thx.
on the bat file:
they looked at the bat file line by line (dominion custom addon) that de-hardens sql server. assumes sql server shutdown. apparently two key lines: 1 copying security credentials in mass to folder. 2 disable encryption on in sql server. 3. restart sql server.
of course anyone with exec permission can run it, even remotely.
Two things.
Spoliation of evidence by Dominion..
Dominion should be forced to pay for audits in every state as they violated the public trust.