Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load

 Original Source: [Sigma source]
Title: Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load
Status: test
Description:Detects the image load of VSS DLL by uncommon executables
References:
  -https://github.com/ORCx41/DeleteShadowCopies
Author: frack113
Date: 2023-02-17
modified:2026-08-27
Tags:
  • -'attack.impact'
  • -'attack.t1490'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    ImageLoaded|endswith: '\vsstrace.dll'
  filter_main_windows:
    - Image:
      - 'C:\Windows\explorer.exe'
      - 'C:\Windows\ImmersiveControlPanel\SystemSettings.exe'
      - 'C:\Windows\servicing\TrustedInstaller.exe'
    - Image|startswith:
      - 'C:\Windows\System32\'
      - 'C:\Windows\SysWOW64\'
      - 'C:\Windows\Temp\{'
      - 'C:\Windows\WinSxS\'
      - 'C:\ProgramData\Package Cache\{'
  filter_main_program_files:
    Image|startswith:
      -'C:\Program Files\'
      -'C:\Program Files (x86)\'

  filter_optional_recovery:
    Image|startswith: 'C:\$WinREAgent\Scratch\'
  filter_main_null_image:
    Image: 'None'
  filter_optional_avira:
    Image|contains|all:
      -'\temp\is-'
      -'\avira_system_speedup.tmp'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium