Event JSON
{
"id": "9dd50bf8735d5c8bd91789ecabc43301cba16d1a2f213a30d7e8b9a4d920d579",
"pubkey": "3ba412ac4b14c4b37cd6ed16b9d262ad4ffefb05c5b6c6b3e15e381471b1221a",
"created_at": 1730157992,
"kind": 1,
"tags": [
[
"p",
"99019452930533c69a2f090e9425275667032cb27ea2ed62f6172bfc9132221d",
"wss://relay.mostr.pub"
],
[
"p",
"5d0910049da6eacaad9e891d5afb88fa613f4ab514d8a6c4fb51a03edeb60ede",
"wss://relay.mostr.pub"
],
[
"e",
"066b6b54e6c16d38bff2f41361b1f61e014bffb0ce46a82e45f18bb5c8448a7f",
"wss://relay.mostr.pub",
"reply"
],
[
"proxy",
"https://infosec.exchange/users/mttaggart/statuses/113387634167384115",
"activitypub"
]
],
"content": "nostr:npub1nyqeg55nq5eudx30py8fgff82ensxt9j063w6chkzu4leyfjygwsr3vvvs I'm unaware of many preventions here, but it's standard to have high scrutiny on 4698, especially tasks running as SYSTEM.\n\nhttps://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4698",
"sig": "23211aef88b7646c07ccd5778c3f7dcd91f2760327f1185429eb1200ccb7c87d91ef0904d635fe65c2185c1863110c0bb0785f25b1c728d2c1c890e6df069a35"
}