Files
WELA/docs/wmi-descendants.md

5.1 KiB

Reviewed WMI namespace descendants

wmi-auditing -WmiIncludeChildren now inventories existing descendants before an inheritable parent SACL write. It still accepts only the five reviewed local catalog namespaces. The CIMV2 definitions use parent-only flags even when this option is selected; the four reference definitions with flag66 receive the extra safeguards. No descendant is passed to a setter.

./WELA.ps1 wmi-auditing -WmiAction Plan -WmiNamespace 'root\default' -WmiIncludeChildren -ResultsPath tree-plan.json
./WELA.ps1 wmi-auditing -WmiAction Configure -WmiNamespace 'root\default' -WmiIncludeChildren -DryRun -ResultsPath tree-dry-run.json
./WELA.ps1 wmi-auditing -WmiAction Configure -WmiNamespace 'root\default' -WmiIncludeChildren -BackupPath C:\Evidence\new-wmi-backup -ResultsPath tree-result.json

Review Controls[].Descendants and the full descriptor strings before configuration. Configure builds a fresh in-memory plan, shows the descendant count in its confirmation, and checks that same tree again before writing. The earlier Plan export is documentation of its observation, not a persisted authorization token consumed by Configure. -Auto skips the confirmation only; it does not skip the tree checks. The CLI refuses unrelated parameters and extra positional arguments instead of silently binding them to an unused output-format parameter.

The inventory records every existing child and grandchild within 64 descendants, eight levels and two MiB of descriptor evidence. Two complete passes must agree on names, parent relationships and every full descriptor. Unknown names, duplicates, access failures, caps, incomplete reads and drift fail closed. The scan checks a 30-second budget between namespaces, and native enumeration requests a ten-second timeout. Individual synchronous provider calls cannot be forcibly cancelled, so this is not a hard total runtime limit. Winmgmt must already be running. Host, implementation fingerprints and the full observed caller SID, logon, groups and privilege attributes must remain unchanged.

before.jsonl retains the existing parent DescriptorJson and DescriptorMof fields and adds complete descendant descriptor strings. After confirmation and journaling, another stable inventory must match before the parent-only SACL setter is reached. A journal or guard failure prevents that setter. Original parent ACEs and owner/group/DACL continue to use the existing preservation contract.

After a write, the command requires the same existing descendants, preserves every unrelated descriptor field and original ACE multiplicity, and accepts only the exact requested inherited success ACEs. A returned SE_SACL_PROTECTED bit is treated conservatively as a preservation barrier for that namespace and its descendants: the entire observed descriptor must stay unchanged. This does not establish that every WMI provider enforces that bit. Missing inherited entries, an unexpected ACE, changed protection or a new/disappearing namespace is unverified and causes a nonzero result. A final full tree read checks for later drift. Results include the individual descendant observations and diagnostics.

Microsoft documents namespace inheritance when a child is created and the inherited ACE flag. This does not establish that adding an inheritable ACE retroactively updates every existing child. A successful parent setter can therefore be followed by a failed descendant verification. The parent addition may remain in place; the command does not retry child writes or claim subtree success. A repeat also fails when the parent is already compliant but existing descendants lack the requested inherited entry. Inspect the recorded native outcomes before choosing a separately reviewed child configuration or recovery procedure.

There is no transaction across the tree. A concurrent change between the final pre-write observations and the provider call remains possible. Namespace names do not establish durable identity across deletion/recreation. No automatic rollback, descendant ACE ownership, future-child behavior, event generation, remote WMI, forwarding or Sigma readiness is inferred. SetSecurityDescriptor's SACL-only contract preserves owner, group and DACL by omitting those fields from the request.

Native acceptance uses generated root\WelaInheritance_<GUID> namespaces on disposable Server2022/2025 hosts, runs the production inventory/configuration functions, records exact provider outcomes and removes only owned instances in reverse creation order. It does not redirect the production catalog or write existing production namespaces. Synthetic tests separately exercise caps, stale descriptors, protected subtrees, missing inheritance, unexpected child changes and final failure propagation. Windows11, production target writes, DC/ADCS role behavior and forwarding remain unverified.