Sensitive File Access Via Volume Shadow Copy Backup

 Original Source: [Sigma source]
Title: Sensitive File Access Via Volume Shadow Copy Backup
Status: test
Description:Detects a command that accesses the VolumeShadowCopy in order to extract sensitive files such as the Security or SAM registry hives or the AD database (ntds.dit)
References:
  -https://twitter.com/vxunderground/status/1423336151860002816?s=20
  -https://www.virustotal.com/gui/file/03e9b8c2e86d6db450e5eceec057d7e369ee2389b9daecaf06331a95410aa5f8/detection
  -https://pentestlab.blog/2018/07/04/dumping-domain-password-hashes/
Author: Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems)
Date: 2021-08-09
modified:2024-01-18
Tags:
  • -'attack.impact'
  • -'attack.t1490'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_1:
    CommandLine|contains: '\\\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy'
  selection_2:
    CommandLine|contains:
      -'\\NTDS.dit'
      -'\\SYSTEM'
      -'\\SECURITY'

  condition:all of selection_*
Falsepositives:
  -Unlikely
Level: high