Changelog¶
Info
This page mirrors the project CHANGELOG.md. See the Releases page for downloads.
2.2.0 [2026/xx/xx] - Dev Release¶
Improvements:
- Added a
configure-saclcommand that sets targeted audit SACLs on the autostart/persistence registry keys and sensitive files the detection rules watch, so File System (4663), Registry (4657) and Handle Manipulation (4656) auditing produce useful events without enabling global object auditing. It covers machine-wide objects plus per-user HKCU keys and profile AppData across all user profiles and the Default profile (so future users inherit the SACL). Targets live inconfig/audit_sacl_targets.json. (#361) (@YamatoSecurity) configurenow also enables Detailed Tracking > Process Termination (4689), Object Access > Detailed File Share (5145), and (on domain controllers) LDAP query logging (Directory Service 1644 via NTDS15 Field Engineering), so a full detection baseline is applied without any manualauditpol/registry steps. (#361) (@YamatoSecurity)- Baseline definitions were moved out of
WELA.ps1into aconfig/baselines.jsonconfig file, so adding or changing a baseline is now a JSON-only edit. (#358) (@fukusuket) - The
Microsoft-Windows-DFSN-Server/Adminchannel is now checked byaudit-settingsandaudit-filesize. (#358) (@fukusuket) - MITRE ATT&CK Navigator heatmaps are now generated for ATT&CK v19, and technique IDs that ATT&CK has revoked are rewritten to their replacements (for example
T1562andT1562.001, which v19 folded intoT1685). Navigator silently discards revoked entries, so that coverage used to disappear from the heatmap. (@fukusuket)
Bug Fixes:
- Fixed domain NTLM auditing:
configurenow setsAuditNTLMInDomain=7(Enable all) only on confirmed domain controllers, instead of writing2on every host. This setting is left unchanged on other hosts and hosts whose role cannot be determined. Audit output reports the domain NTLM setting, and configuration verifies registry writes and reports failures. (#389) (@Shirofune-Security) - Rule filtering applied only the last criterion instead of all of them, so rule counts were inaccurate. (#358) (@fukusuket)
- Rules were reported as usable even when the logs they depend on were disabled. (#358) (@fukusuket)
- Rules that belong to multiple categories were counted and written to the CSV files multiple times. (#358) (@fukusuket)
- Rules that did not match any category were dropped from the CSV files and from the coverage total. They are now reported under
Uncategorized. (#358) (@fukusuket) - The utilization threshold was compared as a string, so the percentage was shown in the wrong color. (#358) (@fukusuket)
Success and Failurewas shown in red even though auditing was enabled. (#358) (@fukusuket)- The MITRE ATT&CK Navigator layer contained invalid technique IDs and was written as UTF-16, which ATT&CK Navigator cannot read. (#358) (@fukusuket)
- Running WELA from a directory other than the one it is installed in failed. (#358) (@fukusuket)
audit-filesizeaborted the whole check when a single log was missing. (#358) (@fukusuket)- PowerShell logging settings were only read from the 32-bit registry view, so a machine configured by GPO was reported as
Disabled. (#358) (@fukusuket) - Parsing of the
auditpoloutput could fail, and runningaudit-settingswithout Administrator privileges produced a confidently wrong report. (#358) (@fukusuket) configure -Baseline ASDsilently applied the YamatoSecurity settings. (#358) (@fukusuket)- A failed download in
update-rulescould corrupt the existing config files. (#358) (@fukusuket) - CSV output was inconsistent between the
std,tableandguioutput types. (#358) (@fukusuket) - The release and CSV creation GitHub Actions workflows were failing. (#358) (@fukusuket)
Note: because of the fixes above, the reported utilization is now lower than in 2.1.0 (23.38% -> 12.94% on the same machine). The new number is the correct one: rules whose logs are disabled are no longer counted as usable, and rules that were previously dropped are now included in the total.
2.1.0 [2026/02/13] - Winter Release¶
Bug Fixes:
- Configuration might break Netlogon on Domain Controllers. (#243) (@fukusuket) (Thanks to @feiglein74 for reporting this!)
2.0.0 [2025/11/16] - CODE BLUE Release¶
New Features:
- Support for MITRE ATT&CK Navigator heatmaps. (#11) (@fukusuket)
- Added a
configurecommand to configure Windows settings to various baselines. (#12) (@fukusuket) - Support for Defender for Identity required logs. (#114) (@fukusuket)
Bug Fixes:
- Some of the rule count was not accurate. (#99) (@fukusuket)
- TaskScheduler log settings were not accurately reported. (#100) (@fukusuket))
1.0.0 [2025/05/20] - AUSCERT/SINCON Release¶
New Features:
audit-settings: Check Windows Event Log audit policy settings.audit-filesize: Check Windows Event Log file size.update-rules: Update WELA's Sigma rules config files.