1:
10.1.1.42
2:
32
3:
psexec
https://www.sans.org/blog/protecting-privileged-domain-accounts-psexec-deep-dive/
Abnormal services created:
%systemroot%\wgWMRHln.exe
%systemroot%\MrEQbpfX.exe
psexec
4:
net user, net localgroup, net share
5:
Susan123!
1:
10.1.1.42
2:
32
3:
psexec
https://www.sans.org/blog/protecting-privileged-domain-accounts-psexec-deep-dive/
Abnormal services created:
%systemroot%\wgWMRHln.exe
%systemroot%\MrEQbpfX.exe
psexec
4:
net user, net localgroup, net share
5:
Susan123!