From 9f456e094aba27ffcd6ec1f905bca04c2728105f Mon Sep 17 00:00:00 2001 From: spydisec <9101327+spydisec@users.noreply.github.com> Date: Thu, 24 Sep 2026 14:36:46 +1000 Subject: [PATCH] Docs: fit-it-to-your-environment checklist The safety guidance was spread across four pages. The Safety page now opens with one checklist to settle before rolling out, linked from the README's Safety section and Getting started's next steps. Co-Authored-By: Claude Opus 5.5 --- CHANGELOG.md | 4 ++++ README.md | 8 +++++++- docs/getting-started.md | 7 +++++-- docs/safety.md | 37 +++++++++++++++++++++++++++++++++++++ 4 files changed, 53 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index de8d04e..490bbfe 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,10 @@ Releases are tagged `vX.Y.Z` and published with a zip and a SHA256 checksum. ## [Unreleased] +### Changed + +- 🧭 **One checklist for fitting the kit to your environment.** The Safety page opens with what to settle before rolling out (your selection, a pilot, SIEM cost, sensitive logs, Group Policy precedence, change process, rollback, your own obligations), linked from the README and Getting started. + ## [2.2.1] - 2026-09-24 More of the logs that matter for lateral movement, and one fix, from a cross-check against other published Windows auditing baselines: SMB server guest logons and security events, the two RDP logs written before a session starts, and Group Policy-forced "do not overwrite" retention reported instead of fought. diff --git a/README.md b/README.md index 19e7be0..853082c 100644 --- a/README.md +++ b/README.md @@ -98,7 +98,13 @@ The kit never touches the settings that can hang or lock out a host (`CrashOnAuditFail`, "do not overwrite" retention, global object access auditing, blanket SACLs) and never reboots, restarts services or shrinks logs. Heavy settings carry a risk note the builder shows before you select -them. Use at your own risk. +them. + +It's a starting point: fit it to your own infrastructure (selection, pilot, +SIEM cost, Group Policy, change process) before rolling out, using the +checklist in +[Safety & FAQ](https://spydisec.github.io/WinLogKit/safety/#fit-it-to-your-environment-first). +Provided as is, without warranty; use at your own risk. ## Contributing diff --git a/docs/getting-started.md b/docs/getting-started.md index 0c35eea..31b1d93 100644 --- a/docs/getting-started.md +++ b/docs/getting-started.md @@ -90,8 +90,11 @@ pipeline or an Intune/RMM check as-is. decisions; [Coverage](mapping.md) shows what they add. To build a selection from scratch instead, run `.\New-LoggingBaseline.ps1` ([Baselines](baselines.md#building-your-own)). -3. **Roll it out** with Intune or Group Policy ([Deploy](deployment.md)). -4. **Collect it centrally**, if you use Windows Event Forwarding +3. **Fit it to your environment**: SIEM cost, Group Policy, change process + and your own obligations + ([checklist](safety.md#fit-it-to-your-environment-first)). +4. **Roll it out** with Intune or Group Policy ([Deploy](deployment.md)). +5. **Collect it centrally**, if you use Windows Event Forwarding ([Collect](wec.md)). ## Where things land diff --git a/docs/safety.md b/docs/safety.md index 5012ad0..b729c14 100644 --- a/docs/safety.md +++ b/docs/safety.md @@ -4,6 +4,43 @@ The settings that can genuinely hurt a Windows machine, how the kit avoids every one of them, and which of the *safe* settings still cost real disk and money. +## Fit it to your environment first + +WinLogKit is a sourced starting point, not a finished policy for your +estate. Before rolling it out: + +- **Pick, then adjust, a selection.** Start from the role preset, copy it, + and turn settings on or off for your hosts + ([Baselines](baselines.md#role-presets)). Keep your copy in version + control. +- **Pilot it.** Run `-WhatIf`, apply on a test host that mirrors + production, and watch it for at least a week: event volume, disk (the + [storage check](#disk-space)) and anything your monitoring or backup + agents do differently. +- **Check the cost downstream.** Every event you turn on is ingested, + stored and licensed by your SIEM. Agree ingest and retention with whoever + runs and pays for it. +- **Treat the logs as sensitive.** Command-line capture and PowerShell + logging can record credentials typed on a command line. Restrict who can + read these logs and where they're forwarded. +- **Know what else sets policy.** On domain-joined hosts, Group Policy + replaces local settings at the next refresh: deliver fleet-wide through + [Group Policy or Intune](deployment.md), and check that nothing else + (other baselines, security tools) sets conflicting audit policy or log + retention. +- **Follow your change process.** The kit never reboots or restarts + services, but it does change audit policy and log settings. Schedule it + like any other configuration change, especially on domain controllers + and certificate authorities. +- **Verify, and keep the way back.** Run `Test-LoggingBaseline.ps1` after + every change. The first real run saves a rollback copy, and `-Rollback` + restores it. +- **Check your obligations.** Retention periods, privacy and sector rules + differ by organisation and country; the kit doesn't decide them for you. + +WinLogKit is provided as is, without warranty, under the +[MIT License](https://github.com/spydisec/WinLogKit/blob/main/LICENSE). + ## What the kit will never do Windows auditing has settings that can hang, halt or lock out a server. The