Files
WELA/config
Shirofune-SecurityandClaude Opus 4.8 1308bc003d Address Copilot review: privilege check, idempotency, ASEP provisioning, service inheritance, update-rules, CLI
- Enable-WelaPrivilege now validates ERROR_NOT_ALL_ASSIGNED per privilege; Set-AuditSacl
  aborts if SeSecurityPrivilege cannot be enabled (was silently proceeding).
- Idempotency (Test-WelaAuditRulePresent) translates IdentityReference to SID before
  comparing (Get-Acl returns NTAccount, not S-1-1-0) and also compares InheritanceFlags,
  so reruns no longer re-add rules and a non-inheriting rule no longer satisfies an
  inheriting target.
- Absent registry ASEP keys (RunOnceEx, Policies\Explorer\Run, ...) are now provisioned
  (created) before the SACL is applied, so a later attacker write is audited via the
  inheritable ACE instead of being missed.
- Services SACL is now inherited (SetValue,CreateSubKey,Delete) so 4657 on child-service
  ImagePath/ServiceDLL/Start edits and service deletion are captured (4697/7045 only cover
  install).
- update-rules now downloads config/audit_sacl_targets.json, matching the recovery message.
- Dropped the non-functional -WhatIf/-Confirm advertising (the script param block has a
  custom -Debug that precludes CmdletBinding); configure-sacl now uses a single -Auto-skippable
  confirmation prompt, consistent with 'configure'.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:11:03 +09:00
..
2025-03-10 18:36:30 +09:00