mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-09-30 03:27:15 +02:00
* Support validated operator-owned advanced audit profile files * Reject lenient custom profile JSON and protect report output aliases * Link custom audit profile changelog to PR 416 * Make custom JSON rejection fixtures portable across PowerShell versions
82 lines
1.9 KiB
JSON
82 lines
1.9 KiB
JSON
{
|
|
"schemaVersion": 1,
|
|
"kind": "WelaCustomAuditProfiles",
|
|
"catalog": [
|
|
{
|
|
"id": "Process Creation",
|
|
"guid": "0CCE922B-69AE-11D9-BED3-505054503030",
|
|
"category": "Detailed Tracking"
|
|
},
|
|
{
|
|
"id": "Process Termination",
|
|
"guid": "0CCE922C-69AE-11D9-BED3-505054503030",
|
|
"category": "Detailed Tracking"
|
|
},
|
|
{
|
|
"id": "Detailed File Share",
|
|
"guid": "0CCE9244-69AE-11D9-BED3-505054503030",
|
|
"category": "Object Access"
|
|
},
|
|
{
|
|
"id": "File System",
|
|
"guid": "0CCE921D-69AE-11D9-BED3-505054503030",
|
|
"category": "Object Access"
|
|
}
|
|
],
|
|
"sources": {
|
|
"organization": {
|
|
"title": "Example organization audit standard (replace with your reviewed source)",
|
|
"version": "1.0",
|
|
"url": "https://example.invalid/security/audit-standard"
|
|
}
|
|
},
|
|
"profiles": [
|
|
{
|
|
"id": "custom-example",
|
|
"version": "1.0",
|
|
"sourceIds": [
|
|
"organization"
|
|
],
|
|
"omitted": "unchanged",
|
|
"scope": "advanced-audit-policy-only",
|
|
"appliesTo": [
|
|
{
|
|
"roles": [
|
|
"Client"
|
|
],
|
|
"minBuild": 26100,
|
|
"maxBuild": 26200
|
|
},
|
|
{
|
|
"roles": [
|
|
"MemberServer",
|
|
"DomainController",
|
|
"ADCS"
|
|
],
|
|
"minBuild": 20348,
|
|
"maxBuild": 26100
|
|
}
|
|
],
|
|
"controls": {
|
|
"Process Creation": {
|
|
"mode": "minimum",
|
|
"mask": 1
|
|
},
|
|
"File System": {
|
|
"mode": "optional",
|
|
"mask": 3
|
|
},
|
|
"Detailed File Share": {
|
|
"mode": "not-configured"
|
|
},
|
|
"Process Termination": {
|
|
"mode": "exact",
|
|
"mask": 1
|
|
}
|
|
},
|
|
"roleOverrides": {},
|
|
"note": "Example only: review before configuring. File System needs matching SACLs."
|
|
}
|
|
]
|
|
}
|