These execution events are unique, which means that they are reported the first time that they are observed on the endpoint. If the same process executes on more than one endpoint, each endpoint will individually report the execution event. If a process executes more than once, only the first execution is reported unless any of the following exceptions occur:
The process is executed from a new file path that has not been seen before on the endpoint.
The hash of the process executable has not been seen before on the endpoint. For instance, the process has been updated to a new binary.