Watson (missing patches)
Watson.exe
Enumerates installed security patches on the host and compares them with known exploits for local privilege escalation (CVE-2019-1388, CVE-2020-0668, etc.).
When you are on a Windows host as a standard user and want to know if there are applicable public exploits based on patch level. Watson queries the OS and installed KBs, and lists exploitable CVEs with their associated tool.
If the host is fully patched (Watson will find nothing) or if the EDR blocks unsigned .NET binaries. On critical server hosts, patch enumeration may correlate with exploitation attempts: assess the noise.