Windows System Software -- Consulting, Training, Development -- Unique Expertise, Guaranteed Results

Before Posting...
Please check out the Community Guidelines in the Announcements and Administration Category.

Shadow Copy IRPs

KeternaKeterna Member Posts: 18

Dear all,

I'm working on intercepting IRPs IRP_MJ_CREATE to filter some file access. I realized that Shadow Copy on Windows does not trigger any IRP when backing up my files. I'm a bit curious; How can Shadow Copy access my files without triggering this IRP ? Is there a way to catch the file interactions of Shadow Copy from a minifilter driver ?

Thanks for your help !

Comments

  • rod_widdowsonrod_widdowson Member - All Emails Posts: 1,095

    Shadow sets (as per VSS) are a device level (I'm guessing a block level copy on write but I've never bothered to look) thing so you'll never see the "backup".

    When the shadow set is surfaced (e.g. to list or restore files) you do see a volume mounted upon a device with an obvious name.

Sign In or Register to comment.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Upcoming OSR Seminars
Kernel Debugging 30 Mar 2020 OSR Seminar Space
Developing Minifilters 20 Apr 2020 OSR Seminar Space & ONLINE
Writing WDF Drivers 11 May 2020 OSR Seminar Space & ONLINE
Internals & Software Drivers 28 Sept 2020 Dulles, VA