VSSAudit Security Event Source Registration

 Original Source: [Sigma source]
Title: VSSAudit Security Event Source Registration
Status: test
Description:Detects the registration of the security event source VSSAudit. It would usually trigger when volume shadow copy operations happen.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-3---esentutlexe-sam-copy
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR)
Date: 2020-10-20
modified:2022-04-28
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    AuditSourceName: 'VSSAudit'
    EventID:
      -'4904'
      -'4905'

  condition:selection
Falsepositives:
  -Legitimate use of VSSVC. Maybe backup operations. It would usually be done by C:\Windows\System32\VSSVC.exe.
Level: informational