Suspicious Volume Shadow Copy VSS_PS.dll Load (333cdbe8-27bb-4246-bf82-b41a0dca4b70)
Detects the image load of vss_ps.dll by uncommon executables
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Suspicious Volume Shadow Copy VSS_PS.dll Load (333cdbe8-27bb-4246-bf82-b41a0dca4b70) | Sigma-Rules | Inhibit System Recovery - T1490 (f5d8eed6-48a9-4cdf-a3d7-d1ffa99c3d2a) | Attack Pattern | 1 |