Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators

Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2020-05-08
Updated
2026-07-31

ATT&CK techniques

Execution → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

What it detects

This rule flags Windows process creation patterns consistent with a document-based dropper attempting to impair recovery by deleting Volume Shadow Copies. It matches a Word parent spawning a temporary .tmp binary and a subsequent wmic execution from a Temp path that runs shadowcopy deletion commands containing traversal to system32. The detection relies on process creation telemetry including ParentImage, Image, and CommandLine.

Related detections9 linkedT1047 — drag to rearrange
Malicious Shadow Copy Deletion Via WMI
Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Windows: Suspicious Process Spawning from Microsoft Office Applications
Suspicious OneNote Spawning Script Interpreter (via process_creation)
Malicious Boot Configuration Set to Safe Mode with Networking via bcdedit
Shadow Copy Deletion via Vssadmin to Inhibit Recovery
Lateral Movement via WMIC Remote Process Creation
Suspicious Symlink Evaluation Enabled via fsutil
Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Pivot detection · T1047 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.