Esentutl Volume Shadow Copy Service Keys

 Original Source: [Sigma source]
Title: Esentutl Volume Shadow Copy Service Keys
Status: test
Description:Detects the volume shadow copy service initialization and processing via esentutl. Registry keys such as HKLM\\System\\CurrentControlSet\\Services\\VSS\\Diag\\VolSnap\\Volume are captured.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-3---esentutlexe-sam-copy
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
Date: 2020-10-20
modified:2022-12-25
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
Logsource:
  • category: registry_event
  • product: windows
Detection:
  selection:
    TargetObject|contains: 'System\CurrentControlSet\Services\VSS'
    Image|endswith: 'esentutl.exe'
  filter:
    TargetObject|contains: 'System\CurrentControlSet\Services\VSS\Start'
  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high