diff --git a/atomics/T1497.001/T1497.001.yaml b/atomics/T1497.001/T1497.001.yaml index c04fe72e..3407c2c1 100644 --- a/atomics/T1497.001/T1497.001.yaml +++ b/atomics/T1497.001/T1497.001.yaml @@ -41,6 +41,7 @@ atomic_tests: command: | if (ioreg -l | grep -e Manufacturer -e 'Vendor Name' | grep -iE 'Oracle|VirtualBox|VMWare|Parallels') then echo 'Virtualization Environment detected'; fi; - name: Detect Virtualization Environment via WMI Manufacturer/Model Listing (Windows) + auto_generated_guid: 4a41089a-48e0-47aa-82cb-5b81a463bc78 description: | Windows Management Instrumentation(WMI) objects contain system information which helps to detect virtualization. This test will get the model and manufacturer of the machine to determine if it is a virtual machine, such as through VMware or VirtualBox. supported_platforms: diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index af9f58b2..3742f37c 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -834,3 +834,4 @@ d07e4cc1-98ae-447e-9d31-36cb430d28c4 99c657aa-ebeb-4179-a665-69288fdd12b8 4299eff5-90f1-4446-b2f3-7f4f5cfd5d62 28498c17-57e4-495a-b0be-cc1e36de408b +4a41089a-48e0-47aa-82cb-5b81a463bc78