BIOC
Informational
✕
Manipulation of Volume Shadow Copy configuration
Modifying this key might remove VSS privileges from user accounts, possibly disabling Volume Shadow Copy.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Tampering
- Status:
- Enabled
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490)
Indicator:
Registry action type = delete_registry_key , rename_registry_key , set_registry_value , delete_registry_value AND registry key name = *\Services\VSS\VssAccessControl Host host os = windows
Preventable: yes