4688201331200x80200000000000001615339Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x1d64C:\Windows\System32\conhost.exe%%19360x940\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1NULL SID--0x0C:\Windows\System32\odbcconf.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000001615338Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x940C:\Windows\System32\odbcconf.exe%%19360x1634odbcconf.exe -f T1218.008.rspNULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000001615336Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x1634C:\Windows\System32\cmd.exe%%19360xf08"cmd.exe" /c "cd C:\AtomicRedTeam\atomics\T1218.008\bin\ & odbcconf.exe -f T1218.008.rsp"NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000001615332Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160xf28C:\Windows\System32\odbcconf.exe%%19360x370odbcconf.exe /S /A {REGSVR "C:\AtomicRedTeam\atomics\T1218.008\src\Win32\T1218-2.dll"}NULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000001615330Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x370C:\Windows\System32\cmd.exe%%19360xf08"cmd.exe" /c "odbcconf.exe /S /A {REGSVR "C:\AtomicRedTeam\atomics\T1218.008\src\Win32\T1218-2.dll"}"NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000001509317Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x1eb0C:\Windows\System32\odbcconf.exe%%19360x1dfcodbcconf.exe /S /A {REGSVR "C:\AtomicRedTeam\atomics\T1218.008\src\Win32\T1218-2.dll"}NULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000001509315Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x1dfcC:\Windows\System32\cmd.exe%%19360xbe8"cmd.exe" /c "odbcconf.exe /S /A {REGSVR "C:\AtomicRedTeam\atomics\T1218.008\src\Win32\T1218-2.dll"}"NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000001509307Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x1d68C:\Windows\System32\odbcconf.exe%%19360x1e0codbcconf.exe /S /A {REGSVR "C:\AtomicRedTeam\atomics\T1218.008\src\Win32\T1218-2.dll"}NULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\High Mandatory Level 4688201331200x80200000000000001509305Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x1e0cC:\Windows\System32\cmd.exe%%19360xbe8"cmd.exe" /c "odbcconf.exe /S /A {REGSVR "C:\AtomicRedTeam\atomics\T1218.008\src\Win32\T1218-2.dll"}"NULL SID--0x0C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exeMandatory Label\High Mandatory Level