Files
WELA/scripts/FailedLogonProbeWorker.ps1
田中ザック Isaac Mathis 6d228fedef Add a native local failed-logon audit probe (#444)
* Add native local nonexistent-account failed-logon probe

* Match actual MSV1 local authentication event package

* Refuse coerced identity and authentication receipt fields

* Preserve explicit UTC DateTime receipts on older PowerShell7

* Reject unknown failed-logon probe options before dispatch
2026-09-21 22:13:20 +09:00

15 lines
1.0 KiB
PowerShell

param([Parameter(Mandatory)][ValidatePattern('^[a-f0-9]{32}$')][string]$Nonce)
$ErrorActionPreference='Stop';[Console]::OutputEncoding=[Text.UTF8Encoding]::new($false)
$script:ScriptRoot=Split-Path $PSScriptRoot -Parent
. "$PSScriptRoot/WefArrival.ps1"
. "$PSScriptRoot/ChannelRead.ps1"
. "$PSScriptRoot/FailedLogonProbe.ps1"
Initialize-WelaFailedLogonNative
foreach($name in @('EventLog','Winmgmt','SamSs','RpcSs')){if((Get-Service -Name $name -ErrorAction Stop).Status -ne 'Running'){throw 'Required native services must already be running.'}}
$hostState=Get-WelaChannelReadHost
if($hostState.ProductType -notin @(1,3) -or $hostState.DomainRole -notin @(0,1,2,3)){throw 'A local SAM client or member/standalone server is required.'}
$before=Get-WelaChannelReader
$result=[Wela.FailedLogonProbe.Native]::Run($Nonce)
$after=Get-WelaChannelReader
[pscustomobject][ordered]@{Nonce=$Nonce;ProcessId=$PID;Executable=(Get-Process -Id $PID).Path;BeforeToken=$before;AfterToken=$after;Attempt=$result}|ConvertTo-Json -Depth 10 -Compress