田中ザック Isaac Mathis 5ba53fbcfb Validate native AppLocker EXE event generation with an opt-in probe (#423)
* Add native AppLocker EXE event validation probe

* Reference PR 423 in changelogs

* Isolate AppLocker native fixture and preserve prerequisite diagnostics

* Report an integer zero for an empty AppLocker policy

* Prepare disposable AppLocker probe policy without bypassing production importer guards

* Retain bounded native AppLocker channel diagnostics on probe failure

* Require native policy application before the disposable AppLocker probe

* Preserve exact timestamp strings in native evidence fixtures

* Record actual runner session and AppLocker publication diagnostics

* Activate and restore the native policy converter on disposable AppLocker hosts

* Compare native task freshness without guessing its timestamp timezone

* Verify effective policy and borrowed converter inactivity during fixture cleanup

* Track the actual native policy-converter task instance instead of cached timestamps
2026-09-20 22:46:56 +09:00
2025-05-12 10:17:50 +09:00

WELA Logo

WELA (Windows Event Log Analyzer) ゑ羅

A tool for auditing Windows event log settings.
Created by Yamato Security — make sure you are actually recording the events that matter for DFIR.

📖 Read the Documentation →

Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية

🦅 About

WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR) — WELA checks your audit policy and log file sizes against best-practice guidelines and real-world Sigma-rule detectability, and can apply the recommended settings for you.

Advanced audit policy can also use versioned WELA, Microsoft, CIS and ASD profiles for shared audit, plan and configure behavior. Profiles cover advanced audit policy only.

📖 Documentation

All documentation now lives on a dedicated, searchable, multi-language site:

👉 yamato-security.github.io/WELA

Section
🚀 Getting Started Prerequisites, downloads and running WELA
⌨️ Command Reference audit-settings, audit-filesize, configure, configure-sacl, update-rules
✨ Features What WELA can do
📦 Resources Companion projects, changelog, contributing

⬇️ Download

Grab the latest release from the Releases page.

🗂️ Looking for the old README?

The previous single-page README is preserved unchanged:

🤝 Contributing & License

Contributions and bug reports are welcome — see Contributing & Support. WELA is released under the MIT license.


S
Description
WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
Readme MIT
110 MiB
0 Stars 1 Watchers 0 Forks
Languages
PowerShell 90.5%
Python 6.3%
CSS 3.2%