Tally write-up by Alamot

that’s probably because you need to be fast, make sure you have the flags from execute -Hc -f C:\\Temp\\rottenpotato.exe and execute impersonate_token “NT AUTHORITY\SYSTEM” immediately after