Volume Shadow Copy Unmounted

Rule Info

Name
Volume Shadow Copy Unmounted
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects unmounting of an NTFS volume shadow copy instance. While this can occur in normal cleaning activity, its a sign of VolumeShadowCopy deletion.
Reference
Internal Research
Date
2024-01-24 00:00:00
Modified
None
Id
d26d61b6-796d-4901-94cd-ffea1eea381b
Tags
attack.defense_evasion
Type
Nextron Sigma feed only (private)

Rule History