audit_sacl_targets.json, matching the recovery message.
- Dropped the non-functional -WhatIf/-Confirm advertising (the script param block has a
  custom -Debug that precludes CmdletBinding); configure-sacl now uses a single -Auto-skippable
  confirmation prompt, consistent with 'configure'.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:11:03 +09:00
Shirofune-SecurityandClaude Opus 4.8 31aeeda768 configure-sacl: cover per-user objects across all profiles + Default
Enumerate every user profile from ProfileList (plus C:\Users\Default so future
users inherit the SACL) and apply per-user SACLs:
- user_files: file SACL under each profile dir (Startup folder, Signal AppData).
- user_registry: registry SACL on each user hive - loaded hives via
  HKEY_USERS\<SID> directly, offline/Default hives by reg-load/unload of
  NTUSER.DAT (HKCU Run/RunOnce, User Shell Folders, StartupApproved, Load/Run,
  Command Processor AutoRun, Control Panel\Desktop screensaver, Environment
  logon script, LangBarAddin, Outlook Addins).
Handles are released ([gc]) before reg unload; objects/hives absent on the host
are skipped. Not covered: folder-redirected AppData on network shares, mandatory
profiles.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:03:24 +09:00
Shirofune-SecurityandClaude Opus 4.8 db9a966a8b Add 'configure-sacl': targeted File System/Registry audit SACLs for detection
'configure' already enables Object Access subcategories such as File Share, SAM
and Certification Services, but File System (4663), Registry (4657) and Handle
Manipulation (4656) auditing produce no events without SACLs on the audited
objects - and enabling them globally floods the log. This adds targeted SACLs on
only the autostart/persistence registry keys (ASEPs) and sensitive files that the
Hayabusa/Sigma Security-channel rules actually watch, so those rules can fire
without global object auditing.

- config/audit_sacl_targets.json: curated, commented list of 30 registry keys
  (Run/RunOnce, Winlogon, IFEO, AppInit, Explorer shell extensions, Active Setup,
  Command Processor AutoRun, Session Manager, LSA packages, Winsock LSP, protocol
  handlers, logon scripts, Defender exclusions, service create/delete, ...) and 7
  files (NTDS dir, SAM/SECURITY/SYSTEM hives, lsass.exe, ntdsutil, vssadmin),
  each tagged with the ATT&CK technique / rule class it serves.
- WELA.ps1: new 'configure-sacl' command. Enables the File System / Registry /
  Handle Manipulation subcategories (by GUID) and applies the SACLs from the
  config (principal Everyone, Success+Failure, ContainerInherit on registry keys),
  idempotently, honoring -Auto / -WhatIf / -Confirm. Enables SeSecurityPrivilege
  first; skips objects absent on the host.

Per-user objects (HKCU / profile AppData) and live LSASS memory/handle access are
intentionally out of scope (need a per-user mechanism / Sysmon EID 10) and are
documented as such.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 21:50:25 +09:00
fukusuket 9834eab011 feat: update MITRE ATT&CK Navigator heatmaps for ATT&CK v19 and handle revoked technique IDs 2026-09-04 05:08:35 +09:00
fukusuket a9ceec469a feat: add DFSN-Server Admin channel to baselines and update changelog 2026-09-01 23:32:53 +09:00
fukusuket a98af726d7 chore: update changelog for version 2.2.0 - Dev Release with improvements and bug fixes 2026-08-31 12:46:17 +09:00
fukusuket dcf29e4a59 fix: update .gitignore and release workflows for new output files and README changes 2026-08-30 21:08:16 +09:00
YamatoSecurity f8d259e895 update changelog 2026-02-13 09:28:11 +09:00
fukusuket a90b6caeed fix: improve module logging path checks in WELA.ps1 2026-02-12 23:35:55 +09:00
fukusuket a6fba5dc9a fix: optimize registry path checks in WELA.ps1 2026-02-12 23:31:24 +09:00
