{"id":7564,"date":"2026-09-03T14:26:11","date_gmt":"2026-09-03T19:26:11","guid":{"rendered":"https:\/\/andreas-wolter.com\/?p=7564"},"modified":"2026-09-03T15:14:41","modified_gmt":"2026-09-03T20:14:41","slug":"2609_rapid7_microsoftdefenderforendpoint_attribution","status":"publish","type":"post","link":"https:\/\/andreas-wolter.com\/en\/2609_rapid7_microsoftdefenderforendpoint_attribution\/","title":{"rendered":"When SIEM Enrichment Becomes False Attribution"},"content":{"rendered":"\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-m0cxh8ps-bc764d6b92139090a238b0bfb62fd60d\">\n#top .av-special-heading.av-m0cxh8ps-bc764d6b92139090a238b0bfb62fd60d{\npadding-bottom:10px;\n}\nbody .av-special-heading.av-m0cxh8ps-bc764d6b92139090a238b0bfb62fd60d .av-special-heading-tag .heading-char{\nfont-size:25px;\n}\n.av-special-heading.av-m0cxh8ps-bc764d6b92139090a238b0bfb62fd60d .av-subheading{\nfont-size:15px;\n}\n<\/style>\n<div  class='av-special-heading av-m0cxh8ps-bc764d6b92139090a238b0bfb62fd60d av-special-heading-h3 blockquote modern-quote  avia-builder-el-0  el_before_av_textblock  avia-builder-el-first '><h3 class='av-special-heading-tag'  itemprop=\"headline\"  >When SIEM Enrichment Becomes False Attribution<\/h3><div class=\"special-heading-border\"><div class=\"special-heading-inner-border\"><\/div><\/div><\/div>\r\n\r\n<section  class='av_textblock_section av-m0cxgkjy-c935304b4106b45214698f40e83a9894 '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/BlogPosting\" itemprop=\"blogPost\" ><div class='avia_textblock'  itemprop=\"text\" ><p>This week, early morning, a customer alerted me that my account was possibly involved in an incident.<\/p>\n<p>The alert came from Rapid7 InsightIDR:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-7567\" src=\"https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-email-user-attribution.png-1030x317.png\" alt=\"\" width=\"1030\" height=\"317\" srcset=\"https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-email-user-attribution.png-1030x317.png 1030w, https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-email-user-attribution.png-300x92.png 300w, https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-email-user-attribution.png-768x236.png 768w, https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-email-user-attribution.png-705x217.png 705w, https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-email-user-attribution.png.png 1277w\" sizes=\"auto, (max-width: 1030px) 100vw, 1030px\" \/><\/p>\n<p>And looking at the alert, yes, there is my name.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7565\" src=\"https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-user-attribution.png\" alt=\"\" width=\"948\" height=\"345\" srcset=\"https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-user-attribution.png 948w, https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-user-attribution-300x109.png 300w, https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-user-attribution-768x279.png 768w, https:\/\/andreas-wolter.com\/wp-content\/uploads\/2026\/09\/2026-09-rapid7-insightidr-malware-alert-user-attribution-705x257.png 705w\" sizes=\"auto, (max-width: 948px) 100vw, 948px\" \/><\/p>\n<p><strong>Way to start the day.<\/strong><\/p>\n<p>However, <strong>I know for sure I do not work before getting up<\/strong>, and immediately was suspicious.