mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-07 23:14:45 +02:00
* Add bounded local delivery measurement and exact EVTX samples * Link delivery measurement changelog to PR 430 * Reject evidence aliases before Windows path normalization * Use PowerShell 5.1-compatible record IDs and bound fixture cleanup * Revalidate the native EVTX artifact before recording final evidence * Require exact observed local computer identities for sampled events * Clarify provider scope within shared built-in event channels * Preserve mixed XML payload ordering in EVTX sample verification * Bound ordered event XML comparisons for nested UserData * Dispose observer wait handle when bookmark creation fails
53 lines
2.2 KiB
Plaintext
53 lines
2.2 KiB
Plaintext
# These inputs are pinned by exact byte hashes; Windows checkouts must keep LF.
|
|
/config/security_rules.json text eol=lf
|
|
/config/eid_subcategory_mapping.csv text eol=lf
|
|
/config/rule_eligibility_manifest.json text eol=lf
|
|
/config/audit_scoring.json text eol=lf
|
|
|
|
# Exact-context default evidence pins these source/collector bytes.
|
|
/config/baselines.json text eol=lf
|
|
/config/audit_profiles.json text eol=lf
|
|
/config/control_applicability.json text eol=lf
|
|
/scripts/ControlApplicability.ps1 text eol=lf
|
|
/scripts/Configuration.ps1 text eol=lf
|
|
/modules/NativeProviders.psm1 text eol=lf
|
|
/modules/AuditProfiles.psm1 text eol=lf
|
|
# Full upstream rule artifacts retain their exact pinned bytes on every platform.
|
|
/config/provider_rule_sources/*.yml -text whitespace=-blank-at-eol
|
|
|
|
# Selected SACL review plans pin these exact source bytes.
|
|
/config/audit_sacl_targets.json text eol=lf
|
|
/scripts/TargetedSaclPlanning.ps1 text eol=lf
|
|
/scripts/SelectedSaclConfiguration.ps1 text eol=lf
|
|
/scripts/SelectedSaclNative.cs text eol=lf
|
|
/modules/AuditCatalog.psm1 text eol=lf
|
|
# Fixed public pending-request fixture is pinned by its exact byte hash.
|
|
/tests/fixtures/adcs-pending-probe.csr text eol=lf
|
|
|
|
scripts/WecUpdate.ps1 text eol=lf
|
|
scripts/WecUpdateNative.cs text eol=lf
|
|
modules/WefSubscriptions.psm1 text eol=lf
|
|
tests/WecUpdate*.ps1 text eol=lf
|
|
modules/WecSubscriptionXml.cs text eol=lf
|
|
# DNS analytical receipts pin the catalog and lifecycle implementation bytes.
|
|
/config/native_provider_packs.json text eol=lf
|
|
/scripts/NativeProviderPacks.ps1 text eol=lf
|
|
/scripts/DnsAnalytical.ps1 text eol=lf
|
|
/scripts/DnsAnalyticalArchive.cs text eol=lf
|
|
# Native WEC XML reader source identity remains identical across checkouts.
|
|
/modules/WecSubscriptionXml.cs text eol=lf
|
|
scripts/AppLockerProbe.ps1 text eol=lf
|
|
tests/AppLockerProbe*.ps1 text eol=lf
|
|
|
|
# Local delivery catalog and native observer retain reproducible source bytes.
|
|
config/event_measurement.json text eol=lf
|
|
scripts/EventMeasurement* text eol=lf
|
|
tests/EventMeasurement* text eol=lf
|
|
tests/SelectedSaclFixtureProtection.cs text eol=lf
|
|
# Fixed local WMI probe source/worker fingerprints.
|
|
/scripts/WmiProbe*.ps1 text eol=lf
|
|
/scripts/WmiProbeNative.cs text eol=lf
|
|
/scripts/WmiNamespaceAuditing.ps1 text eol=lf
|
|
/scripts/WefArrival.ps1 text eol=lf
|
|
/tests/WmiProbe*.ps1 text eol=lf
|