Security researchers have developed an implementation of the Sysinternals PsExec utility that allows moving laterally in a network using a single, less monitored port, Windows TCP port 135. PsExec is ...
You could create a scheduled task, set it up to run under the system account, and allow the user to spawn it off (I think).
Some results have been hidden because they may be inaccessible to you
Show inaccessible results