Files
WELA/config/audit_sacl_targets.json
Shirofune-SecurityandClaude Opus 4.8 10c1bcaac7 Address Copilot re-review: %SystemRoot%, Entra SIDs, WOW64 gate, reg-unload check, subcategory-failure, help
- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system
  drive no longer skips every file target.
- Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*.
- WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows.
- reg unload is now checked (retry once, then error) so a failed unload no longer leaves the
  user's NTUSER.DAT mounted under the temp alias while reporting success.
- A failed auditpol subcategory is tracked; the final message warns (instead of claiming success)
  that SACLs for that class will not produce events.
- configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned.

Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with
SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:49:42 +09:00

480 lines
13 KiB
JSON

{
"description": "Targeted System Access Control Lists (SACLs) that make Object Access File System (4663), Registry (4657) and Handle Manipulation (4656/4658) auditing produce the events the Hayabusa/Sigma Security-channel rules rely on - WITHOUT enabling global file/registry auditing (which would flood). Only the specific autostart/persistence registry keys (ASEPs) and sensitive files referenced by the ruleset are audited. Principal is 'Everyone'. Registry keys use ContainerInherit so subkeys are covered. Objects that are absent on a given host (e.g. Wow6432Node on 32-bit, NTDS on non-DCs) are skipped. Per-user objects are handled via 'user_registry' and 'user_files': WELA enumerates every profile from ProfileList (plus C:\\Users\\Default so future users inherit the SACL), sets file SACLs under each profile, and sets registry SACLs on each user hive (loaded hives directly via HKU:\\<SID>, offline/Default hives by reg-load/unload of NTUSER.DAT). 'user_registry' keys are relative to the user hive root; 'user_files' paths are relative to the profile directory. Remaining edge cases (folder-redirected AppData on network shares, mandatory profiles) are not covered.",
"registry": [
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "ASEP Run (T1547.001)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "ASEP RunOnce"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "ASEP RunOnceEx"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServices",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "ASEP RunServices"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunServicesOnce",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "ASEP RunServicesOnce"
},
{
"path": "HKLM:\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "ASEP Run (WOW64)"
},
{
"path": "HKLM:\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "ASEP RunOnce (WOW64)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "ASEP Policies Explorer Run"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "Winlogon Shell/Userinit/Notify (T1547.004)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "IFEO debugger/GlobalFlag (T1546.012)"
},
{
"path": "HKLM:\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "IFEO (WOW64)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows",
"inherit": false,
"rights": [
"SetValue"
],
"note": "AppInit_DLLs / Load / Run (T1546.010)"
},
{
"path": "HKLM:\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Windows",
"inherit": false,
"rights": [
"SetValue"
],
"note": "AppInit_DLLs (WOW64)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellServiceObjectDelayLoad",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "SSODL (T1547.005)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SharedTaskScheduler",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "SharedTaskScheduler"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers",
"inherit": true,
"rights": [
"CreateSubKey",
"Delete"
],
"note": "ShellIconOverlayIdentifiers"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects",
"inherit": true,
"rights": [
"CreateSubKey",
"Delete"
],
"note": "BHO (T1176)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "Active Setup (T1547.014)"
},
{
"path": "HKLM:\\SOFTWARE\\Wow6432Node\\Microsoft\\Active Setup\\Installed Components",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "Active Setup (WOW64)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Command Processor",
"inherit": false,
"rights": [
"SetValue"
],
"note": "cmd AutoRun (T1546.011)"
},
{
"path": "HKLM:\\SOFTWARE\\Wow6432Node\\Microsoft\\Command Processor",
"inherit": false,
"rights": [
"SetValue"
],
"note": "cmd AutoRun (WOW64)"
},
{
"path": "HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Session Manager",
"inherit": false,
"rights": [
