Commit Graph
1011 Commits
Author SHA1 Message Date
田中ザック Isaac Mathis ff0e5c1890 Apply reviewed SACL plans to explicitly selected local targets (#422)
* Add reviewed configuration for selected native SACL targets

* Link selected SACL changelog to PR 422

* Identify native full-descriptor read failures without partial fallback

* Fix diagnostic variable scope in native C# helper

* Read explicit descriptor sections and retain observation scope
2026-09-20 19:36:05 +09:00
田中ザック Isaac Mathis f1c1f74166 Guard AD CS audit configuration and collect native request evidence (#421)
* Add guarded native CA auditing and disposable request evidence

* Link AD CS changelog to PR 421

* Retain primary native CA failure before cleanup diagnostics

* Normalize native CA certificate hashes and record pending feature removal

* Emit bounded disposable CA request matching diagnostics

* Match observed version 1 CA request events with exact pending disposition
2026-09-20 19:34:03 +09:00
田中ザック Isaac Mathis 38a392f3d6 Export and verify recovery of native probe events from EVTX (#420)
* Export and recover exact native probe events from EVTX

* Link changelog to PR 420

* Make EVTX duplicate JSON fixture portable to PowerShell 5.1
2026-09-20 19:33:20 +09:00
田中ザック Isaac Mathis 60006531be Restore selected audit changes from reviewed recovery evidence (#419)
* Add guarded restoration of selected completed audit writes

* Link changelog to PR 419

* Read recovery host name from Windows instead of environment overrides

* Require local fixed-drive recovery output paths
2026-09-20 19:30:49 +09:00
田中ザック Isaac Mathis e5557df038 Verify native probe arrival in the local WEF collector (#418)
* Verify native probe presence in the local WEF collector

* Link WEF arrival changelog to PR 418

* Make duplicate JSON fixture independent of PowerShell formatting
2026-09-20 19:26:57 +09:00
田中ザック Isaac Mathis f21a9f30e4 Add transparent configuration and native rule readiness scores (#417)
* Add transparent native audit compliance and evidence readiness scores

* Link transparent audit scoring changelog to PR 417

* Resolve scoring outputs against the PowerShell filesystem location
2026-09-20 18:15:04 +09:00
田中ザック Isaac Mathis 3a80ef5e67 Add reviewable GPO audit-policy deployment packages (#415)
* Add reviewable GPO audit-policy deployment components

* Link GPO audit package changelog to PR 415

* Check GPO verification exit code from a real CLI process
2026-09-20 18:13:34 +09:00
田中ザック Isaac Mathis ec6a6df68a Export native audit profiles for reviewed Intune client policies (#414)
* Add offline Intune Audit CSP exports from shared client profiles

* Link Intune audit export changelog to PR 414
2026-09-20 18:10:52 +09:00
田中ザック Isaac Mathis 83b2ddd526 Support validated custom audit profile files through the shared engine (#416)
* Support validated operator-owned advanced audit profile files

* Reject lenient custom profile JSON and protect report output aliases

* Link custom audit profile changelog to PR 416

* Make custom JSON rejection fixtures portable across PowerShell versions
2026-09-20 18:09:52 +09:00
田中ザック Isaac Mathis 4431533535 Collect native 4688 validation components with a fixed benign probe (#413)
* Add opt-in native 4688 validation component collector

* Link native validation changelog to PR 413

* Reject contradictory native probe context observations

* Resolve probe artifact paths against the PowerShell location
2026-09-20 18:08:34 +09:00
田中ザック Isaac Mathis 7719063f6f Add source-specific Windows audit privilege and integrity controls (#412)
* Add opt-in source-profile audit integrity controls

* Reference PR 412 in audit-integrity changelogs
2026-09-20 14:03:18 +09:00
田中ザック Isaac Mathis 55cc427c61 Report native log retention and collection health evidence (#410)
* Add read-only native retention and collection health evidence reports

