BIOC Informational

Creation of volume shadow copy using vssadmin.exe

An attacker may create volume shadow copies to gain access to protected or locked files, whereas backup is the common legitimate use.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Credential Access
Status:
Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Indicator:

Process action type = execution AND target process cmd = * create* shadow* AND target process name = vssadmin.exe

Preventable: yes