mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 07:15:25 +02:00
* Collect bounded local WMI namespace access evidence * Reference PR428 and preserve UTC worker query timestamps * Observe equivalent runtime self tokens without reverting caller context * Test native token equivalence against restricted caller changes * Diagnose native token differences and package WMI probe guidance * Limit WMI connections to the explicitly scoped security privilege * Document verified native WMI events and privilege preservation * Require an already-running WMI service before namespace reads