Files
田中ザック Isaac Mathis 5ba53fbcfb Validate native AppLocker EXE event generation with an opt-in probe (#423)
* Add native AppLocker EXE event validation probe

* Reference PR 423 in changelogs

* Isolate AppLocker native fixture and preserve prerequisite diagnostics

* Report an integer zero for an empty AppLocker policy

* Prepare disposable AppLocker probe policy without bypassing production importer guards

* Retain bounded native AppLocker channel diagnostics on probe failure

* Require native policy application before the disposable AppLocker probe

* Preserve exact timestamp strings in native evidence fixtures

* Record actual runner session and AppLocker publication diagnostics

* Activate and restore the native policy converter on disposable AppLocker hosts

* Compare native task freshness without guessing its timestamp timezone

* Verify effective policy and borrowed converter inactivity during fixture cleanup

* Track the actual native policy-converter task instance instead of cached timestamps
2026-09-20 22:46:56 +09:00

35 lines
1.1 KiB
YAML

name: Native AppLocker EXE probe
on:
push:
branches: ['**']
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
applocker-probe:
strategy:
fail-fast: false
matrix:
os: [windows-2022, windows-2025]
engine: [powershell, pwsh]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
- name: Fixtures in Windows PowerShell 5.1
if: matrix.engine == 'powershell'
shell: powershell
run: ./tests/AppLockerProbe.Tests.ps1
- name: Native probe in Windows PowerShell 5.1
if: matrix.engine == 'powershell'
shell: powershell
run: ./tests/AppLockerProbe.Windows.Tests.ps1 -AllowDisposablePolicyWrite
- name: Fixtures in PowerShell 7
if: matrix.engine == 'pwsh'
shell: pwsh
run: ./tests/AppLockerProbe.Tests.ps1
- name: Native probe in PowerShell 7
if: matrix.engine == 'pwsh'
shell: pwsh
run: ./tests/AppLockerProbe.Windows.Tests.ps1 -AllowDisposablePolicyWrite