.. /Vshadow.exe
Star

Execute

VShadow is a command-line tool that can be used to create and manage volume shadow copies.


Paths:

Resources:
Acknowledgements:

Detection:

Execute

  1. Executes calc.exe from vshadow.exe.

    vshadow.exe -nw -exec=c:\windows\system32\calc.exe C:
    Use case
    Performs execution of specified executable file.
    Privileges required
    Administrator
    Operating systems
    Windows 10, Windows 11
    ATT&CK® technique
    T1127