LoFP LoFP / t1007

t1007

TitleTags
administrators or power users may use this command for troubleshooting.
discord
legitimate administration activities
legitimate powershell scripts that make use of these functions.
legitimate security assessments or administrative audits may run winpeas for privilege escalation checks. exclude trusted security tools to reduce false alerts.
legitimate use of crontab
unlikely