- Enable-WelaPrivilege now validates ERROR_NOT_ALL_ASSIGNED per privilege; Set-AuditSacl aborts if SeSecurityPrivilege cannot be enabled (was silently proceeding). - Idempotency (Test-WelaAuditRulePresent) translates IdentityReference to SID before comparing (Get-Acl returns NTAccount, not S-1-1-0) and also compares InheritanceFlags, so reruns no longer re-add rules and a non-inheriting rule no longer satisfies an inheriting target. - Absent registry ASEP keys (RunOnceEx, Policies\Explorer\Run, ...) are now provisioned (created) before the SACL is applied, so a later attacker write is audited via the inheritable ACE instead of being missed. - Services SACL is now inherited (SetValue,CreateSubKey,Delete) so 4657 on child-service ImagePath/ServiceDLL/Start edits and service deletion are captured (4697/7045 only cover install). - update-rules now downloads config/audit_sacl_targets.json, matching the recovery message. - Dropped the non-functional -WhatIf/-Confirm advertising (the script param block has a custom -Debug that precludes CmdletBinding); configure-sacl now uses a single -Auto-skippable confirmation prompt, consistent with 'configure'. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
WELA (Windows Event Log Analyzer) ゑ羅
A tool for auditing Windows event log settings.
Created by Yamato Security — make sure you are
actually recording the events that matter for DFIR.
📖 Read the Documentation →
Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية🦅 About
WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR) — WELA checks your audit policy and log file sizes against best-practice guidelines and real-world Sigma-rule detectability, and can apply the recommended settings for you.
📖 Documentation
All documentation now lives on a dedicated, searchable, multi-language site:
👉 yamato-security.github.io/WELA
| Section | |
|---|---|
| 🚀 Getting Started | Prerequisites, downloads and running WELA |
| ⌨️ Command Reference | audit-settings, audit-filesize, configure, configure-sacl, update-rules |
| ✨ Features | What WELA can do |
| 📦 Resources | Companion projects, changelog, contributing |
⬇️ Download
Grab the latest release from the Releases page.
🗂️ Looking for the old README?
The previous single-page README is preserved unchanged:
- 📄 OLD-README.md — English
- 📄 OLD-README-Japanese.md — 日本語
🤝 Contributing & License
Contributions and bug reports are welcome — see Contributing & Support. WELA is released under the MIT license.
