4688201331200x80200000000000007670969Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x190cC:\Windows\System32\cmd.exe%%19360x1748cmd.exe /c cscript.exeNULL SID--0x0C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEMandatory Label\High Mandatory Level 4688201331200x80200000000000007669971Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x15a0C:\Windows\System32\cmd.exe%%19360x1748cmd.exe /c cscript.exe c:\atomicredteam\atomics\T1082\src\griffon_recon.vbsNULL SID--0x0C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEMandatory Label\High Mandatory Level 4688201331200x80200000000000007668299Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x1a90C:\Windows\System32\cmd.exe%%19360x1748cmd.exe /c cscript.exe c:\atomicredteam\atomics\T1082\src\griffon_recon.vbsNULL SID--0x0C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEMandatory Label\High Mandatory Level 4688201331200x80200000000000007666034Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x1a90C:\Windows\System32\cscript.exe%%19360x1748cscript.exe c:\atomicredteam\atomics\T1082\src\griffon_recon.vbsNULL SID--0x0C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEMandatory Label\High Mandatory Level 4688201331200x80200000000000007664019Securitywin-dc-mhaag-attack-range-622.attackrange.localATTACKRANGE\AdministratoradministratorATTACKRANGE0x1cfe160x20c0C:\Windows\System32\cscript.exe%%19360x1748cscript.exe c:\atomicredteam\atomics\T1082\src\griffon_recon.vbsNULL SID--0x0C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXEMandatory Label\High Mandatory Level