疑似Oday
Ensure the "Force shutdown from a remote system" policy (SeRemoteShutdownPrivilege) is assigned only to the Administrators group (SID: S-1-5-32-544). Granting this privilege to unauthorized accounts can allow attackers to remotely shut down the system, posing a significant risk.
id: remote-system-shutdown
info:
name: Remote System Forced Shutdown Privilege Check
author: nu
...