Title:Security Privileges Enumeration Via Whoami.EXE Status:test Description:Detects a whoami.exe executed with the /priv command line flag instructing the tool to show all current user privileges. This is often used after a privilege escalation attempt. References: -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/whoami Author: Florian Roth (Nextron Systems) Date: 2021-05-05 modified:2023-02-28 Tags: