Shirofune-SecurityandClaude Opus 4.8 d9bef96e0d configure-sacl: use .NET RegistryKey API for SACLs (Get-Acl -Audit is unreliable on the registry)
Live-tested on Windows Server 2019; three bugs fixed found during testing:
- TOKEN_PRIVILEGES had a `long Luid` after a `uint Count`, which is 8-byte aligned on x64
  and inserted padding, so AdjustTokenPrivileges failed with ERROR_NOT_ALL_ASSIGNED and the
  new privilege guard aborted. Split the LUID into LuidLow(uint)+LuidHigh(int) to match the
  native layout.
- Get-Acl/Set-Acl -Audit is unreliable on the registry provider (returns/throws "path does
  not exist" and null). Registry SACLs now use the .NET RegistryKey API
  (OpenSubKey with ReadPermissions,ChangePermissions -> GetAccessControl(Audit) ->
  AddAuditRule -> SetAccessControl), which honors the enabled SeSecurityPrivilege. Absent
  ASEP keys are provisioned via CreateSubKey then reopened.
- Tamper-protected keys (e.g. Defender Exclusions) that deny even admin are reported as
  SKIPPED, not ERROR.

Verified: File System/Registry/Handle subcategories enabled; HKLM Run carries the Everyone
Success+Failure ContainerInherit SACL; a test autorun write produced EventID 4657 - with no
global registry auditing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
2026-09-17 22:24:27 +09:00
2025-05-12 10:17:50 +09:00

WELA Logo

WELA (Windows Event Log Analyzer) ゑ羅

A tool for auditing Windows event log settings.
Created by Yamato Security — make sure you are actually recording the events that matter for DFIR.

📖 Read the Documentation →

Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية

🦅 About

WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR) — WELA checks your audit policy and log file sizes against best-practice guidelines and real-world Sigma-rule detectability, and can apply the recommended settings for you.

📖 Documentation

All documentation now lives on a dedicated, searchable, multi-language site:

👉 yamato-security.github.io/WELA

Section
🚀 Getting Started Prerequisites, downloads and running WELA
⌨️ Command Reference audit-settings, audit-filesize, configure, configure-sacl, update-rules
✨ Features What WELA can do
📦 Resources Companion projects, changelog, contributing

⬇️ Download

Grab the latest release from the Releases page.

🗂️ Looking for the old README?

The previous single-page README is preserved unchanged:

🤝 Contributing & License

Contributions and bug reports are welcome — see Contributing & Support. WELA is released under the MIT license.


S
Description
WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
Readme MIT
110 MiB
Languages
PowerShell 90.5%
Python 6.3%
CSS 3.2%