Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load (48bfd177-7cf2-412b-ad77-baf923489e82)
Detects the image load of VSS DLL by uncommon executables
| Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
|---|---|---|---|---|
| Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load (48bfd177-7cf2-412b-ad77-baf923489e82) | Sigma-Rules | Inhibit System Recovery - T1490 (f5d8eed6-48a9-4cdf-a3d7-d1ffa99c3d2a) | Attack Pattern | 1 |