Files
WELA/docs/registry-value-probe.md

5.0 KiB

Fixed current-user registry value probe

registry-probe validates a narrow native Security 4657 component using an existing diagnostic key, HKEY_USERS\<actual caller SID>\Software\WELA\AuditProbe. It accepts no alternate key or value input. The default Plan action reads prerequisites; explicit Run creates one unpredictable WELA_Probe_<nonce> REG_SZ value, modifies its fixed marker text, verifies readback, then deletes only that owned value. The key's native last-write metadata changes. This command never creates keys, installs SACLs, changes audit policy, alters autostart entries, starts services or accesses remote computers.

./WELA.ps1 registry-probe
./WELA.ps1 registry-probe -RegistryProbeAction Run -RegistryProbeOutputPath C:\WelaEvidence\registry-001

Prepare the diagnostic key and its auditing through a separately reviewed administrative process. Run requires an ordinary elevated current primary token with its existing SeSecurityPrivilege assigned, native 64-bit Windows PowerShell 5.1 or PowerShell7, an enabled/readable Security channel, Registry success auditing, audit precedence DWORD1, and an ordinary success SetValue SACL ACE matching the actual user or enabled group. No target prerequisites are silently repaired. The fixed key must have no children. Component-by-component native opens reject registry symbolic links and verify the held NT path. Full SDK-defined security-descriptor sections and a bounded inventory of raw typed values are retained; excessive or unreadable state fails closed. Run reserves room for the temporary value before mutation (at most127 original values and sufficient raw-byte capacity). Cleanup queries the exact owned value independently, so unrelated inventory growth cannot strand its marker.

Microsoft describes 4657 and the Set Value SACL prerequisite. The probe uses the documented RegSetValueExW and RegDeleteValueW APIs through the same held key. Existing values are never selected for modification. A collision refuses before writing; a changed owned value is preserved with failed cleanup rather than blindly deleted. Operations are not transactions with other administrators.

A durable intent identifies the exact nonce/key/value before mutation. The operation receipt retains precise native write/readback timestamps, handle, original and final descriptor/value snapshots, and cleanup result. The parser requires exact provider/GUID, event version/task/success keyword/channel/host, record boundary, current SID/logon LUID, process ID/executable, held handle, key, value name, operation type and old/new REG_SZ marker data inside the measured modification interval. Creation/deletion records cannot substitute for the modification. Queries are bounded and completeness failures, duplicate matches, missing records, token changes, cleanup failures or later policy/security/source drift prevent success.

The descriptor reader temporarily enables the caller's assigned SeSecurityPrivilege and restores its original attributes. Full token identity, groups and privilege attributes are compared before and after. It grants no rights. Audit masks, precedence, services, channel settings, descriptors and unrelated values must remain unchanged. Local reads and the temporary value lifecycle can themselves generate audit events; the Security log is never cleared.

If interrupted, the private output directory retains intent.json and any completed receipts. Inspect the exact fixed key and nonce value. Delete a leftover marker only after establishing it is still the value owned by this run and contains the recorded marker data; preserve unexpected replacement data. There is no blind cleanup of keys or other values. Protect evidence files, which include local policy/token metadata and selected event XML.

Validation and limits

Focused tests cover strict prerequisites, typed receipts, cleanup refusal, XML attribution, source drift and durable intent. The disposable native fixture creates the fixed WELA parent only if absent, marks ownership, prepares one SetValue SACL and independent audit prerequisites, then invokes public Run twice. It requires two exact4657 records, no retained temporary values, preserved unrelated typed values/security/token, and restoration of all59 audit masks/precedence plus removal of its owned keys. CI retains artifacts, source fingerprints, host/engine context and cleanup receipts on Server2022/2025 with Windows PowerShell5.1/PowerShell7.

This is component evidence for the fixed diagnostic key and current user only. It does not validate production registry paths, inherited SACL coverage, access failures, other users, Windows11/DC/ADCS behavior, forwarding, backend normalization or complete Sigma rules. SigmaEvtxCredit=0. Built-in Windows only; Sysmon is excluded.