This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Volume Shadow Copy Vssapi.dll Load
Original Source:
[Sigma source]
Title:
Suspicious Volume Shadow Copy Vssapi.dll Load
Status:
test
Description:
Detects the image load of VSS DLL by uncommon executables
References:
-https://github.com/ORCx41/DeleteShadowCopies
Author:
frack113
Date:
2022-10-31
modified:
2026-08-27
Tags:
-'attack.impact'
-'attack.t1490'
Logsource:
category: image_load
product: windows
Detection:
selection:
ImageLoaded|endswith
:
'\vssapi.dll'
filter_main_windows:
- Image
:
- 'C:\Windows\explorer.exe'
- 'C:\Windows\ImmersiveControlPanel\SystemSettings.exe'
- 'C:\Windows\servicing\TrustedInstaller.exe'
- Image|startswith
:
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
- 'C:\Windows\Temp\{'
- 'C:\Windows\WinSxS\'
- 'C:\$WinREAgent\Scratch\'
filter_main_program_files:
Image|startswith
:
-'C:\Program Files\'
-'C:\Program Files (x86)\'
filter_main_null_image:
Image
:
'None'
filter_optional_programdata_packagecache:
Image|startswith
:
'C:\ProgramData\Package Cache\'
filter_optional_avira:
Image|contains|all
:
-'\temp\is-'
-'\avira_system_speedup.tmp'
condition
:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Unknown
Level:
high