mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-01 12:04:46 +02:00
* Add native local nonexistent-account failed-logon probe * Match actual MSV1 local authentication event package * Refuse coerced identity and authentication receipt fields * Preserve explicit UTC DateTime receipts on older PowerShell7 * Reject unknown failed-logon probe options before dispatch
15 lines
1.0 KiB
PowerShell
15 lines
1.0 KiB
PowerShell
param([Parameter(Mandatory)][ValidatePattern('^[a-f0-9]{32}$')][string]$Nonce)
|
|
$ErrorActionPreference='Stop';[Console]::OutputEncoding=[Text.UTF8Encoding]::new($false)
|
|
$script:ScriptRoot=Split-Path $PSScriptRoot -Parent
|
|
. "$PSScriptRoot/WefArrival.ps1"
|
|
. "$PSScriptRoot/ChannelRead.ps1"
|
|
. "$PSScriptRoot/FailedLogonProbe.ps1"
|
|
Initialize-WelaFailedLogonNative
|
|
foreach($name in @('EventLog','Winmgmt','SamSs','RpcSs')){if((Get-Service -Name $name -ErrorAction Stop).Status -ne 'Running'){throw 'Required native services must already be running.'}}
|
|
$hostState=Get-WelaChannelReadHost
|
|
if($hostState.ProductType -notin @(1,3) -or $hostState.DomainRole -notin @(0,1,2,3)){throw 'A local SAM client or member/standalone server is required.'}
|
|
$before=Get-WelaChannelReader
|
|
$result=[Wela.FailedLogonProbe.Native]::Run($Nonce)
|
|
$after=Get-WelaChannelReader
|
|
[pscustomobject][ordered]@{Nonce=$Nonce;ProcessId=$PID;Executable=(Get-Process -Id $PID).Path;BeforeToken=$before;AfterToken=$after;Attempt=$result}|ConvertTo-Json -Depth 10 -Compress
|