impact/inhibit-system-recovery
# generated using capa explorer for IDA Pro
rule:
meta:
name: resize volume shadow copy storage
namespace: impact/inhibit-system-recovery
authors:
- michael.hunhoff@mandiant.com
scopes:
static: basic block
dynamic: call
features:
- and:
- match: interact with driver via IOCTL
- number: 0x53C028 = IOCTL_VOLSNAP_SET_MAX_DIFF_AREA_SIZE
last edited: 2024-02-14 13:56:47