<br \/>\nSo I got hold of the details of the alert. Here are the relevant snippets:<\/p>\n<p style=\"padding-left: 40px;\">{<br \/>\n&#8220;timestamp&#8221;:\u00a0&#8220;2026-09-XXXXXXXX&#8221;,<br \/>\n&#8220;product&#8221;:\u00a0&#8220;Microsoft Defender For Endpoint&#8221;,<br \/>\n&#8220;type&#8221;:\u00a0&#8220;Malware&#8221;,<br \/>\n&#8220;severity&#8221;:\u00a0&#8220;High&#8221;,<br \/>\n&#8220;title&#8221;:\u00a0&#8220;&#8216;Splinter&#8217; high-severity malware was prevented&#8221;,<br \/>\n&#8220;description&#8221;:\u00a0&#8220;High-severity malware refers tools used by advanced Threat Activity Groups to target victims. \u2026long text.. \\n- _Weaponized_ tools that enable acts of deliberate sabotage or destruction or denial of service.&#8221;,<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0&#8220;alert_id&#8221;:\u00a0&#8220;XXXXXXXXX-49db-8fc8-39d852d9f596_1&#8221;,<br \/>\n<strong>\u00a0\u00a0&#8220;user&#8221;:\u00a0&#8220;Andreas Wolter&#8221;,<\/strong><br \/>\n&#8220;asset&#8221;:\u00a0&#8220;ServerName&#8221;,<br \/>\n&#8220;source_json&#8221;:\u00a0{<\/p>\n<p style=\"padding-left: 40px;\"><strong>This source_json-boundary turned out to be the most important part of the alert.<\/strong><\/p>\n<p style=\"padding-left: 40px;\">&#8220;actorDisplayName&#8221;:\u00a0null,<br \/>\n&#8220;additionalData&#8221;:\u00a0{<br \/>\n},<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0&#8220;alertPolicyId&#8221;:\u00a0null,<br \/>\n&#8220;alertWebUrl&#8221;:\u00a0&#8220;https:\/\/security.microsoft.com\/alerts\/xxxxxxxxxxxxxxx?tid=a97c78aa-xxxxxxxxxxx&#8221;,<br \/>\n&#8220;assignedTo&#8221;:\u00a0null,<br \/>\n&#8220;categories&#8221;:\u00a0[<br \/>\n&#8220;Malware&#8221;<br \/>\n],<br \/>\n\u2026<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0&#8220;detectionSource&#8221;:\u00a0&#8220;antivirus&#8221;,<br \/>\n&#8220;detectorId&#8221;:\u00a0&#8220;xxxxxxxxxxxxxxxxx&#8221;,<br \/>\n&#8220;determination&#8221;:\u00a0null,<\/p>\n<p style=\"padding-left: 40px;\"><strong>\u00a0\u00a0\u00a0\u00a0&#8220;evidence&#8221;:\u00a0[<\/strong><\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0{<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0&#8220;@odata.type&#8221;:\u00a0&#8220;#microsoft.graph.security.deviceEvidence&#8221;,<br \/>\n&#8220;azureAdDeviceId&#8221;:\u00a0null,<br \/>\n&#8220;createdDateTime&#8221;:\u00a0&#8220;2026-09-xxxxxxxxxxxxx&#8221;,<br \/>\n&#8220;defenderAvStatus&#8221;:\u00a0&#8220;unknown&#8221;,<br \/>\n\u2026<br \/>\n&#8220;deviceDnsName&#8221;:\u00a0&#8220;ServerName&#8221;,<br \/>\n&#8220;dnsDomain&#8221;:\u00a0&#8220;Domain&#8221;,<br \/>\n&#8220;firstSeenDateTime&#8221;:\u00a0&#8220;2025-xxxxxxxxxxxxx&#8221;,<br \/>\n&#8220;healthStatus&#8221;:\u00a0&#8220;active&#8221;,<br \/>\n&#8220;hostName&#8221;:\u00a0&#8220;Servername&#8221;,<br \/>\n&#8220;ipInterfaces&#8221;:\u00a0[<br \/>\n],<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0&#8220;lastExternalIpAddress&#8221;:\u00a0&#8220;x.x.x.x&#8221;,<br \/>\n&#8220;lastIpAddress&#8221;:\u00a0&#8221; x.x.x.x &#8220;,<\/p>\n<p style=\"padding-left: 40px;\"><strong>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0&#8220;loggedOnUsers&#8221;:\u00a0[\u00a0],\u00a0<\/strong><\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0&#8220;ntDomain&#8221;:\u00a0null,<br \/>\n\u2026<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0&#8220;remediationStatus&#8221;:\u00a0&#8220;active&#8221;,<br \/>\n\u2026<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0],<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0&#8220;verdict&#8221;:\u00a0&#8220;suspicious&#8221;,<\/p>\n<p style=\"padding-left: 40px;\">\u2026<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0{<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0&#8220;@odata.type&#8221;:\u00a0&#8220;#microsoft.graph.security.fileEvidence&#8221;,<br \/>\n&#8220;createdDateTime&#8221;:\u00a0&#8220;2026-09-xxxxxxxxxx&#8221;,<br \/>\n&#8220;detailedRoles&#8221;:\u00a0[<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0],<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0&#8220;detectionStatus&#8221;:\u00a0&#8220;prevented&#8221;,<br \/>\n&#8220;fileDetails&#8221;:\u00a0{<br \/>\n&#8220;fileName&#8221;:\u00a0&#8220;printsvc_vbh.dll&#8221;,<br \/>\n&#8220;filePath&#8221;:\u00a0&#8220;C:\\Windows\\system32\\spool\\drivers\\x64\\3&#8221;,<br \/>\n&#8220;filePublisher&#8221;:\u00a0null,<\/p>\n<p style=\"padding-left: 40px;\">\u2026<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0},<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0&#8220;mdeDeviceId&#8221;:\u00a0&#8220;xxxxxxxxxxxxxxxxxxxx&#8221;,<br \/>\n&#8220;remediationStatus&#8221;:\u00a0&#8220;prevented&#8221;,<br \/>\n&#8220;remediationStatusDetails&#8221;:\u00a0&#8220;Entity was pre-remediated by Windows Defender&#8221;,<\/p>\n<p style=\"padding-left: 40px;\">\u2026<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0],<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0&#8220;firstActivityDateTime&#8221;:\u00a0&#8220;2026-09-xxxxxxxxxxxxx&#8221;,<br \/>\n\u2026<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0&#8220;productName&#8221;:\u00a0&#8220;Microsoft Defender for Endpoint&#8221;,<br \/>\n&#8220;providerAlertId&#8221;:\u00a0&#8220;xxxxxxxxxxxxxxxxxxx_1&#8221;,<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0&#8220;recommendedActions&#8221;:\u00a0&#8220;A. \u00a0long text \u2026.&#8221;,<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0&#8220;serviceSource&#8221;:\u00a0&#8220;microsoftDefenderForEndpoint&#8221;,<br \/>\n&#8220;severity&#8221;:\u00a0&#8220;high&#8221;,<br \/>\n&#8220;status&#8221;:\u00a0&#8220;new&#8221;,<br \/>\n&#8220;systemTags&#8221;:\u00a0[<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0],<\/p>\n<p style=\"padding-left: 40px;\">\u00a0\u00a0\u00a0\u00a0&#8220;threatDisplayName&#8221;:\u00a0&#8220;Trojan:Win64\/Splinter.MS!dha&#8221;,<br \/>\n&#8220;threatFamilyName&#8221;:\u00a0&#8220;Splinter&#8221;,<br \/>\n&#8220;title&#8221;:\u00a0&#8220;&#8216;Splinter&#8217; high-severity malware was prevented&#8221;<\/p>\n<p style=\"padding-left: 40px;\">\u2026<\/p>\n<p style=\"padding-left: 40px;\">}<\/p>\n<p>The important distinction is between <strong>who was logged on<\/strong>, <strong>what process caused the file to be examined<\/strong>, and the &#8220;user&#8221; field added to the alert.<\/p>\n<p><strong>What the alert actually says<\/strong><\/p>\n<p>The original, raw data from Microsoft Defender For Endpoint contains:<\/p>\n<p>&#8220;deviceDnsName&#8221;: &#8220;Servername&#8221;,<\/p>\n<p>&#8220;loggedOnUsers&#8221;: []<\/p>\n<p>Microsoft defines loggedOnUsers as the users logged onto the machine at the time of the alert. Here it is empty.<\/p>\n<p>The &#8220;user&#8221;: &#8220;My Name&#8221; &#8211; field is <strong>outside source_json<\/strong>.<\/p>\n<p>There is no user evidence associating my account with the detection in the original MDE data. The user field exists only in the outer Rapid7 record.<\/p>\n<p>And this is the key point: <strong>the presence of a name in the SIEM alert is not evidence that that account created, loaded, or executed the DLL.<\/strong><\/p>\n<p>The user field was added by <strong>Rapid7 InsightIDR<\/strong> during normalization\/enrichment; it is not present in the original Microsoft Defender alert data.