Create Volume Shadow Copy with Powershell

 Original Source: [Sigma source]
Title: Create Volume Shadow Copy with Powershell
Status: test
Description:Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information
References:
  -https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1&viewFallbackFrom=powershell-7
Author: frack113
Date: 2022-01-12
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.003'
  • -'attack.ds0005'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains|all:
      -'Win32_ShadowCopy'
      -').Create('
      -'ClientAccessible'

  condition:selection
Falsepositives:
  -Legitimate PowerShell scripts
Level: high