VSSVC.exe
Sources: 300M+ executions observed in the wild.
Summary
Volume Shadow Copy Service (vssvc.exe) manages the VSS infrastructure that creates and manages shadow copies. It coordinates between requestors, writers, and providers to create consistent point-in-time copies of data.
VSSVC.exe is the 178th most commonly executed Windows program in EchoTrail's dataset, observed 87,234 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by services.exe.
Get this in your tools
The same record for vssvc.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/vssvc.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- 799759acdf514f195a6c9dacba966866e9012aa862b45d2e27d345d5901b792411.5%
- b48997fada4a600febfe36b249684e9caf01570bad36ed1fc9da99f2d100638e9.25%
- 9d89dc644971f93931d0e59d42ade0a4ab49a5490709b46fcbbc309041c5432d7.24%
- 74b6e612f9e009a5e43b603bcad854f3711f6c8a7ed0328b1e3a9b2d4c9ea3426.71%
- 38af0b59ce7c1adec1d624203afbd6db3df9aface7d629626c71694f7e9c06c76.16%
- 48654670d63e4ad0701b79c1ab64b73d34dd295941034c7ca0c8a92de081054d6.13%
- 82459b7d6ceeff22e6e81ca445f9134c3ee917bdc3df185700813f23ac7db77e5.93%
- 190932fb3bae64a8d9ff069abbceb3706969c70c36df1678385045a14bdeff1e5.8%
- c4a4bb9b050d214d44119d6f39822e9e3b36ef7da67471843c0856e090987b705.34%
- 76ec29f534ac4ef211b7914aeb7d0b6fc0088378f1c0d67bfcaac19b104e580f4.95%
Process Ancestry
Top Grandparents
- wininit.exe100%
Top Parents
- services.exe99.98%
Top Children
- find.exe50%
- conhost.exe25%
- NETSTAT.EXE25%
Security Analysis
What does VSSVC.exe normally do?
Located in C:\Windows\System32. Always launched by services.exe (runs as a service). Single instance.
When is VSSVC.exe suspicious?
Not typically suspicious itself. Monitor vssadmin.exe and wmic for shadow copy manipulation rather than vssvc.exe.
How do attackers abuse VSSVC.exe?
Not directly abused. The service that vssadmin.exe and wmic interact with.
Detection guidance
No direct detection needed. Focus on vssadmin.exe and wmic shadow copy operations.
False positive notes
Normal background service.
Related Processes
Ask Rocky about VSSVC.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for VSSVC.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.