<\/p>\n<p>The outer JSON is Rapid7&#8217;s normalized <strong>third_party_alert<\/strong> format. Rapid7 documents these fields:\u00a0 https:\/\/docs.rapid7.com\/insightidr\/keys-to-use-in-your-queries\/<\/p>\n<p>The actual Microsoft alert is what sits inside the &#8220;source_json&#8221;: { &#8230; }<\/p>\n<p><strong>This is the actual detection<\/strong><\/p>\n<p>Trojan:Win64\/Splinter.MS!dha<\/p>\n<p>C:\\Windows\\system32\\spool\\drivers\\x64\\3\\printsvc_vbh.dll<\/p>\n<p>And Defender says:<\/p>\n<p>detectionStatus: prevented<\/p>\n<p>remediationStatus: prevented<\/p>\n<p>&#8220;Entity was pre-remediated by Windows Defender&#8221;<\/p>\n<p>verdict: malicious<\/p>\n<p>That&#8217;s good: Defender says it prevented\/remediated the file.<\/p>\n<h2>What do we take away from this?<\/h2>\n<p>Always distinguish between <strong>source evidence<\/strong> and <strong>SIEM enrichment<\/strong>.<\/p>\n<p>In this case, the alert presented my account as being involved in the activity. But the underlying Microsoft Defender evidence contained no logged-on user, and the user field was not part of the original Defender data.<\/p>\n<p>Enrichment can be useful, but it should not be mistaken for forensic evidence. Before attributing an incident to a user, check where that attribution actually came from.<\/p>\n<p>I would be interested to hear from Rapid7 how this user attribution is derived and whether the UI could make the distinction between <strong>source evidence<\/strong> and <strong>enriched attribution<\/strong> more explicit.<\/p>\n<p>Happy monitoring<\/p>\n<p>\/Andreas<\/p>\n<\/div><\/section>\r\n\r\n<div  class='flex_column av-vb4k9-5c390a090b8757fafe36b077b8d164ce av_one_full  avia-builder-el-2  el_after_av_textblock  el_before_av_social_share  first flex_column_div  column-top-margin'     ><div  class='hr av-7coejt-c2ec2e6fb5dfa2080806798514392349 hr-default  avia-builder-el-3  el_before_av_textblock  avia-builder-el-first '><span class='hr-inner '><span class=\"hr-inner-style\"><\/span><\/span><\/div>\n<section  class='av_textblock_section av-6e2h5l-f15ae97e4272ea5736cfded1578c506a '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/BlogPosting\" itemprop=\"blogPost\" ><div class='avia_textblock'  itemprop=\"text\" ><p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"869\" data-end=\"1089\"><strong data-start=\"869\" data-end=\"934\">A security finding is only as good as the evidence behind it.<\/strong><br data-start=\"934\" data-end=\"937\" \/>This is why I do not treat scanner or SIEM output as the conclusion. I verify the underlying evidence and determine what the finding actually means.<\/p>\n<p data-start=\"1097\" data-end=\"1286\">I apply the same approach in my SQL Server Security Assessments &#8211; looking beyond generic checks to identify real privilege escalation paths, configuration weaknesses, and security exposure.<\/p>\n<\/div><\/section>\n<div  class='avia-button-wrap av-4g244p-1b06fca702069cb5fd2a42aa9fc7e5c0-wrap avia-button-center  avia-builder-el-5  el_after_av_textblock  el_before_av_hr '>\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-4g244p-1b06fca702069cb5fd2a42aa9fc7e5c0\">\n#top #wrap_all .avia-button.av-4g244p-1b06fca702069cb5fd2a42aa9fc7e5c0{\nfont-size:14px;\nbackground-color:#75a823;\nborder-color:#75a823;\ncolor:#ffffff;\nbox-shadow: 0 0 5px 5px ;\ntransition:all 0.4s ease-in-out;\n}\n<\/style>\n<a href=\"https:\/\/sarpedonqualitylab.us\/sql-server-security-assessment\/\" class=\"avia-button av-4g244p-1b06fca702069cb5fd2a42aa9fc7e5c0 avia-icon_select-yes-left-icon avia-size-medium avia-position-center\" target=\"_blank\" rel=\"noopener\"><span class='avia_button_icon avia_button_icon_left' aria-hidden='true' data-av_icon='\ue832' data-av_iconfont='entypo-fontello'><\/span><span class='avia_iconbox_title' >Learn more about SQL Server Security Assessments from Sarpedon Quality Lab LLC.