technique://Scheduled Task Abuse
- MarkupWindows Tier 2 Apr 27, 2026
XXE in an order form reads the Administrator's SSH private key from disk. job.bat runs as SYSTEM on a schedule — drop a reverse shell into the watched directory.
also uses: XXE File Read