.. /Vshadow.exe
Star

VShadow is a command-line tool that can be used to create and manage volume shadow copies.


Paths:

Resources:
Acknowledgements:

Detection:

Execute

Executes calc.exe from vshadow.exe.
vshadow.exe -nw -exec=c:\windows\system32\calc.exe C:
Usecase: Performs execution of specified executable file.
Privileges required: Administrator
OS: Windows 10, Windows 11
MITRE ATT&CK®: T1127