run_process
Execute a program on a remote agent host with options to suspend, capture output, or use token impersonation.
Instructions
Run a program on the agent host via 'ps run'. Args: args: Full path + arguments, e.g. 'C:\Windows\System32\cmd.exe /c whoami' suspend: Start process suspended (-s) with_output: Capture output (-o) impersonate: Use token impersonation (-i)
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| agent_id | Yes | ||
| args | Yes | ||
| suspend | No | ||
| with_output | No | ||
| impersonate | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |