When Windows Defender realizes that a malicious file has a cloud tag it rewrites the file to it's original location. The PoC abuses this behaviour to overwrite system files and gain administrative privileges.https://github.com/Nightmare-Eclipse/RedSun#infosec #cybersecurity #pentest #windows