Techniques
Sample rules
Volume Shadow Copy Mount
- source: sigma
- technicques:- t1003
- t1003.002
 
Description
Detects volume shadow copy mount via Windows event log
Detection logic
condition: selection
selection:
  DeviceName|contains: HarddiskVolumeShadowCopy
  EventID: 98
  Provider_Name: Microsoft-Windows-Ntfs
