LoFP LoFP / legitimate use of volume shadow copy mounts (backups maybe).

Techniques

Sample rules

Volume Shadow Copy Mount

Description

Detects volume shadow copy mount via Windows event log

Detection logic

condition: selection
selection:
  DeviceName|contains: HarddiskVolumeShadowCopy
  EventID: 98
  Provider_Name: Microsoft-Windows-Ntfs