Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
39 rules
Windows Process Creation: Detects Volume Shadow Copy Listing via vssadmin
Alerts on Windows command lines that list VSS shadow copies and write results to log.txt.
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2021-08-09PowerShell SAM Hive Copy via Volume Shadow Copy Paths on Windows
Flags PowerShell commands that copy the SAM hive from Volume Shadow Copy locations using .NET or PowerShell copy semantics.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh339Free2021-07-29Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
frack113, Huntrule TeamWindowsps_classic_startHigh369Free2021-06-03Windows Command-Line Disables Volume Shadow Copy (VSS) Snapshots
Flags Windows command lines that disable Volume Shadow Copy (VSS) snapshots via VSS Diag service switches.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh211Free2021-01-28Windows Event Log Detects Volume Shadow Copy Mounts (HarddiskVolumeShadowCopy, EventID 98)
Alerts when NTFS logs indicate a VSS (HarddiskVolumeShadowCopy) mount using EventID 98.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssystemLow468Free2020-10-20Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical169Free2020-05-08Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.
Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh91Free2019-10-22Windows Shadow Copy Creation via PowerShell/pwsh/wmic/vssadmin Commands
Detects Windows processes using PowerShell/pwsh/wmic/vssadmin with shadow copy creation parameters.
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationMedium325Free2019-10-22Windows Volume Shadow Copy Symlink Creation Using mklink
Flags Windows mklink commands that reference HarddiskVolumeShadowCopy to create symlinks.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh123Free2019-10-22