* Verify retention HTML evidence across PowerShell JSON serializers

* Reference PR 410 in retention changelogs

* Preserve previous-report arrays on Windows PowerShell and test both server releases
2026-09-20 14:01:43 +09:00
田中ザック Isaac Mathis 14ac8667d4 Gate historical controls and require evidence for Windows defaults (#409)
* Gate historical controls and require provenance for Windows defaults

* Bind default evidence to UTC provenance and native architecture

* Reference PR 409 in applicability changelogs
2026-09-20 14:00:10 +09:00
田中ザック Isaac Mathis d35b1374d0 Add opt-in native DNS and provider audit packs (#411)
* Add selective native provider packs with pinned rule and schema evidence

* Reference PR 411 in provider-pack changelogs

* Fix provider pack service reader export and CI exit propagation
2026-09-20 13:58:49 +09:00
田中ザック Isaac Mathis 35aca8f494 Add OneSettings auditing and Security warning controls (#408)
* Add explicit OneSettings auditing and Security warning controls

* Reference PR 408 in notification changelogs

* Handle expected child CLI failure under Windows PowerShell 5.1

* Block dependent Privacy channel changes when OneSettings policy drifts

* Recheck notification producer prerequisites at channel write boundaries
2026-09-20 13:55:24 +09:00
田中ザック Isaac Mathis e4a6f67ab3 Merge pull request #407 from Shirofune-Security/feat/387-native-rule-eligibility
Report native rule eligibility with pinned inputs and evidence gates
2026-09-20 08:47:15 +09:00
田中ザック Isaac Mathis c34fcc2774 Merge pull request #406 from Shirofune-Security/feat/368-wef-deployment
Add opt-in native WEF source and collector provisioning
2026-09-20 08:42:42 +09:00
田中ザック Isaac Mathis 39c82dcf00 Merge pull request #405 from Shirofune-Security/feat/376-powershell-transcription
Add opt-in Windows PowerShell transcription for CIS Level 2
2026-09-20 08:39:53 +09:00
田中ザック Isaac Mathis 3172ea1101 Merge pull request #404 from Shirofune-Security/feat/383-ldap-diagnostics
Make LDAP 1644 diagnostics explicit and preserve existing DC settings
2026-09-20 08:39:13 +09:00
田中ザック Isaac Mathis 72704d4780 Merge pull request #403 from Shirofune-Security/fix/380-audit-catalog-mappings
Correct token audit GUID and validate catalog mapping uncertainty
2026-09-20 08:36:22 +09:00
田中ザック Isaac Mathis 3f6fe32ce7 Merge pull request #402 from Shirofune-Security/feat/371-ad-object-sacl
Add opt-in AD object and Configuration partition audit SACLs
2026-09-19 19:49:50 +09:00
田中ザック Isaac Mathis 5665fd2f0f Merge pull request #401 from Shirofune-Security/feat/367-native-channel-access
Configure native WEF channel prerequisites and CAPI2 read access
2026-09-19 19:49:07 +09:00
田中ザック Isaac Mathis f0444aedef Merge pull request #400 from Shirofune-Security/feat/381-applocker-readiness
Assess native AppLocker readiness and guard audit-only imports
2026-09-19 19:48:26 +09:00
田中ザック Isaac Mathis 423277428a Merge pull request #399 from Shirofune-Security/feat/372-wmi-namespace-auditing
Add opt-in WMI namespace audit SACL configuration
2026-09-19 19:45:11 +09:00
田中ザック Isaac Mathis ded0b9c375 Merge pull request #398 from Shirofune-Security/feat/373-targeted-sacl-planning
Plan targeted SACL prerequisites alongside audit profiles
2026-09-19 19:41:51 +09:00
Shirofune-Security ab70ec740a Integrate completed native logging stack into rule eligibility 2026-09-19 11:50:48 +09:00
