# Synthetic source/collector data only. No native event generation or telemetry claim. function New-WelaEvtxFixture { param([string]$Directory,[datetime]$Timestamp=([DateTime]::UtcNow.AddSeconds(-5))) $now=$Timestamp $hostState=[pscustomobject][ordered]@{Status='Observed';Build=20348;UBR=4000;Edition='ServerDatacenter';ProductType=3;DomainRole=3;DomainJoined=$true;Domain='lab.test';Architecture='64-bit';ProcessorArchitecture=9;InstalledRoles=@('Web-Server');RolesStatus='Observed';Diagnostic=''} $policies=@{};foreach ($p in (Import-WelaAuditProfiles).catalog) {$policies[$p.guid]=0};$policies['0cce922b-69ae-11d9-bed3-505054503030']=1 $state=[pscustomobject][ordered]@{capturedAtUtc=$now.AddSeconds(-2).ToString('o');context=[pscustomobject]@{computer='source01';role='MemberServer';build=20348;patch='20348.4000';domainJoined=$true;installedRoles=@('Web-Server')};hostObservation=$hostState;auditPolicies=$policies;auditPrecedence=[pscustomobject]@{KeyExists=$true;ValueExists=$true;Value=1;Type='DWord'};commandLineCapture=[pscustomobject]@{KeyExists=$true;ValueExists=$true;Value=1;Type='DWord'};securityChannelEnabled=$true} $process=[pscustomobject]@{ProcessId=123;ParentProcessId=456;Executable='C:\Windows\System32\cmd.exe';Arguments='/d /c echo WELA_PROBE_0123456789abcdef0123456789abcdef';Marker='WELA_PROBE_0123456789abcdef0123456789abcdef';StartedUtc=$now.ToString('o');CompletedUtc=$now.AddSeconds(1).ToString('o');ExitCode=0} $before=$state|ConvertTo-Json -Depth 16 $state.capturedAtUtc=$now.AddSeconds(2).ToString('o');$after=$state|ConvertTo-Json -Depth 16 $xml=@" 4688201331200x8020000000000000100Securitysource01.lab.testS-1-5-18SOURCE01$LAB0x3e70x7bC:\Windows\System32\cmd.exe%%19360x1c8"C:\Windows\System32\cmd.exe" /d /c echo WELA_PROBE_0123456789abcdef0123456789abcdefS-1-0-0--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeS-1-16-16384 "@ $null=New-Item -ItemType Directory -Path $Directory $artifacts=@();foreach ($entry in @(@('before-state.json',$before),@('after-state.json',$after),@('process.json',($process|ConvertTo-Json -Depth 6)),@('event.xml',$xml))) {$artifacts+=Write-WelaProbeArtifact $Directory $entry[0] $entry[1]} $manifest=[pscustomobject][ordered]@{SchemaVersion=1;Kind='WelaNativeProbeComponents';Probe='security-4688-command-line-v1';Action='Run';Status='NativeEventObserved';ExitCode=0;GeneratedUtc=$now.AddSeconds(-3).ToString('o');PolicyChanges=0;ReadyRuleCredit=0;Scope='Synthetic test fixture';RequiredEvidence=@('Reviewed complete rule and normalization','Backend ingestion','Translated query and successful query result');BeforeState=(ConvertFrom-WelaEvtxJson $before);AfterState=(ConvertFrom-WelaEvtxJson $after);Process=$process;Artifacts=$artifacts;Diagnostic='';OutputPath=$Directory} $null=Write-WelaProbeArtifact $Directory 'manifest.json' ($manifest|ConvertTo-Json -Depth 20) [pscustomobject]@{Directory=$Directory;Xml=$xml;Host=$hostState;Process=$process;Manifest=$manifest} }