Volume Shadow Copy Mount

 Original Source: [Sigma source]
Title: Volume Shadow Copy Mount
Status: test
Description:Detects volume shadow copy mount via Windows event log
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-3---esentutlexe-sam-copy
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR)
Date: 2020-10-20
modified:2022-12-25
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
Logsource:
  • product: windows
  • service: system
Detection:
  selection:
    Provider_Name: 'Microsoft-Windows-Ntfs'
    EventID: '98'
    DeviceName|contains: 'HarddiskVolumeShadowCopy'
  condition:selection
Falsepositives:
  -Legitimate use of volume shadow copy mounts (backups maybe).
Level: low