Live-tested on Windows Server 2019; three bugs fixed found during testing: - TOKEN_PRIVILEGES had a `long Luid` after a `uint Count`, which is 8-byte aligned on x64 and inserted padding, so AdjustTokenPrivileges failed with ERROR_NOT_ALL_ASSIGNED and the new privilege guard aborted. Split the LUID into LuidLow(uint)+LuidHigh(int) to match the native layout. - Get-Acl/Set-Acl -Audit is unreliable on the registry provider (returns/throws "path does not exist" and null). Registry SACLs now use the .NET RegistryKey API (OpenSubKey with ReadPermissions,ChangePermissions -> GetAccessControl(Audit) -> AddAuditRule -> SetAccessControl), which honors the enabled SeSecurityPrivilege. Absent ASEP keys are provisioned via CreateSubKey then reopened. - Tamper-protected keys (e.g. Defender Exclusions) that deny even admin are reported as SKIPPED, not ERROR. Verified: File System/Registry/Handle subcategories enabled; HKLM Run carries the Everyone Success+Failure ContainerInherit SACL; a test autorun write produced EventID 4657 - with no global registry auditing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
WELA (Windows Event Log Analyzer) ゑ羅
A tool for auditing Windows event log settings.
Created by Yamato Security — make sure you are
actually recording the events that matter for DFIR.
📖 Read the Documentation →
Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية🦅 About
WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR) — WELA checks your audit policy and log file sizes against best-practice guidelines and real-world Sigma-rule detectability, and can apply the recommended settings for you.
📖 Documentation
All documentation now lives on a dedicated, searchable, multi-language site:
👉 yamato-security.github.io/WELA
| Section | |
|---|---|
| 🚀 Getting Started | Prerequisites, downloads and running WELA |
| ⌨️ Command Reference | audit-settings, audit-filesize, configure, configure-sacl, update-rules |
| ✨ Features | What WELA can do |
| 📦 Resources | Companion projects, changelog, contributing |
⬇️ Download
Grab the latest release from the Releases page.
🗂️ Looking for the old README?
The previous single-page README is preserved unchanged:
- 📄 OLD-README.md — English
- 📄 OLD-README-Japanese.md — 日本語
🤝 Contributing & License
Contributions and bug reports are welcome — see Contributing & Support. WELA is released under the MIT license.
