This presentation discusses offensive uses for various elements of the Microsoft SysInternals tool suite. In Sally and David’s experience, these tools are often found or are accessible from inside a target organization network and can be valuable using unprivileged user access. In organizations where built-in features like PowerShell, the net commands, and WMIC are being instrumented or restricted these tools may provide a set of viable alternatives….signed, sealed, and delivered by Microsoft. This presentation also serves as a warning to system administrators to protect these tools properly.