Suspicious usage of File Server Remote VSS Protocol (FSRVP)
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Use Alternate Authentication Material: Pass the Hash (T1550.002)
Severity
High
Description
A suspicious usage of File Server Remote VSS Protocol (FSRVP) was done.
Attacker's Goals
An attacker is attempting to steal credentials and move laterally within a network.
Investigative actions
Check for suspicious processes on the source host.
Check if the source host is a vulnerability scanner.
Look for additional suspicious activities by users.
PreviousSuspicious usage of EC2 token
NextSuspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet
Was this helpful?
