BIOC Informational

Manipulation of Volume Shadow Copy configuration

Modifying this key might remove VSS privileges from user accounts, possibly disabling Volume Shadow Copy.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490)
Indicator:

Registry action type = delete_registry_key , rename_registry_key , set_registry_value , delete_registry_value AND registry key name = *\Services\VSS\VssAccessControl Host host os = windows

Preventable: yes