mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
* Add bounded local delivery measurement and exact EVTX samples * Link delivery measurement changelog to PR 430 * Reject evidence aliases before Windows path normalization * Use PowerShell 5.1-compatible record IDs and bound fixture cleanup * Revalidate the native EVTX artifact before recording final evidence * Require exact observed local computer identities for sampled events * Clarify provider scope within shared built-in event channels * Preserve mixed XML payload ordering in EVTX sample verification * Bound ordered event XML comparisons for nested UserData * Dispose observer wait handle when bookmark creation fails
16 lines
756 B
JSON
16 lines
756 B
JSON
{
|
|
"schemaVersion": 1,
|
|
"kind": "WelaLocalDeliveryMeasurement",
|
|
"channels": [
|
|
"Security",
|
|
"System",
|
|
"Application",
|
|
"Microsoft-Windows-DNS-Client/Operational",
|
|
"Microsoft-Windows-CAPI2/Operational",
|
|
"Microsoft-Windows-WinRM/Operational",
|
|
"Microsoft-Windows-PowerShell/Operational"
|
|
],
|
|
"source": "https://learn.microsoft.com/en-us/windows/win32/api/winevt/nf-winevt-evtsubscribe",
|
|
"scope": "Exact registered local Administrative/Operational channels only. ForwardedEvents, Analytic/Debug and third-party channels are excluded. Shared built-in channels may contain records from non-Microsoft providers; actual provider identity is retained. Registration, availability and reader access are verified on the actual host."
|
|
}
|