Copy From VolumeShadowCopy Via Cmd.EXE

 Original Source: [Sigma source]
Title: Copy From VolumeShadowCopy Via Cmd.EXE
Status: test
Description:Detects the execution of the builtin "copy" command that targets a shadow copy (sometimes used to copy registry hives that are in use)
References:
  -https://twitter.com/vxunderground/status/1423336151860002816?s=20
  -https://www.virustotal.com/gui/file/03e9b8c2e86d6db450e5eceec057d7e369ee2389b9daecaf06331a95410aa5f8/detection
  -https://pentestlab.blog/2018/07/04/dumping-domain-password-hashes/
Author: Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems)
Date: 2021-08-09
modified:2023-03-07
Tags:
  • -'attack.impact'
  • -'attack.t1490'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'copy '
      -'\\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy'

  condition:selection
Falsepositives:
  -Backup scenarios using the commandline
Level: high