I need help understanding the depth of what malcode can do, using the logged in user's creds.
I'm not asking about session hijacking, but rather just accessing all of the resources that the logged in user has access to.
Is it similar to sharing everything, like in an RDP session? Any links to learn from would be awesome!
Thank you!