mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-09-28 18:14:41 +02:00
- Machine file targets now use %SystemRoot% and are expanded at runtime, so a non-C: system drive no longer skips every file target. - Get-WelaUserProfiles now also matches Entra/Azure AD user SIDs (S-1-12-1-*), not only S-1-5-21-*. - WOW64 (Wow6432Node) registry targets are skipped/not provisioned on 32-bit Windows. - reg unload is now checked (retry once, then error) so a failed unload no longer leaves the user's NTUSER.DAT mounted under the temp alias while reporting success. - A failed auditpol subcategory is tracked; the final message warns (instead of claiming success) that SACLs for that class will not produce events. - configure-sacl help text updated: per-user HKCU/AppData ARE covered and absent ASEP keys are provisioned. Registry SACLs continue to use the .NET RegistryKey API (GetAccessControl/SetAccessControl with SeSecurityPrivilege enabled), which was verified live to read/write the SACL and emit 4657. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7