@james_inthe_box side note: I've never seen a threat actor purposely add themselves to the event log before... 😂