Tag
Detecting Unusual Image Loads of vsstrace.dll
1 rule 1 TTPDetection of anomalous process loading of the Volume Shadow Copy service DLL vsstrace.dll which may indicate unauthorized attempts to interact with or disrupt shadow copy operations.
Suspicious Loading of Vssapi.dll
1 rule 1 TTPDetection of the Volume Shadow Copy API library (vssapi.dll) being loaded by unauthorized processes, a common indicator of ransomware activity targeting backup shadow copies.
Volume Shadow Copy Deletion via PowerShell
2 rules 1 TTPDetects the use of PowerShell to delete volume shadow copies, a tactic commonly employed by ransomware and other destructive attacks to hinder data recovery efforts.
VssAdmin Shadow Copy Deletion or Resize
2 rules 1 TTPThe rule identifies the use of vssadmin.exe to delete or resize shadow copies on Windows endpoints, which is a common tactic used in ransomware attacks to prevent system recovery.
Volume Shadow Copy Deletion via WMIC
2 rules 2 TTPsAttackers use Windows Management Instrumentation Command-line (WMIC) to delete volume shadow copies, inhibiting system recovery in ransomware and destructive attacks.