Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin

Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades) (SigmaHQ), DRL 1.1
Published
2019-10-22
Updated
2026-07-30

ATT&CK techniques

Defense Evasion → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule identifies Windows process executions where built-in utilities commonly used for managing Shadow Copies are invoked with command-line arguments indicating deletion or removal actions. Attackers and administrators may use these commands to eliminate recovery artifacts and hinder incident response or backup-based recovery. The detection relies on process creation telemetry, specifically the executable path/name and the presence of Shadow Copy-related and deletion/resizing terms in the command line.

Related detections9 linkedT1490 — drag to rearrange
Malicious Boot Configuration Set to Safe Mode with Networking via bcdedit
Shadow Copy Deletion via Vssadmin to Inhibit Recovery
Suspicious Symlink Evaluation Enabled via fsutil
Malicious Mass Hyper-V Virtual Machine Shutdown via PowerShell by Kraken Ransomware
Suspicious Shadow Copy Deletion via Vssadmin by Kraken Ransomware
Malicious Volume Shadow Copy Deletion via vssadmin or WMIC
Malicious Volume Shadow Copy Deletion via vssadmin
Suspicious Free Space Wipe via cipher.exe
Malicious Shadow Copy Deletion Via WMI
Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Pivot detection · T1490 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.