VSSVC.exe

by Microsoft
Operating System

Summary

Volume Shadow Copy Service (vssvc.exe) manages the VSS infrastructure that creates and manages shadow copies. It coordinates between requestors, writers, and providers to create consistent point-in-time copies of data.

VSSVC.exe is the 178th most commonly executed Windows program in EchoTrail's dataset, observed 87,234 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by services.exe.

178th
most commonly executed Windows program
87,234
observed executions
medium
statistical confidence

Behavior

Top Paths

  • C:\Windows\System32100%

Top Hashes (SHA256)

  • 799759acdf514f195a6c9dacba966866e9012aa862b45d2e27d345d5901b792411.5%
  • b48997fada4a600febfe36b249684e9caf01570bad36ed1fc9da99f2d100638e9.25%
  • 9d89dc644971f93931d0e59d42ade0a4ab49a5490709b46fcbbc309041c5432d7.24%
  • 74b6e612f9e009a5e43b603bcad854f3711f6c8a7ed0328b1e3a9b2d4c9ea3426.71%
  • 38af0b59ce7c1adec1d624203afbd6db3df9aface7d629626c71694f7e9c06c76.16%
  • 48654670d63e4ad0701b79c1ab64b73d34dd295941034c7ca0c8a92de081054d6.13%
  • 82459b7d6ceeff22e6e81ca445f9134c3ee917bdc3df185700813f23ac7db77e5.93%
  • 190932fb3bae64a8d9ff069abbceb3706969c70c36df1678385045a14bdeff1e5.8%
  • c4a4bb9b050d214d44119d6f39822e9e3b36ef7da67471843c0856e090987b705.34%
  • 76ec29f534ac4ef211b7914aeb7d0b6fc0088378f1c0d67bfcaac19b104e580f4.95%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does VSSVC.exe normally do?

Located in C:\Windows\System32. Always launched by services.exe (runs as a service). Single instance.

When is VSSVC.exe suspicious?

Not typically suspicious itself. Monitor vssadmin.exe and wmic for shadow copy manipulation rather than vssvc.exe.

How do attackers abuse VSSVC.exe?

Not directly abused. The service that vssadmin.exe and wmic interact with.

Detection guidance

No direct detection needed. Focus on vssadmin.exe and wmic shadow copy operations.

False positive notes

Normal background service.

Related Processes

Ask Rocky about VSSVC.exe

Rocky answers questions about VSSVC.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.