@loke powershell scripts that call scripts from external IPs in the cloud to run legitimate patches, often passing credentials in clear text (Which is the giveaway that it's #lazyadmin )
so many other things... just look malicious at a glance, and then have a team start an investigation and waste several hours of time.
Hey Windows sysadmins... can we chat for a second?
Could you please stop doing stuff that looks like malicious behavior when you update your systems?
K, Thx.
Signed,
A former Windows Sysadmin who is really tired of having to explain the difference between #LazyAdmin and #APTs
Oh hey you can make notes on users on your instance now, neat. Wonder when that got added. #lazyadmin
(this is my husband's account, I call him things like this all the time :hairy_heart:)