mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 15:25:24 +02:00
* Add native AppLocker EXE event validation probe * Reference PR 423 in changelogs * Isolate AppLocker native fixture and preserve prerequisite diagnostics * Report an integer zero for an empty AppLocker policy * Prepare disposable AppLocker probe policy without bypassing production importer guards * Retain bounded native AppLocker channel diagnostics on probe failure * Require native policy application before the disposable AppLocker probe * Preserve exact timestamp strings in native evidence fixtures * Record actual runner session and AppLocker publication diagnostics * Activate and restore the native policy converter on disposable AppLocker hosts * Compare native task freshness without guessing its timestamp timezone * Verify effective policy and borrowed converter inactivity during fixture cleanup * Track the actual native policy-converter task instance instead of cached timestamps
29 lines
1.2 KiB
Plaintext
29 lines
1.2 KiB
Plaintext
# These inputs are pinned by exact byte hashes; Windows checkouts must keep LF.
|
|
/config/security_rules.json text eol=lf
|
|
/config/eid_subcategory_mapping.csv text eol=lf
|
|
/config/rule_eligibility_manifest.json text eol=lf
|
|
/config/audit_scoring.json text eol=lf
|
|
|
|
# Exact-context default evidence pins these source/collector bytes.
|
|
/config/baselines.json text eol=lf
|
|
/config/audit_profiles.json text eol=lf
|
|
/config/control_applicability.json text eol=lf
|
|
/scripts/ControlApplicability.ps1 text eol=lf
|
|
/scripts/Configuration.ps1 text eol=lf
|
|
/modules/NativeProviders.psm1 text eol=lf
|
|
/modules/AuditProfiles.psm1 text eol=lf
|
|
# Full upstream rule artifacts retain their exact pinned bytes on every platform.
|
|
/config/provider_rule_sources/*.yml -text whitespace=-blank-at-eol
|
|
|
|
# Selected SACL review plans pin these exact source bytes.
|
|
/config/audit_sacl_targets.json text eol=lf
|
|
/scripts/TargetedSaclPlanning.ps1 text eol=lf
|
|
/scripts/SelectedSaclConfiguration.ps1 text eol=lf
|
|
/scripts/SelectedSaclNative.cs text eol=lf
|
|
/modules/AuditCatalog.psm1 text eol=lf
|
|
# Fixed public pending-request fixture is pinned by its exact byte hash.
|
|
/tests/fixtures/adcs-pending-probe.csr text eol=lf
|
|
|
|
scripts/AppLockerProbe.ps1 text eol=lf
|
|
tests/AppLockerProbe*.ps1 text eol=lf
|