'configure' already enables Object Access subcategories such as File Share, SAM and Certification Services, but File System (4663), Registry (4657) and Handle Manipulation (4656) auditing produce no events without SACLs on the audited objects - and enabling them globally floods the log. This adds targeted SACLs on only the autostart/persistence registry keys (ASEPs) and sensitive files that the Hayabusa/Sigma Security-channel rules actually watch, so those rules can fire without global object auditing. - config/audit_sacl_targets.json: curated, commented list of 30 registry keys (Run/RunOnce, Winlogon, IFEO, AppInit, Explorer shell extensions, Active Setup, Command Processor AutoRun, Session Manager, LSA packages, Winsock LSP, protocol handlers, logon scripts, Defender exclusions, service create/delete, ...) and 7 files (NTDS dir, SAM/SECURITY/SYSTEM hives, lsass.exe, ntdsutil, vssadmin), each tagged with the ATT&CK technique / rule class it serves. - WELA.ps1: new 'configure-sacl' command. Enables the File System / Registry / Handle Manipulation subcategories (by GUID) and applies the SACLs from the config (principal Everyone, Success+Failure, ContainerInherit on registry keys), idempotently, honoring -Auto / -WhatIf / -Confirm. Enables SeSecurityPrivilege first; skips objects absent on the host. Per-user objects (HKCU / profile AppData) and live LSASS memory/handle access are intentionally out of scope (need a per-user mechanism / Sysmon EID 10) and are documented as such. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MVUmXZBkr5FnZ2hwFkDhx7
3.9 KiB
WELA (Windows Event Log Analyzer) ゑ羅
A tool for auditing Windows event log settings.
Created by Yamato Security — make sure you are
actually recording the events that matter for DFIR.
📖 Read the Documentation →
Available in 15 languages — English · 日本語 · 繁體中文 · 한국어 · Deutsch · Türkçe · Français · Español · Português (Brasil) · Українська · हिन्दी · Bahasa Indonesia · မြန်မာဘာသာ · ไทย · العربية🦅 About
WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing Windows event log settings. Windows event logs are a vital source of information for Digital Forensics and Incident Response (DFIR) — WELA checks your audit policy and log file sizes against best-practice guidelines and real-world Sigma-rule detectability, and can apply the recommended settings for you.
📖 Documentation
All documentation now lives on a dedicated, searchable, multi-language site:
👉 yamato-security.github.io/WELA
| Section | |
|---|---|
| 🚀 Getting Started | Prerequisites, downloads and running WELA |
| ⌨️ Command Reference | audit-settings, audit-filesize, configure, configure-sacl, update-rules |
| ✨ Features | What WELA can do |
| 📦 Resources | Companion projects, changelog, contributing |
⬇️ Download
Grab the latest release from the Releases page.
🗂️ Looking for the old README?
The previous single-page README is preserved unchanged:
- 📄 OLD-README.md — English
- 📄 OLD-README-Japanese.md — 日本語
🤝 Contributing & License
Contributions and bug reports are welcome — see Contributing & Support. WELA is released under the MIT license.
