diff --git a/CHANGELOG.md b/CHANGELOG.md index de8d04e..490bbfe 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,10 @@ Releases are tagged `vX.Y.Z` and published with a zip and a SHA256 checksum. ## [Unreleased] +### Changed + +- 🧭 **One checklist for fitting the kit to your environment.** The Safety page opens with what to settle before rolling out (your selection, a pilot, SIEM cost, sensitive logs, Group Policy precedence, change process, rollback, your own obligations), linked from the README and Getting started. + ## [2.2.1] - 2026-09-24 More of the logs that matter for lateral movement, and one fix, from a cross-check against other published Windows auditing baselines: SMB server guest logons and security events, the two RDP logs written before a session starts, and Group Policy-forced "do not overwrite" retention reported instead of fought. diff --git a/README.md b/README.md index 19e7be0..853082c 100644 --- a/README.md +++ b/README.md @@ -98,7 +98,13 @@ The kit never touches the settings that can hang or lock out a host (`CrashOnAuditFail`, "do not overwrite" retention, global object access auditing, blanket SACLs) and never reboots, restarts services or shrinks logs. Heavy settings carry a risk note the builder shows before you select -them. Use at your own risk. +them. + +It's a starting point: fit it to your own infrastructure (selection, pilot, +SIEM cost, Group Policy, change process) before rolling out, using the +checklist in +[Safety & FAQ](https://spydisec.github.io/WinLogKit/safety/#fit-it-to-your-environment-first). +Provided as is, without warranty; use at your own risk. ## Contributing diff --git a/docs/getting-started.md b/docs/getting-started.md index 0c35eea..31b1d93 100644 --- a/docs/getting-started.md +++ b/docs/getting-started.md @@ -90,8 +90,11 @@ pipeline or an Intune/RMM check as-is. decisions; [Coverage](mapping.md) shows what they add. To build a selection from scratch instead, run `.\New-LoggingBaseline.ps1` ([Baselines](baselines.md#building-your-own)). -3. **Roll it out** with Intune or Group Policy ([Deploy](deployment.md)). -4. **Collect it centrally**, if you use Windows Event Forwarding +3. **Fit it to your environment**: SIEM cost, Group Policy, change process + and your own obligations + ([checklist](safety.md#fit-it-to-your-environment-first)). +4. **Roll it out** with Intune or Group Policy ([Deploy](deployment.md)). +5. **Collect it centrally**, if you use Windows Event Forwarding ([Collect](wec.md)). ## Where things land diff --git a/docs/safety.md b/docs/safety.md index 5012ad0..b729c14 100644 --- a/docs/safety.md +++ b/docs/safety.md @@ -4,6 +4,43 @@ The settings that can genuinely hurt a Windows machine, how the kit avoids every one of them, and which of the *safe* settings still cost real disk and money. +## Fit it to your environment first + +WinLogKit is a sourced starting point, not a finished policy for your +estate. Before rolling it out: + +- **Pick, then adjust, a selection.** Start from the role preset, copy it, + and turn settings on or off for your hosts + ([Baselines](baselines.md#role-presets)). Keep your copy in version + control. +- **Pilot it.** Run `-WhatIf`, apply on a test host that mirrors + production, and watch it for at least a week: event volume, disk (the + [storage check](#disk-space)) and anything your monitoring or backup + agents do differently. +- **Check the cost downstream.** Every event you turn on is ingested, + stored and licensed by your SIEM. Agree ingest and retention with whoever + runs and pays for it. +- **Treat the logs as sensitive.** Command-line capture and PowerShell + logging can record credentials typed on a command line. Restrict who can + read these logs and where they're forwarded. +- **Know what else sets policy.** On domain-joined hosts, Group Policy + replaces local settings at the next refresh: deliver fleet-wide through + [Group Policy or Intune](deployment.md), and check that nothing else + (other baselines, security tools) sets conflicting audit policy or log + retention. +- **Follow your change process.** The kit never reboots or restarts + services, but it does change audit policy and log settings. Schedule it + like any other configuration change, especially on domain controllers + and certificate authorities. +- **Verify, and keep the way back.** Run `Test-LoggingBaseline.ps1` after + every change. The first real run saves a rollback copy, and `-Rollback` + restores it. +- **Check your obligations.** Retention periods, privacy and sector rules + differ by organisation and country; the kit doesn't decide them for you. + +WinLogKit is provided as is, without warranty, under the +[MIT License](https://github.com/spydisec/WinLogKit/blob/main/LICENSE). + ## What the kit will never do Windows auditing has settings that can hang, halt or lock out a server. The