redcanaryco / atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.
MIT License
9.79k stars 2.8k forks source link

Update T1082.yaml #2956

Closed krdmnbrk closed 1 month ago

krdmnbrk commented 1 month ago

New atomic added.

Details: Listing shadow copies is a technique used by attackers. For example, the group G0114 (Chimera) used this technique during system discovery.

Testing: The atomic tested on local windows server.

Associated Issues: