Files
WELA/.github/workflows/wmi-probe.yml
T
田中ザック Isaac Mathis b84b97b358 Collect local WMI namespace audit evidence with a fixed read probe (#428)
* Collect bounded local WMI namespace access evidence

* Reference PR428 and preserve UTC worker query timestamps

* Observe equivalent runtime self tokens without reverting caller context

* Test native token equivalence against restricted caller changes

* Diagnose native token differences and package WMI probe guidance

* Limit WMI connections to the explicitly scoped security privilege

* Document verified native WMI events and privilege preservation

* Require an already-running WMI service before namespace reads
2026-09-21 09:08:20 +09:00

40 lines
1.2 KiB
YAML

name: Native local WMI access probe
on:
push:
branches: ['**']
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
wmi-probe:
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
os: [windows-2022, windows-2025]
engine: [powershell, pwsh]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
- name: Fixtures and public guards in Windows PowerShell5.1
if: matrix.engine == 'powershell'
shell: powershell
run: |
./tests/WmiProbe.Tests.ps1
./tests/WmiProbe.Cli.Tests.ps1
- name: Native owned namespace and4662 in Windows PowerShell5.1
if: matrix.engine == 'powershell'
shell: powershell
run: ./tests/WmiProbe.Windows.Tests.ps1 -AllowDisposableNamespaceWrite
- name: Fixtures and public guards in PowerShell7
if: matrix.engine == 'pwsh'
shell: pwsh
run: |
./tests/WmiProbe.Tests.ps1
./tests/WmiProbe.Cli.Tests.ps1
- name: Native owned namespace and4662 in PowerShell7
if: matrix.engine == 'pwsh'
shell: pwsh
run: ./tests/WmiProbe.Windows.Tests.ps1 -AllowDisposableNamespaceWrite