@dwmetz Yes, I've checked these before and there is currently no such event; haven't been able to see it. The #Sysmon one does exist, but I want to see what else is there, because what if we don't have Sysmon on the endpoint! Thanks Doug!
@salm Unfortunately, I was unable to see those with all my testing, except the Sysmon one which I'm trying to avoid. The EID #25 is not found either on Windows 10 (system I'm testing on). Thanks Fluffy!