Shadow Copies Creation Using Operating Systems Utilities

 Original Source: [Sigma source]
Title: Shadow Copies Creation Using Operating Systems Utilities
Status: test
Description:Shadow Copies creation using operating systems utilities, possible credential access
References:
  -https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
  -https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/tutorial-for-ntds-goodness-vssadmin-wmis-ntdsdit-system/
Author: Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community
Date: 2019-10-22
modified:2022-11-10
Tags:
  • -'attack.credential-access'
  • -'attack.t1003'
  • -'attack.t1003.002'
  • -'attack.t1003.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wmic.exe'
      - '\vssadmin.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
      - 'wmic.exe'
      - 'VSSADMIN.EXE'
  selection_cli:
    CommandLine|contains|all:
      -'shadow'
      -'create'

  condition:all of selection_*
Falsepositives:
  -Legitimate administrator working with shadow copies, access for backup purposes
Level: medium