11241100x8000000000000000166381638Microsoft-Windows-Sysmon/Operationalmswin-server.attackrange.local-2023-05-11 16:34:34.843{EF490992-8FFB-645A-7087-00000000CE02}7068C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\Com\comadmin.dat2023-05-09 21:00:27.163MSWIN-SERVER\Administrator
23542300x8000000000000000166381637Microsoft-Windows-Sysmon/Operationalmswin-server.attackrange.local-2023-05-11 16:34:34.843{EF490992-8FFB-645A-7087-00000000CE02}7068MSWIN-SERVER\AdministratorC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\Com\comadmin.datMD5=5E7F811F59F86B9988B8DED2EC5F299F,SHA256=474420651A35920497A1CA8F39311A52359E4CC6C62097C89281F0989CD10381falsetrue