I'd be interested to know how effective these are against Windows when it is hardened against local admin abuse. I suspect that the overwhelming majority of these would be mitigated in a hardened enterprise environment, where correct UAC settings, removal / disable of local admin and application control over PS / CMD. As we all know though, hardened environments are the outlier and not the norm. Very interesting video though. #Blueteamer