Windows Shadow Copy Creation via PowerShell/pwsh/wmic/vssadmin Commands

Detects Windows processes using PowerShell/pwsh/wmic/vssadmin with shadow copy creation parameters.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-22
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process executions on Windows that invoke system utilities associated with PowerShell, pwsh, wmic, or vssadmin and include command-line arguments indicating shadow copy creation. Attackers may use this technique to access or extract credential material from snapshots while avoiding direct access to live system files. Telemetry relies on Windows process creation events, including the executable image path and command-line content.

Related detections9 linkedT1003.002 — drag to rearrange
Malicious Credential Hive Copy from Volume Shadow Copy
Windows Print.EXE Sensitive File Dump for Credential Access
Windows PUA: MemProcFS memory dump mounting via -device
Windows File Events: NTDS.DIT Created by Suspicious or Rare Process
Windows esentutl Usage with /p Flag for Credential Access
Zeek SMB: Network Share File Transfers of Credential-Related Filenames
Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Windows Volume Shadow Copy Symlink Creation Using mklink
Windows Shadow Copy Creation via PowerShell/pwsh/wmic/vssadmin Commands
Pivot detection · T1003.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.