4688201331200x802000000000000031233071Securitywin-dc-mhaag-attack-range-602.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0xd08f940xaccC:\Windows\hh.exe%%19360x90c"C:\Windows\hh.exe" -decompile C:\AtomicRedTeam\atomics\T1218.001\src\T1218.001.chm C:\AtomicRedTeam\atomics\T1218.001\srcNULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002796646Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x6a0C:\Windows\hh.exe%%19360x1434hh.exe -decompile C:\AtomicRedTeam\atomics\T1218.001\src\T1218.001.chm C:\AtomicRedTeam\atomics\T1218.001\srcNULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002796644Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x1434C:\Windows\System32\cmd.exe%%19360x7c0"cmd.exe" /c "hh.exe -decompile C:\AtomicRedTeam\atomics\T1218.001\src\T1218.001.chm C:\AtomicRedTeam\atomics\T1218.001\src"NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002789794Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x1cd4C:\Windows\hh.exe%%19360x790hh.exe -decompile C:\AtomicRedTeam\atomics\T1218.001\src\T1218.001.chm C:\AtomicRedTeam\atomics\T1218.001\srcNULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000002789792Securitywin-host-mhaag-attack-range-117WIN-HOST-MHAAG-\AdministratorAdministratorWIN-HOST-MHAAG-0xe7a0c0x790C:\Windows\System32\cmd.exe%%19360x7c0"cmd.exe" /c "hh.exe -decompile C:\AtomicRedTeam\atomics\T1218.001\src\T1218.001.chm C:\AtomicRedTeam\atomics\T1218.001\src"NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMandatory Label\High Mandatory Level