<\/span><\/a><\/div>\n<div  class='hr av-2df7qh-97a70af29223f51de4e8a5134ac96e31 hr-default  avia-builder-el-6  el_after_av_button  avia-builder-el-last '><span class='hr-inner '><span class=\"hr-inner-style\"><\/span><\/span><\/div><\/div>\r\n\r\n<div  class='av-social-sharing-box av-5n5vpa-78ffdd9d224b4a246af65bdc00dce900 av-social-sharing-box-default  avia-builder-el-7  el_after_av_one_full  el_before_av_hr  av-social-sharing-box-fullwidth'><div class=\"av-share-box\"><h5 class='av-share-link-description av-no-toc '>Share article<\/h5><ul class=\"av-share-box-list noLightbox\"><li class='av-share-link av-social-link-facebook' ><a target=\"_blank\" aria-label=\"Share on Facebook\" href=\"https:\/\/www.facebook.com\/sharer.php?u=https:\/\/andreas-wolter.com\/en\/2609_rapid7_microsoftdefenderforendpoint_attribution\/&amp;t=When%20SIEM%20Enrichment%20Becomes%20False%20Attribution\" aria-hidden=\"false\" data-av_icon=\"\ue8f3\" data-av_iconfont=\"entypo-fontello\" title=\"\" data-avia-related-tooltip=\"Share on Facebook\" rel=\"noopener\"><span class='avia_hidden_link_text'>Share on Facebook<\/span><\/a><\/li><li class='av-share-link av-social-link-twitter' ><a target=\"_blank\" aria-label=\"Share on Twitter\" href=\"https:\/\/twitter.com\/share?text=When%20SIEM%20Enrichment%20Becomes%20False%20Attribution&amp;url=https:\/\/andreas-wolter.com\/en\/?p=7564\" aria-hidden=\"false\" data-av_icon=\"\ue8f1\" data-av_iconfont=\"entypo-fontello\" title=\"\" data-avia-related-tooltip=\"Share on Twitter\" rel=\"noopener\"><span class='avia_hidden_link_text'>Share on Twitter<\/span><\/a><\/li><li class='av-share-link av-social-link-linkedin' ><a target=\"_blank\" aria-label=\"Share on LinkedIn\" href=\"https:\/\/linkedin.com\/shareArticle?mini=true&amp;title=When%20SIEM%20Enrichment%20Becomes%20False%20Attribution&amp;url=https:\/\/andreas-wolter.com\/en\/2609_rapid7_microsoftdefenderforendpoint_attribution\/\" aria-hidden=\"false\" data-av_icon=\"\ue8fc\" data-av_iconfont=\"entypo-fontello\" title=\"\" data-avia-related-tooltip=\"Share on LinkedIn\" rel=\"noopener\"><span class='avia_hidden_link_text'>Share on LinkedIn<\/span><\/a><\/li><\/ul><\/div><\/div>\r\n\r\n\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-4ofg9q-c2108540b480aba02923089240a3a176\">\n#top .hr.hr-invisible.av-4ofg9q-c2108540b480aba02923089240a3a176{\nheight:50px;\n}\n<\/style>\n<div  class='hr av-4ofg9q-c2108540b480aba02923089240a3a176 hr-invisible  avia-builder-el-8  el_after_av_social_share  el_before_av_comments_list '><span class='hr-inner '><span class=\"hr-inner-style\"><\/span><\/span><\/div>\r\n\r\n<div  class='av-buildercomment av-284ftq-f5a1564cd6b8ffad6ce835e2d40de4b7  av-blog-meta-author-disabled av-blog-meta-html-info-disabled'><\/div>","protected":false},"excerpt":{"rendered":"","protected":false},"author":4,"featured_media":7565,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[57],"tags":[380,27,387],"class_list":["post-7564","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-en","tag-auditing","tag-security-en","tag-siem"],"_links":{"self":[{"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/posts\/7564","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/comments?post=7564"}],"version-history":[{"count":6,"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/posts\/7564\/revisions"}],"predecessor-version":[{"id":7572,"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/posts\/7564\/revisions\/7572"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/media\/7565"}],"wp:attachment":[{"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/media?parent=7564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/categories?post=7564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/andreas-wolter.com\/en\/wp-json\/wp\/v2\/tags?post=7564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}