title: Conti Volume Shadow Listing id: aa92fd02-09f2-48b0-8a93-864813fb8f41 description: Detects a command used by conti to exfiltrate NTDS author: Max Altgelt, Tobias Michalski date: 2021/08/09 status: experimental references: - https://twitter.com/vxunderground/status/1423336151860002816?s=20 - https://www.virustotal.com/gui/file/03e9b8c2e86d6db450e5eceec057d7e369ee2389b9daecaf06331a95410aa5f8/detection logsource: category: process_creation product: windows detection: selection: CommandLine|contains|all: - '7za.exe' - '\\C$\\temp\\log.zip' condition: selection falsepositives: - Unknown level: high tags: - attack.collection - attack.t1560