A Windows post-exploitation toolkit linked to a ransomware investigation used reverse shells, credential theft utilities, ...