Commit Graph
891 Commits
Author SHA1 Message Date
Shirofune-Security fa5141755b Reject unsupported dry runs and preserve freshly observed NTLM restrictions 2026-09-18 22:10:17 +09:00
Shirofune-Security ebd8d14d04 Include read-only Windows CLI profile smoke checks 2026-09-18 22:06:06 +09:00
Shirofune-Security 6392c9bd58 Merge commit 'f4f9c33' into feat/369-missing-audit-controls 2026-09-18 22:05:30 +09:00
Shirofune-Security aa34a0360b Integrate minimum-policy and role-detection safeguards 2026-09-18 22:05:29 +09:00
Shirofune-Security d96f04dcef Integrate profile masks metadata and dry runs with verified execution 2026-09-18 22:05:25 +09:00
Shirofune-Security f4f9c33de2 Exercise real audit CLI export in Windows read-only smoke 2026-09-18 22:05:13 +09:00
Shirofune-Security c7b4e47925 Merge commit 'd3160a2' into feat/369-missing-audit-controls 2026-09-18 22:05:01 +09:00
Shirofune-Security d3160a2033 Preserve additional minimum audit flags and reject unknown CA roles 2026-09-18 22:04:43 +09:00
Shirofune-Security 24dcbdd852 Refresh native audit control evidence assertions for integration 2026-09-18 22:01:53 +09:00
Shirofune-Security 7fc5c0034f Retain profile evidence and prerequisites in integration results
# Conflicts:
#	WELA.ps1
2026-09-18 22:01:04 +09:00
Shirofune-Security a6cef75c12 Verify source attribution and prerequisites in native control results 2026-09-18 22:00:52 +09:00
Shirofune-Security 4432090a6f Merge commit '98d37fb' into feat/369-missing-audit-controls 2026-09-18 22:00:40 +09:00
Shirofune-Security 4a192d7a13 Integrate six missing native audit controls with profile execution 2026-09-18 22:00:30 +09:00
Shirofune-Security d480db5a76 Integrate versioned audit profiles with verified configuration
# Conflicts:
#	.github/workflows/release.yml
#	WELA.ps1
2026-09-18 22:00:30 +09:00
Shirofune-Security 98d37fbf37 Retain policy prerequisites and evidence in apply results 2026-09-18 21:59:59 +09:00
Shirofune-Security 5be186f952 Add six missing native audit subcategories with source-specific masks 2026-09-18 21:58:33 +09:00
Shirofune-Security f2dc28a66b Test composed NTLM policy journaling dry runs and failures 2026-09-18 21:58:06 +09:00
Shirofune-Security e0518b41ed Refresh configuration regression harness for integration 2026-09-18 21:57:42 +09:00
Shirofune-Security f5a19a45fd Integrate verified configuration results for review
# Conflicts:
#	WELA.ps1
2026-09-18 21:56:07 +09:00
Shirofune-Security bf82f2c458 Clear expected child failure codes after regression assertions 2026-09-18 21:56:01 +09:00
Shirofune-Security ee7a0e2216 Unify advanced audit policy audit, plan and configure profiles 2026-09-18 21:54:38 +09:00
Shirofune-Security eb3232faf5 Read audit masks through Windows API and preserve missing registry parents 2026-09-18 21:53:44 +09:00
Shirofune-Security 7979019ef0 Integrate domain NTLM audit role scoping for review
# Conflicts:
#	WELA.ps1
2026-09-18 21:51:44 +09:00
Shirofune-Security 8cb4804334 Integrate outgoing NTLM audit-only behavior for review 2026-09-18 21:51:29 +09:00
Shirofune-Security 36c4b4018f Run configuration checks with explicit PowerShell shells 2026-09-18 21:49:46 +09:00
Shirofune-Security d51c37258f Use explicit PowerShell shells in regression workflow 2026-09-18 21:49:46 +09:00
Shirofune-Security ca54b5cf74 Use explicit PowerShell shells in regression workflow 2026-09-18 21:49:46 +09:00
Shirofune-Security 1ae4930438 Verify configure changes and propagate per-control failures 2026-09-18 21:48:27 +09:00
Shirofune-Security 16d88a6f1e Enable full domain NTLM auditing only on domain controllers 2026-09-18 21:46:28 +09:00
Shirofune-Security ade681ff1b Make outgoing NTLM configuration audit-only by default 2026-09-18 21:46:06 +09:00
Zach Mathis (田中ザック) 8ef938f096 Merge pull request #361 from Shirofune-Security/feat/targeted-object-audit-sacls
Add 'configure-sacl': targeted File System/Registry audit SACLs for detection (no global auditing)
2026-09-14 20:32:50 +09:00
Shirofune-SecurityandClaude Opus 4.8 10c1bcaac7 Address Copilot re-review: %SystemRoot%, Entra SIDs, WOW64 gate, reg-unload check, subcategory-failure, help
- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system
  drive no longer skips every file target.
- Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*.
- WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows.
- reg unload is now checked (retry once, then error) so a failed unload no longer leaves the
  user's NTUSER.DAT mounted under the temp alias while reporting success.
- A failed auditpol subcategory is tracked; the final message warns (instead of claiming success)
  that SACLs for that class will not produce events.
- configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned.

Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with
SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:49:42 +09:00
Shirofune-SecurityandClaude Opus 4.8 570b9565d1 CHANGELOG: note configure additions (#361)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:32:51 +09:00
Shirofune-SecurityandClaude Opus 4.8 35e5329f74 configure: add Process Termination, Detailed File Share, and DC LDAP 1644 logging
Fills the remaining gaps so 'configure' + 'configure-sacl' cover a full detection
baseline out of the box (no manual auditpol/registry needed downstream):
- Detailed Tracking > Process Termination (4689)
- Object Access > Detailed File Share (5145)
- Directory Service LDAP query logging (1644) via NTDS "15 Field Engineering"=5,
  applied only on domain controllers (BloodHound/LDAP recon).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:31:54 +09:00
Shirofune-SecurityandClaude Opus 4.8 d9bef96e0d configure-sacl: use .NET RegistryKey API for SACLs (Get-Acl -Audit is unreliable on the registry)
Live-tested on Windows Server 2019; three bugs fixed found during testing:
- TOKEN_PRIVILEGES had a `long Luid` after a `uint Count`, which is 8-byte aligned on x64
  and inserted padding, so AdjustTokenPrivileges failed with ERROR_NOT_ALL_ASSIGNED and the
  new privilege guard aborted. Split the LUID into LuidLow(uint)+LuidHigh(int) to match the
  native layout.
- Get-Acl/Set-Acl -Audit is unreliable on the registry provider (returns/throws "path does
  not exist" and null). Registry SACLs now use the .NET RegistryKey API
  (OpenSubKey with ReadPermissions,ChangePermissions -> GetAccessControl(Audit) ->
  AddAuditRule -> SetAccessControl), which honors the enabled SeSecurityPrivilege. Absent
  ASEP keys are provisioned via CreateSubKey then reopened.
- Tamper-protected keys (e.g. Defender Exclusions) that deny even admin are reported as
  SKIPPED, not ERROR.

Verified: File System/Registry/Handle subcategories enabled; HKLM Run carries the Everyone
Success+Failure ContainerInherit SACL; a test autorun write produced EventID 4657 - with no
global registry auditing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:24:27 +09:00
Shirofune-SecurityandClaude Opus 4.8 1308bc003d Address Copilot review: privilege check, idempotency, ASEP provisioning, service inheritance, update-rules, CLI
- Enable-WelaPrivilege now validates ERROR_NOT_ALL_ASSIGNED per privilege; Set-AuditSacl
  aborts if SeSecurityPrivilege cannot be enabled (was silently proceeding).
- Idempotency (Test-WelaAuditRulePresent) translates IdentityReference to SID before
  comparing (Get-Acl returns NTAccount, not S-1-1-0) and also compares InheritanceFlags,
  so reruns no longer re-add rules and a non-inheriting rule no longer satisfies an
  inheriting target.
- Absent registry ASEP keys (RunOnceEx, Policies\Explorer\Run, ...) are now provisioned
  (created) before the SACL is applied, so a later attacker write is audited via the
  inheritable ACE instead of being missed.
- Services SACL is now inherited (SetValue,CreateSubKey,Delete) so 4657 on child-service
  ImagePath/ServiceDLL/Start edits and service deletion are captured (4697/7045 only cover
  install).
- update-rules now downloads config/audit_sacl_targets.json, matching the recovery message.
- Dropped the non-functional -WhatIf/-Confirm advertising (the script param block has a
  custom -Debug that precludes CmdletBinding); configure-sacl now uses a single -Auto-skippable
  confirmation prompt, consistent with 'configure'.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:11:03 +09:00
Shirofune-SecurityandClaude Opus 4.8 917037a679 CHANGELOG: note per-user coverage for configure-sacl (#361)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:03:47 +09:00
Shirofune-SecurityandClaude Opus 4.8 31aeeda768 configure-sacl: cover per-user objects across all profiles + Default
Enumerate every user profile from ProfileList (plus C:\Users\Default so future
users inherit the SACL) and apply per-user SACLs:
- user_files: file SACL under each profile dir (Startup folder, Signal AppData).
