mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-07 23:14:45 +02:00
- Enable-WelaPrivilege now validates ERROR_NOT_ALL_ASSIGNED per privilege; Set-AuditSacl aborts if SeSecurityPrivilege cannot be enabled (was silently proceeding). - Idempotency (Test-WelaAuditRulePresent) translates IdentityReference to SID before comparing (Get-Acl returns NTAccount, not S-1-1-0) and also compares InheritanceFlags, so reruns no longer re-add rules and a non-inheriting rule no longer satisfies an inheriting target. - Absent registry ASEP keys (RunOnceEx, Policies\Explorer\Run, ...) are now provisioned (created) before the SACL is applied, so a later attacker write is audited via the inheritable ACE instead of being missed. - Services SACL is now inherited (SetValue,CreateSubKey,Delete) so 4657 on child-service ImagePath/ServiceDLL/Start edits and service deletion are captured (4697/7045 only cover install). - update-rules now downloads config/audit_sacl_targets.json, matching the recovery message. - Dropped the non-functional -WhatIf/-Confirm advertising (the script param block has a custom -Debug that precludes CmdletBinding); configure-sacl now uses a single -Auto-skippable confirmation prompt, consistent with 'configure'. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7