LoFP LoFP / legitimate use of vssvc. maybe backup operations. it would usually be done by c:\windows\system32\vssvc.exe.

Techniques

Sample rules

VSSAudit Security Event Source Registration

Description

Detects the registration of the security event source VSSAudit. It would usually trigger when volume shadow copy operations happen.

Detection logic

condition: selection
selection:
  AuditSourceName: VSSAudit
  EventID:
  - 4904
  - 4905