ShadowCoerce NTLM Coercion via FssAgent
Detects unauthorized attempts to coerce the File Server VSS Agent (FssAgent) into authenticating to an attacker-controlled host. This is achieved by invoking the IsPathSupported (opnum 8) or IsPathShadowCopied (opnum 9) functions on the FssAgent RPC interface, which can be leveraged to capture NTLM hashes.
Cortex XDR