"SetValue"
],
"note": "BootExecute/AppCertDlls/SubSystems (T1546.009)"
},
{
"path": "HKLM:\\SYSTEM\\CurrentControlSet\\Control\\Lsa",
"inherit": false,
"rights": [
"SetValue"
],
"note": "LSA Security/Authentication/Notification Packages - SSP (T1547.005/T1556)"
},
{
"path": "HKLM:\\SYSTEM\\CurrentControlSet\\Services\\WinSock2\\Parameters",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey"
],
"note": "Winsock LSP (T1546.015)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Ctf\\LangBarAddin",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "LangBarAddin"
},
{
"path": "HKLM:\\SOFTWARE\\Classes\\Protocols\\Handler",
"inherit": true,
"rights": [
"CreateSubKey",
"Delete"
],
"note": "Protocol handler hijack"
},
{
"path": "HKLM:\\SOFTWARE\\Classes\\Protocols\\Filter",
"inherit": true,
"rights": [
"CreateSubKey",
"Delete"
],
"note": "Protocol filter hijack"
},
{
"path": "HKLM:\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\Scripts",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey"
],
"note": "Logon/Logoff/Startup scripts (T1037)"
},
{
"path": "HKLM:\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey"
],
"note": "Defender exclusion tampering (T1562.001)"
},
{
"path": "HKLM:\\SYSTEM\\CurrentControlSet\\Services",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "Service create/delete + ImagePath/ServiceDLL/Start edits on child keys (T1543.003). Inherited so 4657 on service value changes is captured (4697/7045 cover install only)."
}
],
"user_registry": [
{
"key": "Software\\Microsoft\\Windows\\CurrentVersion\\Run",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "HKCU ASEP Run (T1547.001)"
},
{
"key": "Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "HKCU ASEP RunOnce"
},
{
"key": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "HKCU Policies Explorer Run"
},
{
"key": "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
"inherit": false,
"rights": [
"SetValue"
],
"note": "Startup folder redirection (T1547.001)"
},
{
"key": "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartupApproved\\Run",
"inherit": false,
"rights": [
"SetValue",
"Delete"
],
"note": "StartupApproved (enable/disable autorun)"
},
{
"key": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows",
"inherit": false,
"rights": [
"SetValue"
],
"note": "HKCU Load/Run (T1546.010)"
},
{
"key": "Software\\Microsoft\\Command Processor",
"inherit": false,
"rights": [
"SetValue"
],
"note": "HKCU cmd AutoRun (T1546.011)"
},
{
"key": "Control Panel\\Desktop",
"inherit": false,
"rights": [
"SetValue"
],
"note": "Scrnsave.exe screensaver hijack (T1546.002)"
},
{
"key": "Environment",
"inherit": false,
"rights": [
"SetValue"
],
"note": "UserInitMprLogonScript logon-script persistence (T1037.001)"
},
{
"key": "Software\\Microsoft\\Ctf\\LangBarAddin",
"inherit": true,
"rights": [
"SetValue",
"CreateSubKey",
"Delete"
],
"note": "HKCU LangBarAddin"
},
{
"key": "Software\\Microsoft\\Office\\Outlook\\Addins",
"inherit": true,
"rights": [
"CreateSubKey",
"Delete",
"SetValue"
],
"note": "Outlook add-in persistence (T1137.006)"
}
],
"user_files": [
{
"relpath": "AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup",
"inherit": true,
"rights": [
"WriteData",
"CreateFiles",
"Delete"
],
"note": "Startup folder persistence (T1547.001)"
},
{
"relpath": "AppData\\Roaming\\Signal",
"inherit": true,
"rights": [
"ReadData"
],
"note": "Signal Desktop sensitive data access (T1005)"
}
],
"files": [
{
"path": "%SystemRoot%\\NTDS",
"inherit": true,
"rights": [
"ReadData",
"WriteData",
"Delete",
"ChangePermissions",
"TakeOwnership"
],
"note": "AD database dir - ntds.dit theft (T1003.003)"
},
{
"path": "%SystemRoot%\\System32\\config\\SAM",
"inherit": false,
"rights": [
"ReadData",
"WriteData",
"Delete",
"TakeOwnership"
],
"note": "SAM hive theft (T1003.002)"
},
{
"path": "%SystemRoot%\\System32\\config\\SECURITY",
"inherit": false,
"rights": [
"ReadData",
"WriteData",
"Delete",
"TakeOwnership"
],
"note": "SECURITY hive (T1003.004 LSA secrets)"
},
{
"path": "%SystemRoot%\\System32\\config\\SYSTEM",
"inherit": false,
"rights": [
"ReadData",
"WriteData",
"Delete",
"TakeOwnership"
],
"note": "SYSTEM hive (boot key for offline SAM)"
},
{
"path": "%SystemRoot%\\System32\\lsass.exe",
"inherit": false,
"rights": [
"ReadData",
"WriteData",
"TakeOwnership"
],
"note": "LSASS binary read/replace. NOTE: live LSASS memory/handle access (credential dumping) is better detected via Sysmon EID 10, not a file SACL."
},
{
"path": "%SystemRoot%\\System32\\ntdsutil.exe",
"inherit": false,
"rights": [
"ExecuteFile"
],
"note": "ntdsutil execution (IFM/ntds.dit dump)"
},
{
"path": "%SystemRoot%\\System32\\vssadmin.exe",
"inherit": false,
"rights": [
"ExecuteFile"
],
"note": "Shadow copy tooling"
}
]
}