Shirofune-Security 9815e609d8 Integrate reviewed catalog and LDAP commands into WEF branch 2026-09-19 11:48:11 +09:00
Shirofune-Security 8834dba4e6 Merge commit '45b6be91a8a35e1f08f6138fff70e0c6fafc58d1' into feat/387-native-rule-eligibility
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	tests/AuditProfileOutput.Tests.ps1
#	tests/NativeProviders.Tests.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 11:46:07 +09:00
Shirofune-Security f1b5be8bf2 Merge reviewed PowerShell transcription into WEF integration 2026-09-19 11:45:59 +09:00
Shirofune-Security 03265a0940 Merge commit '26d7f8b09df915c0f2b3dc837112f5f963b437a7' into feat/376-powershell-transcription 2026-09-19 11:45:34 +09:00
Shirofune-Security 273af05e36 Merge reviewed LDAP diagnostics into transcription branch 2026-09-19 11:45:34 +09:00
Shirofune-Security 26d7f8b09d Merge remote-tracking branch 'origin/dev' into feat/383-ldap-diagnostics
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 11:45:13 +09:00
Shirofune-Security 852de965a6 Merge commit 'f9303313148c80ad1d26376b943459d38598547b' into feat/387-native-rule-eligibility
# Conflicts:
#	CHANGELOG-Japanese.md
#	CHANGELOG.md
#	WELA.ps1
#	website/docs/resources/changelog.ja.md
#	website/docs/resources/changelog.md
2026-09-19 11:45:05 +09:00
Shirofune-Security 2df9715dc1 Use explicit canonical framing for portable metadata hashes 2026-09-19 07:39:47 +09:00
Shirofune-Security f930331314 Clear handled native-read exit status after Windows smoke assertions 2026-09-19 07:35:04 +09:00
Shirofune-Security e8a0aeb59b Keep rule evidence identities stable across Windows checkouts and shells 2026-09-19 07:34:10 +09:00
Shirofune-Security 0403f14446 Clear expected child failure exit status after CLI assertions 2026-09-19 07:33:32 +09:00
Shirofune-Security 787c66e009 Normalize WEF XML evidence before PowerShell 5.1 JSON serialization 2026-09-19 07:31:23 +09:00
Shirofune-Security 1106fd0900 Verify HTML evidence encoding across PowerShell JSON serializers 2026-09-19 07:28:29 +09:00
Shirofune-Security 781c420481 Use explicit Windows test shells and link eligibility changelog 2026-09-19 07:26:46 +09:00
Shirofune-Security d6da8f82c8 Retain recorded eligibility evidence scope in HTML reports 2026-09-19 07:25:44 +09:00
Shirofune-Security 9b93473904 Link WEF provisioning changelog to PR 406 2026-09-19 07:24:31 +09:00
Shirofune-Security 36ad97114c Assess native rule eligibility with explicit evidence gates 2026-09-19 07:24:04 +09:00
Shirofune-Security 9a69600947 Add opt-in native WEF source and collector subscription controls 2026-09-19 07:23:47 +09:00
Shirofune-Security bca56fbad9 Link LDAP diagnostics changelog to PR 404 2026-09-19 07:18:27 +09:00
Shirofune-Security c7cfb0d112 Reject LDAP options before profile command dispatch 2026-09-19 07:15:31 +09:00
Shirofune-Security e0d531c669 Record passing Windows transcription evidence and link PR 405 2026-09-19 07:13:22 +09:00
Shirofune-Security 89253fa812 Add opt-in Windows PowerShell transcription for CIS Level 2 2026-09-19 07:09:33 +09:00
Shirofune-Security 9e2b4b5b43 Make LDAP 1644 diagnostics explicit and preserve existing DC settings 2026-09-19 07:09:07 +09:00
Shirofune-Security 45b6be91a8 Link audit catalog changelog entries to PR 403 2026-09-19 07:07:43 +09:00