- user_registry: registry SACL on each user hive - loaded hives via
  HKEY_USERS\<SID> directly, offline/Default hives by reg-load/unload of
  NTUSER.DAT (HKCU Run/RunOnce, User Shell Folders, StartupApproved, Load/Run,
  Command Processor AutoRun, Control Panel\Desktop screensaver, Environment
  logon script, LangBarAddin, Outlook Addins).
Handles are released ([gc]) before reg unload; objects/hives absent on the host
are skipped. Not covered: folder-redirected AppData on network shares, mandatory
profiles.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:03:24 +09:00
Shirofune-SecurityandClaude Opus 4.8 6aef4c0f7b Add CHANGELOG entry for configure-sacl (#361)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 21:51:14 +09:00
Shirofune-SecurityandClaude Opus 4.8 db9a966a8b Add 'configure-sacl': targeted File System/Registry audit SACLs for detection
'configure' already enables Object Access subcategories such as File Share, SAM
and Certification Services, but File System (4663), Registry (4657) and Handle
Manipulation (4656) auditing produce no events without SACLs on the audited
objects - and enabling them globally floods the log. This adds targeted SACLs on
only the autostart/persistence registry keys (ASEPs) and sensitive files that the
Hayabusa/Sigma Security-channel rules actually watch, so those rules can fire
without global object auditing.

- config/audit_sacl_targets.json: curated, commented list of 30 registry keys
  (Run/RunOnce, Winlogon, IFEO, AppInit, Explorer shell extensions, Active Setup,
  Command Processor AutoRun, Session Manager, LSA packages, Winsock LSP, protocol
  handlers, logon scripts, Defender exclusions, service create/delete, ...) and 7
  files (NTDS dir, SAM/SECURITY/SYSTEM hives, lsass.exe, ntdsutil, vssadmin),
  each tagged with the ATT&CK technique / rule class it serves.
- WELA.ps1: new 'configure-sacl' command. Enables the File System / Registry /
  Handle Manipulation subcategories (by GUID) and applies the SACLs from the
  config (principal Everyone, Success+Failure, ContainerInherit on registry keys),
  idempotently, honoring -Auto / -WhatIf / -Confirm. Enables SeSecurityPrivilege
  first; skips objects absent on the host.

Per-user objects (HKCU / profile AppData) and live LSASS memory/handle access are
intentionally out of scope (need a per-user mechanism / Sysmon EID 10) and are
documented as such.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 21:50:25 +09:00
Zach Mathis (田中ザック) 4fdb6b09fc Merge pull request #360 from Yamato-Security/update-mitre
feat: support MITRE ATT&CK v19 in Navigator heatmaps
2026-09-14 19:28:08 +09:00
fukusuket 9834eab011 feat: update MITRE ATT&CK Navigator heatmaps for ATT&CK v19 and handle revoked technique IDs 2026-09-04 05:08:35 +09:00
github-actions[bot]andYamatoSecurity faa7988b87 Sigma Rule Update (2026-09-01 22:29:49) (#359)
Co-authored-by: YamatoSecurity <71482215+YamatoSecurity@users.noreply.github.com>
2026-09-01 22:29:56 +00:00
Zach Mathis (田中ザック) 89f681ac7c Merge pull request #358 from Yamato-Security/refactor-fix-bugs
refactor: move baseline definitions to data and fix detection-logic bugs
2026-09-02 07:10:38 +09:00
fukusuket eee2c58f5a feat: update baselines.json to change currentSetting type to channel and specify DFSN-Server Admin 2026-09-01 23:39:47 +09:00
fukusuket a9ceec469a feat: add DFSN-Server Admin channel to baselines and update changelog 2026-09-01 23:32:53 +09:00
fukusuket a98af726d7 chore: update changelog for version 2.2.0 - Dev Release with improvements and bug fixes 2026-08-31 12:46:17 +09:00
fukusuket dcb183871d fix: remove extraneous closing parenthesis in baselines.json note 2026-08-30 21:20:23 +09:00
fukusuket 8d8e401fdb fix: correct spelling errors in baselines.json settings 2026-08-30 21:19:11 +09:00
fukusuket dcf29e4a59 fix: update .gitignore and release workflows for new output files and README changes 2026-08-30 21:08:16 +09:00