Play all audios:
Thank you so much for the details, just I realized we restrict heavily what we log in event id 3 on the attack_range:
https://github.com/splunk/attack_range/blob/develop/ansible/roles/sysmon/templates/AttackRangeSysmon.xml.j2#L257 which is why I had not seen any yet :-). Looking forward to part 2!