Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 3IT Vendor NewsHuntress

How Attackers Abuse VSS, and How Huntress Detects It

Huntress, Monday, September 14th, 2026

Huntress explains adversary abuse of Windows Volume Shadow Copy Service for credential theft and ransomware prep, plus detection logic.

This technical post explains how attackers abuse the Windows Volume Shadow Copy Service (VSS), both to extract credential material such as NTDS.dit and to delete shadow copies ahead of ransomware encryption.

Huntress breaks down the relevant command-line and API techniques and why they often blend into legitimate backup activity.

The article then describes the telemetry and detection logic Huntress uses to separate malicious VSS interaction from routine administration. Defenders get concrete behavioral signals to monitor.

more →  ·  More from Huntress →