If an attacker wanted to dump hashes or run wmic commands on a target machine, which of the following tools would he use?