Files
Shirofune-SecurityandClaude Opus 4.8 10c1bcaac7 Address Copilot re-review: %SystemRoot%, Entra SIDs, WOW64 gate, reg-unload check, subcategory-failure, help
- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system
  drive no longer skips every file target.
- Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*.
- WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows.
- reg unload is now checked (retry once, then error) so a failed unload no longer leaves the
  user's NTUSER.DAT mounted under the temp alias while reporting success.
- A failed auditpol subcategory is tracked; the final message warns (instead of claiming success)
  that SACLs for that class will not produce events.
- configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned.

Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with
SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:49:42 +09:00
..