Sensitive File Access Via Volume Shadow Copy Backup — Detection Rule

Detects a command that accesses the VolumeShadowCopy in order to extract sensitive files such as the Security or SAM registry hives or the AD database (ntds.dit)

Read the full analysis on IntelFusions