diff --git a/atomics/Indexes/index.yaml b/atomics/Indexes/index.yaml index e68cb4a9..1a2f1860 100644 --- a/atomics/Indexes/index.yaml +++ b/atomics/Indexes/index.yaml @@ -4175,11 +4175,9 @@ defense-evasion: executor: name: sh elevation_required: true - command: 'if (systemd-detect-virt || sudo dmidecode | egrep -i ''manufacturer|product|vendor'' - | grep -iE ''Oracle|VirtualBox|VMWare|Parallels'') then echo "Virtualization - Environment detected"; fi; - - ' + command: | + if (systemd-detect-virt) then echo "Virtualization Environment detected"; fi; + if (sudo dmidecode | egrep -i 'manufacturer|product|vendor' | grep -iE 'Oracle|VirtualBox|VMWare|Parallels') then echo "Virtualization Environment detected"; fi; - name: Detect Virtualization Environment (Windows) auto_generated_guid: 502a7dc4-9d6f-4d28-abf2-f0e84692562d description: 'Windows Management Instrumentation(WMI) objects contains system @@ -84279,11 +84277,9 @@ discovery: executor: name: sh elevation_required: true - command: 'if (systemd-detect-virt || sudo dmidecode | egrep -i ''manufacturer|product|vendor'' - | grep -iE ''Oracle|VirtualBox|VMWare|Parallels'') then echo "Virtualization - Environment detected"; fi; - - ' + command: | + if (systemd-detect-virt) then echo "Virtualization Environment detected"; fi; + if (sudo dmidecode | egrep -i 'manufacturer|product|vendor' | grep -iE 'Oracle|VirtualBox|VMWare|Parallels') then echo "Virtualization Environment detected"; fi; - name: Detect Virtualization Environment (Windows) auto_generated_guid: 502a7dc4-9d6f-4d28-abf2-f0e84692562d description: 'Windows Management Instrumentation(WMI) objects contains system diff --git a/atomics/T1497.001/T1497.001.md b/atomics/T1497.001/T1497.001.md index c2a1fb4c..3e170d74 100644 --- a/atomics/T1497.001/T1497.001.md +++ b/atomics/T1497.001/T1497.001.md @@ -41,7 +41,8 @@ At boot, dmesg stores a log if a hypervisor is detected. ```sh -if (systemd-detect-virt || sudo dmidecode | egrep -i 'manufacturer|product|vendor' | grep -iE 'Oracle|VirtualBox|VMWare|Parallels') then echo "Virtualization Environment detected"; fi; +if (systemd-detect-virt) then echo "Virtualization Environment detected"; fi; +if (sudo dmidecode | egrep -i 'manufacturer|product|vendor' | grep -iE 'Oracle|VirtualBox|VMWare|Parallels') then echo "Virtualization Environment detected"; fi; ```