VSSVC.exe

by Microsoft
Operating System

Sources: 300M+ executions observed in the wild.

Summary

Volume Shadow Copy Service (vssvc.exe) manages the VSS infrastructure that creates and manages shadow copies. It coordinates between requestors, writers, and providers to create consistent point-in-time copies of data.

VSSVC.exe is the 178th most commonly executed Windows program in EchoTrail's dataset, observed 87,234 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by services.exe.

Get this in your tools

The same record for vssvc.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/vssvc.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

178th
most commonly executed Windows program
87,234
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 799759acdf514f195a6c9dacba966866e9012aa862b45d2e27d345d5901b792411.5%
  • b48997fada4a600febfe36b249684e9caf01570bad36ed1fc9da99f2d100638e9.25%
  • 9d89dc644971f93931d0e59d42ade0a4ab49a5490709b46fcbbc309041c5432d7.24%
  • 74b6e612f9e009a5e43b603bcad854f3711f6c8a7ed0328b1e3a9b2d4c9ea3426.71%
  • 38af0b59ce7c1adec1d624203afbd6db3df9aface7d629626c71694f7e9c06c76.16%
  • 48654670d63e4ad0701b79c1ab64b73d34dd295941034c7ca0c8a92de081054d6.13%
  • 82459b7d6ceeff22e6e81ca445f9134c3ee917bdc3df185700813f23ac7db77e5.93%
  • 190932fb3bae64a8d9ff069abbceb3706969c70c36df1678385045a14bdeff1e5.8%
  • c4a4bb9b050d214d44119d6f39822e9e3b36ef7da67471843c0856e090987b705.34%
  • 76ec29f534ac4ef211b7914aeb7d0b6fc0088378f1c0d67bfcaac19b104e580f4.95%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does VSSVC.exe normally do?

Located in C:\Windows\System32. Always launched by services.exe (runs as a service). Single instance.

When is VSSVC.exe suspicious?

Not typically suspicious itself. Monitor vssadmin.exe and wmic for shadow copy manipulation rather than vssvc.exe.

How do attackers abuse VSSVC.exe?

Not directly abused. The service that vssadmin.exe and wmic interact with.

Detection guidance

No direct detection needed. Focus on vssadmin.exe and wmic shadow copy operations.

False positive notes

Normal background service.

Related Processes

Ask Rocky about VSSVC.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for VSSVC.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.