Hackers Abuse VSSAdmin to Extract NTDS.dit and Delete Windows Recovery Copies

Windows attackers are turning a built-in recovery feature into a tool for disruption. By abusing Volume Shadow Copy Service, intruders can copy protected data, access the Active Directory database, and erase recovery copies after ransomware. The technique blends into Windows activity. Backup software, remote management tools, and administrators may create or remove shadow copies, forcing […]

This article has been indexed from Cyber Security News

Read the original article: