Malicious Shadow Copy Deletion and Recovery Inhibition via process_creation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-17
Updated
2026-09-17

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule detects the destruction of volume shadow copies and disabling of Windows recovery options, a hallmark of WannaCry and other ransomware families. The activity removes backups via vssadmin and wmic, disables boot recovery via bcdedit, or deletes the backup catalog via wbadmin to prevent victim recovery. This behavior almost always precedes or accompanies file encryption and warrants immediate response.

Related detections9 linkedT1486 — drag to rearrange
RedCurl QWCrypt Ransomware Execution with Hyper-V Targeting Flags
Malicious Azure Deletion of Resource Locks and Immutability Policies
Malicious BitLocker Encryption With Shadow Copy Removal via manage-bde (via process_creation)
Malicious Azure Storage and Compute Destruction via Key Listing and Snapshot Deletion
Windows process activity matching WannaCry executables and ransom note text
Malicious WannaCry tasksche Execution from mssecsvc Service via process_creation
Suspicious EKANS Ransomware Payload Dropped to Drive Root (via file_event)
Malicious Shadow Copy Deletion and Boot Recovery Tampering via Process Creation
Malicious BlackSuit Ransomware Execution via Process Creation
Malicious Shadow Copy Deletion and Recovery Inhibition via process_creation
Pivot detection · T1486 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.