Files
WELA/.gitattributes
T
田中ザック Isaac Mathis 5ba53fbcfb Validate native AppLocker EXE event generation with an opt-in probe (#423)
* Add native AppLocker EXE event validation probe

* Reference PR 423 in changelogs

* Isolate AppLocker native fixture and preserve prerequisite diagnostics

* Report an integer zero for an empty AppLocker policy

* Prepare disposable AppLocker probe policy without bypassing production importer guards

* Retain bounded native AppLocker channel diagnostics on probe failure

* Require native policy application before the disposable AppLocker probe

* Preserve exact timestamp strings in native evidence fixtures

* Record actual runner session and AppLocker publication diagnostics

* Activate and restore the native policy converter on disposable AppLocker hosts

* Compare native task freshness without guessing its timestamp timezone

* Verify effective policy and borrowed converter inactivity during fixture cleanup

* Track the actual native policy-converter task instance instead of cached timestamps
2026-09-20 22:46:56 +09:00

29 lines
1.2 KiB
Plaintext

# These inputs are pinned by exact byte hashes; Windows checkouts must keep LF.
/config/security_rules.json text eol=lf
/config/eid_subcategory_mapping.csv text eol=lf
/config/rule_eligibility_manifest.json text eol=lf
/config/audit_scoring.json text eol=lf
# Exact-context default evidence pins these source/collector bytes.
/config/baselines.json text eol=lf
/config/audit_profiles.json text eol=lf
/config/control_applicability.json text eol=lf
/scripts/ControlApplicability.ps1 text eol=lf
/scripts/Configuration.ps1 text eol=lf
/modules/NativeProviders.psm1 text eol=lf
/modules/AuditProfiles.psm1 text eol=lf
# Full upstream rule artifacts retain their exact pinned bytes on every platform.
/config/provider_rule_sources/*.yml -text whitespace=-blank-at-eol
# Selected SACL review plans pin these exact source bytes.
/config/audit_sacl_targets.json text eol=lf
/scripts/TargetedSaclPlanning.ps1 text eol=lf
/scripts/SelectedSaclConfiguration.ps1 text eol=lf
/scripts/SelectedSaclNative.cs text eol=lf
/modules/AuditCatalog.psm1 text eol=lf
# Fixed public pending-request fixture is pinned by its exact byte hash.
/tests/fixtures/adcs-pending-probe.csr text eol=lf
scripts/AppLockerProbe.ps1 text eol=lf
tests/AppLockerProbe*.ps1 text eol=lf