Malicious Shadow Copy Deletion via WMI PowerShell

PremiumReviewedSigma · High · v1
Category
ps_script
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

Execution → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

What it detects

This rule detects PowerShell querying Win32_Shadowcopy through WMI and deleting the returned shadow copies, an alternative recovery-inhibition technique that avoids the vssadmin binary. It is associated with REvil ransomware-as-a-service affiliate operations seeking to destroy backups prior to encryption. Detecting the WMI-based variant closes a common evasion gap around shadow copy deletion.

Related detections9 linkedT1047 — drag to rearrange
Malicious Shadow Copy Deletion Via WMI
Malicious Volume Shadow Copy Deletion for Recovery Inhibition
Suspicious Shadow Copy Deletion via WMIC or PowerShell (via process_creation)
Malicious Mass Hyper-V Virtual Machine Shutdown via PowerShell by Kraken Ransomware
Windows process creation: CrackMapExec execution via characteristic command-line flags
Windows PowerShell Command Lines with WMI Process Creation and rundll32 Invocation
Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Malicious Shadow Copy Deletion via WMI PowerShell
Pivot detection · T1047 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.