mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-05 14:04:47 +02:00
* Add native AppLocker EXE event validation probe * Reference PR 423 in changelogs * Isolate AppLocker native fixture and preserve prerequisite diagnostics * Report an integer zero for an empty AppLocker policy * Prepare disposable AppLocker probe policy without bypassing production importer guards * Retain bounded native AppLocker channel diagnostics on probe failure * Require native policy application before the disposable AppLocker probe * Preserve exact timestamp strings in native evidence fixtures * Record actual runner session and AppLocker publication diagnostics * Activate and restore the native policy converter on disposable AppLocker hosts * Compare native task freshness without guessing its timestamp timezone * Verify effective policy and borrowed converter inactivity during fixture cleanup * Track the actual native policy-converter task instance instead of cached timestamps
20 lines
4.0 KiB
PowerShell
20 lines
4.0 KiB
PowerShell
# Synthetic source/collector data only. No native event generation or telemetry claim.
|
|
function New-WelaArrivalFixture {
|
|
param([string]$Directory,[datetime]$Timestamp=([DateTime]::UtcNow.AddSeconds(-5)))
|
|
$now=$Timestamp
|
|
$hostState=[pscustomobject][ordered]@{Status='Observed';Build=20348;UBR=4000;Edition='ServerDatacenter';ProductType=3;DomainRole=3;DomainJoined=$true;Domain='lab.test';Architecture='64-bit';ProcessorArchitecture=9;InstalledRoles=@('Web-Server');RolesStatus='Observed';Diagnostic=''}
|
|
$policies=@{};foreach ($p in (Import-WelaAuditProfiles).catalog) {$policies[$p.guid]=0};$policies['0cce922b-69ae-11d9-bed3-505054503030']=1
|
|
$state=[pscustomobject][ordered]@{capturedAtUtc=$now.AddSeconds(-2).ToString('o');context=[pscustomobject]@{computer='source01';role='MemberServer';build=20348;patch='20348.4000';domainJoined=$true;installedRoles=@('Web-Server')};hostObservation=$hostState;auditPolicies=$policies;auditPrecedence=[pscustomobject]@{KeyExists=$true;ValueExists=$true;Value=1;Type='DWord'};commandLineCapture=[pscustomobject]@{KeyExists=$true;ValueExists=$true;Value=1;Type='DWord'};securityChannelEnabled=$true}
|
|
$process=[pscustomobject]@{ProcessId=123;ParentProcessId=456;Executable='C:\Windows\System32\cmd.exe';Arguments='/d /c echo WELA_PROBE_0123456789abcdef0123456789abcdef';Marker='WELA_PROBE_0123456789abcdef0123456789abcdef';StartedUtc=$now.ToString('o');CompletedUtc=$now.AddSeconds(1).ToString('o');ExitCode=0}
|
|
$before=$state|ConvertTo-Json -Depth 16
|
|
$state.capturedAtUtc=$now.AddSeconds(2).ToString('o');$after=$state|ConvertTo-Json -Depth 16
|
|
$xml=@"
|
|
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"><System><Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}"/><EventID>4688</EventID><Version>2</Version><Level>0</Level><Task>13312</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime="$($now.ToString('o'))"/><EventRecordID>100</EventRecordID><Correlation/><Execution ProcessID="4" ThreadID="100"/><Channel>Security</Channel><Computer>source01.lab.test</Computer><Security/></System><EventData><Data Name="SubjectUserSid">S-1-5-18</Data><Data Name="SubjectUserName">SOURCE01$</Data><Data Name="SubjectDomainName">LAB</Data><Data Name="SubjectLogonId">0x3e7</Data><Data Name="NewProcessId">0x7b</Data><Data Name="NewProcessName">C:\Windows\System32\cmd.exe</Data><Data Name="TokenElevationType">%%1936</Data><Data Name="ProcessId">0x1c8</Data><Data Name="CommandLine">"C:\Windows\System32\cmd.exe" /d /c echo WELA_PROBE_0123456789abcdef0123456789abcdef</Data><Data Name="TargetUserSid">S-1-0-0</Data><Data Name="TargetUserName">-</Data><Data Name="TargetDomainName">-</Data><Data Name="TargetLogonId">0x0</Data><Data Name="ParentProcessName">C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe</Data><Data Name="MandatoryLabel">S-1-16-16384</Data></EventData></Event>
|
|
"@
|
|
$null=New-Item -ItemType Directory -Path $Directory
|
|
$artifacts=@();foreach ($entry in @(@('before-state.json',$before),@('after-state.json',$after),@('process.json',($process|ConvertTo-Json -Depth 6)),@('event.xml',$xml))) {$artifacts+=Write-WelaProbeArtifact $Directory $entry[0] $entry[1]}
|
|
$manifest=[pscustomobject][ordered]@{SchemaVersion=1;Kind='WelaNativeProbeComponents';Probe='security-4688-command-line-v1';Action='Run';Status='NativeEventObserved';ExitCode=0;GeneratedUtc=$now.AddSeconds(-3).ToString('o');PolicyChanges=0;ReadyRuleCredit=0;Scope='Synthetic test fixture';RequiredEvidence=@('Reviewed complete rule and normalization','Backend ingestion','Translated query and successful query result');BeforeState=(ConvertFrom-WelaArrivalJson $before);AfterState=(ConvertFrom-WelaArrivalJson $after);Process=$process;Artifacts=$artifacts;Diagnostic='';OutputPath=$Directory}
|
|
$null=Write-WelaProbeArtifact $Directory 'manifest.json' ($manifest|ConvertTo-Json -Depth 20)
|
|
[pscustomobject]@{Directory=$Directory;Xml=$xml;Host=$hostState;Process=$process;Manifest=$manifest}
|
|
}
|