Files
WELA/config/custom-audit-profile.example.json
田中ザック Isaac Mathis 83b2ddd526 Support validated custom audit profile files through the shared engine (#416)
* Support validated operator-owned advanced audit profile files

* Reject lenient custom profile JSON and protect report output aliases

* Link custom audit profile changelog to PR 416

* Make custom JSON rejection fixtures portable across PowerShell versions
2026-09-20 18:09:52 +09:00

82 lines
1.9 KiB
JSON

{
"schemaVersion": 1,
"kind": "WelaCustomAuditProfiles",
"catalog": [
{
"id": "Process Creation",
"guid": "0CCE922B-69AE-11D9-BED3-505054503030",
"category": "Detailed Tracking"
},
{
"id": "Process Termination",
"guid": "0CCE922C-69AE-11D9-BED3-505054503030",
"category": "Detailed Tracking"
},
{
"id": "Detailed File Share",
"guid": "0CCE9244-69AE-11D9-BED3-505054503030",
"category": "Object Access"
},
{
"id": "File System",
"guid": "0CCE921D-69AE-11D9-BED3-505054503030",
"category": "Object Access"
}
],
"sources": {
"organization": {
"title": "Example organization audit standard (replace with your reviewed source)",
"version": "1.0",
"url": "https://example.invalid/security/audit-standard"
}
},
"profiles": [
{
"id": "custom-example",
"version": "1.0",
"sourceIds": [
"organization"
],
"omitted": "unchanged",
"scope": "advanced-audit-policy-only",
"appliesTo": [
{
"roles": [
"Client"
],
"minBuild": 26100,
"maxBuild": 26200
},
{
"roles": [
"MemberServer",
"DomainController",
"ADCS"
],
"minBuild": 20348,
"maxBuild": 26100
}
],
"controls": {
"Process Creation": {
"mode": "minimum",
"mask": 1
},
"File System": {
"mode": "optional",
"mask": 3
},
"Detailed File Share": {
"mode": "not-configured"
},
"Process Termination": {
"mode": "exact",
"mask": 1
}
},
"roleOverrides": {},
"note": "Example only: review before configuring. File System needs matching SACLs."
}
]
}