fukusuket 7a8ce70e16 fix: update default auditing values in WELA.ps1 2025-11-16 19:05:38 +09:00
fukusuket 9d2d60a77a fix: adjust default value for PowerShell operational logging 2025-11-16 17:26:38 +09:00
fukusuket b8b591f41e fix: update default auditing values in WELA.ps1 2025-11-16 17:14:22 +09:00
fukusuket 061fb8dc9c fix: update attack and navigator versions in WELA.ps1 2025-11-15 13:06:48 +09:00
fukusuket 87aa4ca3f3 chore: update WELA.ps1 to display release version in output 2025-11-15 13:04:29 +09:00
fukusuket ea8ae2ba07 chore: update WELA.ps1 header for CODE BLUE release v2.0.0 2025-11-15 12:43:10 +09:00
fukusuket 288feca218 fix: remove service restart from AuditFilter setting command in WELA.ps1 2025-11-15 10:41:55 +09:00
fukusuket f07fbfbe2c fix: remove redundant output for AuditFilter setting in WELA.ps1 2025-11-15 10:38:04 +09:00
fukusuket 34ce48c886 fix: remove unnecessary output for AD CS AuditFilter configuration in WELA.ps1 2025-11-15 10:36:38 +09:00
fukusuket 08da2a2d59 fix: remove redundant registry output for AuditFilter check in WELA.ps1 2025-11-15 10:35:06 +09:00
fukusuket 775a716c90 fix: update AuditFilter setting command for improved error handling in WELA.ps1 2025-11-15 10:34:07 +09:00
fukusuket 4d93de3bb5 fix: enhance auditing setup with new auditpol configurations and batch script for event log management 2025-11-15 10:27:34 +09:00
fukusuket 7559cfea84 fix: add AD CS AuditFilter configuration to streamline auditing setup in WELA.ps1 2025-11-15 10:22:36 +09:00
fukusuket 22b469cb5e fix: add Set-RegistryConfig function for streamlined registry configuration in WELA.ps1 2025-11-08 09:15:46 +09:00
fukusuket eb81232e7e fix: optimize rule counting logic in WELA.ps1 for improved performance 2025-11-02 02:05:30 +09:00
fukusuket 4fdf712dbf fix: update auditing logic in WELA.ps1 to differentiate between 'No Auditing' and 'Disabled' settings 2025-11-02 00:48:05 +09:00
fukusuket f30868aa10 fix: add Crypto-DPAPI Debug log size configuration to WELA.ps1 2025-11-02 00:27:00 +09:00
fukusuket b4db197218 fix: add Crypto-DPAPI Debug logging support to WELA.ps1 2025-11-02 00:26:06 +09:00
fukusuket 32183f0592 fix: enhance WELA.ps1 to handle empty Baseline parameter and update help messages for audit commands 2025-10-25 09:03:00 +09:00
fukusuket f920e9aaf6 fix: add Help switch to WELA.ps1 for usage instructions in audit commands 2025-10-23 23:19:51 +09:00
fukusuket 11beefd929 fix: add Baseline parameter to WELA.ps1 for enhanced configuration options 2025-10-22 23:10:33 +09:00
fukusuket 010185e1ad fix: update WELA.ps1 to handle empty Baseline parameter and provide usage examples for configure command 2025-10-22 23:09:02 +09:00
fukusuket 4413e317f0 fix: update ConfigureAuditSettings function to accept Auto parameter and add new audit policy configuration script 2025-10-22 00:29:55 +09:00
fukusuket 88e7aa8c80 fix: update parameter invocation for ConfigureAuditSettings function 2025-10-22 00:27:24 +09:00
fukusuket cd5ad60449 fix: remove default value for Auto parameter in ConfigureAuditSettings function 2025-10-22 00:23:28 +09:00
fukusuket 93eac259b0 fix: set default value for Auto parameter in ConfigureAuditSettings function 2025-10-22 00:20:35 +09:00
fukusuket 3f5b4ee2bb fix: update log size message from 1 GB to 1024 MB in WELA.ps1 2025-10-22 00:18:41 +09:00
fukusuket 50d010a940 fix: update log size message from 1 GB to 1024 MB in WELA.ps1 2025-10-22 00:13:17 +09:00
fukusuket e23e921382 feat: add command execution for auditpol and improve module logging prompts in WELA.ps1 2025-10-22 00:10:50 +09:00
fukusuket 09363063d3 feat: add auto-configuration option to ConfigureAuditSettings in WELA.ps1 2025-10-21 23:18:49 +09:00
fukusuket f1be0ad4e1 feat: update WELA.ps1 to display audit results in GUI format 2025-10-19 17:27:15 +09:00