Does anybody know the most effective way to disable or block someone from using any of the PSTools remotely on a machine on the AD network?
I have some folks at work messing around with pstools and I’m going to go ahead and lock it down. Would the answer be to create a hash rule or possibly a path rule in the LSP or at the GPO level? What if they rename one of the 12 PStools executables? I’d appreciate the input. Thanks.