Creation Of Shadow Copy

Description

Monitor for signs that Vssadmin or Wmic has been used to create a shadow copy.

   Help

Creation Of Shadow Copy Help

You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model.

   Search

Open in Search