Copy From VolumeShadowCopy Via Cmd.EXE — Detection Rule

Detects the execution of the builtin "copy" command that targets a shadow copy (sometimes used to copy registry hives that are in use)

Read the full analysis on IntelFusions