# These inputs are pinned by exact byte hashes; Windows checkouts must keep LF. /config/security_rules.json text eol=lf /config/eid_subcategory_mapping.csv text eol=lf /config/rule_eligibility_manifest.json text eol=lf /config/audit_scoring.json text eol=lf # Exact-context default evidence pins these source/collector bytes. /config/baselines.json text eol=lf /config/audit_profiles.json text eol=lf /config/control_applicability.json text eol=lf /scripts/ControlApplicability.ps1 text eol=lf /scripts/Configuration.ps1 text eol=lf /modules/NativeProviders.psm1 text eol=lf /modules/AuditProfiles.psm1 text eol=lf # Full upstream rule artifacts retain their exact pinned bytes on every platform. /config/provider_rule_sources/*.yml -text whitespace=-blank-at-eol # Selected SACL review plans pin these exact source bytes. /config/audit_sacl_targets.json text eol=lf /scripts/TargetedSaclPlanning.ps1 text eol=lf /scripts/SelectedSaclConfiguration.ps1 text eol=lf /scripts/SelectedSaclNative.cs text eol=lf /modules/AuditCatalog.psm1 text eol=lf # Fixed public pending-request fixture is pinned by its exact byte hash. /tests/fixtures/adcs-pending-probe.csr text eol=lf scripts/WecUpdate.ps1 text eol=lf scripts/WecUpdateNative.cs text eol=lf modules/WefSubscriptions.psm1 text eol=lf tests/WecUpdate*.ps1 text eol=lf modules/WecSubscriptionXml.cs text eol=lf # DNS analytical receipts pin the catalog and lifecycle implementation bytes. /config/native_provider_packs.json text eol=lf /scripts/NativeProviderPacks.ps1 text eol=lf /scripts/DnsAnalytical.ps1 text eol=lf /scripts/DnsAnalyticalArchive.cs text eol=lf # Native WEC XML reader source identity remains identical across checkouts. /modules/WecSubscriptionXml.cs text eol=lf scripts/AppLockerProbe.ps1 text eol=lf tests/AppLockerProbe*.ps1 text eol=lf /scripts/ChannelRead.ps1 text eol=lf /scripts/ChannelReadNative.cs text eol=lf /config/native_channel_profile.json text eol=lf /tests/ChannelRead*.ps1 text eol=lf # Pending AD CS restart plans bind exact implementation bytes. /scripts/AdcsRestartResume.ps1 text eol=lf /scripts/AdcsAuditing.ps1 text eol=lf /tests/AdcsRestartResume*.ps1 text eol=lf # Local delivery catalog and native observer retain reproducible source bytes. config/event_measurement.json text eol=lf scripts/EventMeasurement* text eol=lf tests/EventMeasurement* text eol=lf tests/SelectedSaclFixtureProtection.cs text eol=lf # Fixed local WMI probe source/worker fingerprints. /scripts/WmiProbe*.ps1 text eol=lf /scripts/WmiProbeNative.cs text eol=lf /scripts/WmiNamespaceAuditing.ps1 text eol=lf /scripts/WefArrival.ps1 text eol=lf /tests/WmiProbe*.ps1 text eol=lf # Leaf-file recovery review binds these exact helper bytes. /scripts/FileSaclRecovery* text eol=lf /tests/FileSaclRecovery* text eol=lf # Actual archive-reader evidence binds implementation and native-token source bytes. /scripts/EvtxRecovery.ps1 text eol=lf /scripts/NativeValidation.ps1 text eol=lf /tests/EvtxRecovery*.ps1 text eol=lf /tests/fixtures/EvtxReader*.ps1 text eol=lf /scripts/TranscriptProbe* text eol=lf /scripts/PowerShellTranscription.ps1 text eol=lf /scripts/WefArrival.ps1 text eol=lf /tests/TranscriptProbe*.ps1 text eol=lf # Named registry recovery binds implementation bytes across checkouts. /scripts/NamedRegistryRecovery* text eol=lf /scripts/AuditRecovery.ps1 text eol=lf /tests/NamedRegistryRecovery* text eol=lf /scripts/Capi2Probe* text eol=lf /tests/Capi2Probe* text eol=lf /scripts/CustomAuditProfiles.ps1 text eol=lf # Reviewed WEC state plans bind native setter and runtime source bytes. /scripts/WecState* text eol=lf /scripts/WecRuntime* text eol=lf /tests/WecState* text eol=lf /scripts/WecListener* text eol=lf # Existing-file read receipts bind identical native/worker source bytes. /scripts/FileAccessProbe* text eol=lf /tests/FileAccessProbe* text eol=lf # Disposable native provider configuration fixture tests/NativeProviderConfigure.Windows.Tests.ps1 text eol=lf # Disposable public registry lifecycle fixture bytes are retained in evidence. /tests/RegistrySacl* text eol=lf /scripts/WecAuthorization* text eol=lf /tests/WecAuthorization* text eol=lf # Reviewed channel restoration binds exact installed source bytes. /scripts/ChannelRecovery.ps1 text eol=lf /tests/ChannelRecovery*.ps1 text eol=lf # Registry recovery plans bind identical source bytes across native hosts. /scripts/RegistrySaclRecovery* text eol=lf /tests/RegistrySaclRecovery* text eol=lf /scripts/SelectedSaclDescendants.ps1 text eol=lf /scripts/AuditRecovery.ps1 text eol=lf /scripts/EvtxRecovery.ps1 text eol=lf # Collector inventory reads native UTF16 names and bounded Unicode XML. /modules/WecSubscriptionInventory.cs text eol=lf /tests/WecCollectorObservation* text eol=lf /tests/WecSubscriptionInventory* text eol=lf /tests/TokenRightAttribution*.ps1 text eol=lf /tests/TokenRightAttribution*.cs text eol=lf # Disposable public OneSettings fixture source identity. /tests/OneSettingsConfigure*.ps1 text eol=lf # Scoped NTLM source and native evidence retain stable bytes. /scripts/NtlmAudit.ps1 text eol=lf /tests/NtlmAudit* text eol=lf # Native query receipts bind the same source bytes on every supported engine. /scripts/WefQuery* text eol=lf /tests/WefQuery* text eol=lf # Public filesystem-SACL disposable lifecycle evidence. tests/FileSaclProfileFixture.cs text eol=lf tests/FileSaclLifecycle.Windows.Tests.ps1 text eol=lf /scripts/RegistryValueProbe* text eol=lf /tests/RegistryValueProbe* text eol=lf /scripts/ProcessCommandline.ps1 text eol=lf /tests/ProcessCommandline* text eol=lf # Native WMI tree evidence binds source bytes across checkouts. /scripts/WmiNamespaceAuditing.ps1 text eol=lf /scripts/WmiNamespaceDescendants.ps1 text eol=lf /tests/WmiNamespaceDescendants* text eol=lf /WELA.ps1 text eol=lf # Reviewed WMI namespace recovery binds exact source bytes. /scripts/WmiSaclRecovery.ps1 text eol=lf /tests/WmiSaclRecovery* text eol=lf