>_ shadow.red

AppLocker Recon and Common Bypass Path

Privilege Escalation Windows Misc windows

Verify the service

powershell -C Get-Service AppIDSvc

Often-allowed write path

C:\Windows\System32\spool\drivers\color