Uncommon creation or access operation of sensitive shadow copy
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
OS Credential Dumping (T1003)
Severity
Low
Description
An uncommon creation or access of a sensitive Shadow Copy volume path.
Attacker's Goals
Attackers may try to copy sensitive data or dump OS credentials from the host file system by using Shadow Copy volume utilities.
Investigative actions
Verify if the shadow copy operation is part of an IT activity.
Look for other hosts performing the same shadow copy event with similar causality process behavior.* Inspect the causality process and its characteristics as they appear on other hosts.
Variations
PreviousUncommon communication to an instant messaging server
NextUncommon DLL-sideloading from a logical CD-ROM (ISO) device
Was this helpful?
