nyan on Nostr: Ok, I need someone to explain file access auditing in Windows to me... I enable the ...
Ok, I need someone to explain file access auditing in Windows to me...
I enable the Audit File System policy, then I create an Audit "permission" entry for files/folders I want to monitor (I guess those are the SACLs? Would help if frontend & docs used in any way related language). Do those grant permissions (the frontend kinda implies that?) or are they just a mask for events? I guess the second?
So if I Everyone/The Entire List Of Permissions the Audit "permission" then I get all accesses?
Published at
2026-08-05 19:12:54 UTCEvent JSON
{
"id": "b6fef234d1fff0efc33a7fdac0d93f7a688bde1acccb24c9eeaad919861c16e1",
"pubkey": "5941667d19e40b7581976ddf20bfae28022f6837f5467c96f0e377da7ba264a2",
"created_at": 1785957174,
"kind": 1,
"tags": [
[
"proxy",
"https://infosec.exchange/@nyanbinary/117044489374221774",
"web"
],
[
"proxy",
"https://infosec.exchange/users/nyanbinary/statuses/117044489374221774",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://infosec.exchange/users/nyanbinary/statuses/117044489374221774",
"pink.momostr"
],
[
"-"
]
],
"content": "Ok, I need someone to explain file access auditing in Windows to me...\n\nI enable the Audit File System policy, then I create an Audit \"permission\" entry for files/folders I want to monitor (I guess those are the SACLs? Would help if frontend \u0026 docs used in any way related language). Do those grant permissions (the frontend kinda implies that?) or are they just a mask for events? I guess the second?\nSo if I Everyone/The Entire List Of Permissions the Audit \"permission\" then I get all accesses?",
"sig": "ab1f6535c0c58856302ae2650b41daf3454c0e8d1f207b91992e57ddd96e895930524d065349e070343943110547a741d115b43606632e951a4d759d1f6fbfe6"
}