mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2025-01-14 15:51:41 +01:00
Adding <version> placeholder to Vshadow
This commit is contained in:
parent
39a7120d40
commit
55d84345ac
@ -12,7 +12,7 @@ Commands:
|
|||||||
MitreID: T1127
|
MitreID: T1127
|
||||||
OperatingSystem: Windows 10, Windows 11
|
OperatingSystem: Windows 10, Windows 11
|
||||||
Full_Path:
|
Full_Path:
|
||||||
- Path: C:\Program Files (x86)\Windows Kits\10\bin\10.0.XXXXX.0\x64\vshadow.exe
|
- Path: C:\Program Files (x86)\Windows Kits\10\bin\<version>\x64\vshadow.exe
|
||||||
Detection:
|
Detection:
|
||||||
- IOC: vshadow.exe usage with -exec parameter
|
- IOC: vshadow.exe usage with -exec parameter
|
||||||
Resources:
|
Resources:
|
||||||
|
Loading…
Reference in New Issue
Block a user