diff --git a/atomics/T1082/T1082.yaml b/atomics/T1082/T1082.yaml index 1d83a641..e8ed5ab9 100644 --- a/atomics/T1082/T1082.yaml +++ b/atomics/T1082/T1082.yaml @@ -527,4 +527,14 @@ atomic_tests: command: sysctl -n hw.model name: sh elevation_required: false - +- name: 'operating system discovery ' + description: |- + operating system discovery using get-ciminstance + https://petri.com/getting-operating-system-information-powershell/ + supported_platforms: + - windows + executor: + command: Get-CimInstance Win32_OperatingSystem | Select-Object Caption, Version, ServicePackMajorVersion, OSArchitecture, CSName, WindowsDirectory | Out-null + name: powershell + elevation_required: false +