Skip to content
Please update to the latest release 0.77.3 to address Multiple CVEs.
Windows.Search.VSS

Windows.Search.VSS

Finds files in Volume Shadow Copies (VSS) using the ntfs_vss accessor.

Typically used to output deduplicated paths for processing by other artifacts.

NOTE: This used to be more complicated but now delegates to the ntfs_vss accessor to do all the hard work.


name: Windows.Search.VSS
description: |
  Finds files in Volume Shadow Copies (VSS) using the `ntfs_vss`
  accessor.
  
  Typically used to output deduplicated paths for processing by other
  artifacts.

  NOTE: This used to be more complicated but now delegates to the
  `ntfs_vss` accessor to do all the hard work.

author: Matt Green - @mgreen27

precondition: SELECT * FROM info() where OS = 'windows'

parameters:
  - name: SearchFilesGlob
    default: C:\Windows\System32\winevt\Logs\Security.evtx
    description: Use a glob to define the files that will be searched.

  - name: VSS_MAX_AGE_DAYS
    type: int
    description: |
      If larger than 0 we restrict VSS age to this many days
      ago. Otherwise we find all VSS.

sources:
  - query: |
      SELECT * FROM glob(globs=SearchFilesGlob, accessor="ntfs_vss")
      ORDER BY OSPath