Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕
Download CSV Show ATT&CK heatmapUncommon creation or access operation of sensitive shadow copy Low 2 variations
An uncommon creation or access of a sensitive Shadow Copy volume path.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: OS Credential Dumping (T1003)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Attackers may try to copy sensitive data or dump OS credentials from the host file system by using Shadow Copy volume utilities.Investigative actions: Verify if the shadow copy operation is part of an IT activity. Look for other hosts performing the same shadow copy event with similar causality process behavior.* Inspect the causality process and its characteristics as they appear on other hosts.Variations
Uncommon creation or access operation of sensitive shadow copy by a remote actor
Low overridden
An uncommon creation or access of a sensitive Shadow Copy volume path. overridden
Uncommon creation or access operation of sensitive shadow copy by a high-risk process
High overridden
An uncommon creation or access of a sensitive Shadow Copy volume path by a high-risk process. overridden