Malicious Volume Shadow Copy Deletion for Recovery Inhibition

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

Execution → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

What it detects

This rule detects deletion of volume shadow copies through vssadmin, wmic or PowerShell, the recovery-inhibition step used by the Handala group and many destructive operations before encryption or wiping. Removing shadow copies prevents victims from restoring affected files. Administrative shadow copy deletion on endpoints is uncommon and warrants review alongside other impact indicators.

Related detections9 linkedT1490 — drag to rearrange
Suspicious Shadow Copy Deletion via WMIC or PowerShell (via process_creation)
Malicious Shadow Copy Deletion Via WMI
Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Malicious Volume Shadow Copy Deletion via Vssadmin
Malicious Boot Configuration Tampering via bcdedit [Intel471] #2
Malicious Volume Shadow Copy Deletion Before Ransomware Encryption
Malicious Volume Shadow Copy Deletion via Vssadmin or WMIC (via process_creation)
Malicious Volume Shadow Copy Deletion via vssadmin
Suspicious WMIC Remote Process Creation for Lateral Movement
Malicious Volume Shadow Copy Deletion for Recovery Inhibition
Pivot detection · T1490 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.