Creating a Shadow Copy

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This Threat Hunt package identifies suspicious activities related shadow copies being created from a variety of techniques.

Attribute Value
Type Hunting Query
Solution Intel471
ID 262d9692-6d36-4b10-9fc5-159930cff604
Tactics Collection, CredentialAccess
Techniques T1003.003, T1005
Required Connectors SecurityEvents, WindowsSecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
SecurityEvent CommandLine contains "shadow"
CommandLine has "Checkpoint-Computer"
CommandLine has "create"
✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries · Back to Intel471