You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Add COM diagnostics and retain unrecognized Learning Mode events - #1386
Adds diagnostic labels for COM activation and interface calls. Retains unfamiliar providers and event IDs in verbose logs, extracting their properties where possible and recording a diagnostic reason when parsing fails.
Tests
Ran 219 decoder tests and Clippy locally; all passed. Validated native block/allow capture, COM events, deduplication, timeout, ETL retention and telemetry consent. Processing the same real traces before and after produced identical actionable JSON.
Expands Learning Mode diagnostics with COM-specific outcomes and retention of unfamiliar events, while keeping actionable denial extraction limited to known schemas.
Changes:
Adds version-3 verbose diagnostics and nonfatal schema-failure reporting.
Broadens process-scoped ETL retention and deduplicates sanitized telemetry.
Adds decoder, relogging, and telemetry regression coverage.
The reason will be displayed to describe this comment to others. Learn more.
Copilot review overview
🔵 Needs a closer look
Privileged trace-scoping changes need human validation, and supported-event schema failures can produce apparently complete but incomplete learned policies.
When a supported brokered Event 28 has no resolvable schema, its payload ProcessId cannot be recovered. If the broker's header PID is outside the sandbox lifetimes, this fallback silently drops the event. Subsequent analysis cannot detect the loss and can report deniedResourcesTruncated=false, allowing an incomplete adjusted policy. Keep schema failures fatal during brokered-event scoping, without retaining unscoped host events. Update relog_selection_skips_unattributable_capability_schema_failure to expect the failure.
TraceLogging events commonly share event ID 0 and are distinguished by schema-declared names. decode_event_parts reads that name but retains it only on failure. Two successfully decoded, differently named events from the same provider and PID with identical properties therefore collapse into one signature here, losing their identities and combining their counts. Carry the schema name into successful diagnostic signatures as sanitized metadata, keeping it distinct from payload fields, and test two differently named events with identical payloads. Telemetry can continue stripping this metadata.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds diagnostic labels for COM activation and interface calls. Retains unfamiliar providers and event IDs in verbose logs, extracting their properties where possible and recording a diagnostic reason when parsing fails.
Tests
Ran 219 decoder tests and Clippy locally; all passed. Validated native block/allow capture, COM events, deduplication, timeout, ETL retention and telemetry consent. Processing the same real traces before and after produced identical actionable JSON.
Microsoft Reviewers: Open in CodeFlow