Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
39 rules
Shadow Copy Deletion via Vssadmin to Inhibit Recovery
This rule detects vssadmin.exe deleting all volume shadow copies quietly, the recovery-inhibition step performed by PlayBoy Locker before encryption. Removing shadow copies prevents victims from restoring files and is a defining precursor to ransomware detonation.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-09-14Suspicious Shadow Copy Deletion via Vssadmin by Kraken Ransomware
This rule detects deletion of Volume Shadow Copies using vssadmin with the delete shadows and all flags. This behavior is associated with the Kraken ransomware group which inhibits system recovery prior to encryption. Removing shadow copies prevents victims from restoring files without paying the ransom.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-11Malicious Volume Shadow Copy Deletion via vssadmin or WMIC
This rule detects deletion of volume shadow copies via vssadmin Delete Shadows or wmic shadowcopy delete. Ransomware families in this report remove shadow copies to prevent victims from restoring encrypted files. Shadow copy deletion is a hallmark inhibit-recovery step performed during ransomware execution.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-09-11Malicious Volume Shadow Copy Deletion via vssadmin
This rule detects vssadmin deleting volume shadow copies, an inhibit-recovery action performed in Talos IR ransomware engagements immediately before encryption. Removing shadow copies prevents victims from restoring files and is a near-universal precursor to ransomware detonation.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-09-11Malicious Shadow Copy Deletion Via WMI
This rule detects PowerShell querying Win32_Shadowcopy and piping the result to Remove-WmiObject to delete volume shadow copies. Akira ransomware used Get-WmiObject Win32_Shadowcopy piped to Remove-WmiObject to destroy shadow copies before encryption. Deleting shadow copies is an inhibit-recovery action that prevents victims from restoring files without paying the ransom.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-10Volume Shadow Copy Deletion via vssadmin or wmic
This rule detects deletion of Volume Shadow Copies through vssadmin or wmic, an anti-recovery step performed by Phobos ransomware deployed by the 8Base group. Removing shadow copies prevents victims from restoring encrypted files without paying. This inhibit-recovery behavior almost always precedes or accompanies ransomware encryption.
HuntRule TeamWindowsprocess_creationHigh00Premium2026-09-10Malicious Inhibit System Recovery via Backup and Shadow Copy Deletion (via process_creation)
This rule detects deletion of volume shadow copies and backup catalogs and disabling of recovery via native tools, a destructive precursor observed in Phobos ransomware affiliate activity. Removing recovery options prevents victims from restoring data without paying, increasing the impact of the subsequent encryption.
HuntRule TeamWindowsprocess_creationHigh80Premium2026-09-10Malicious Shadow Copy Deletion via vssadmin
This rule detects vssadmin deleting all volume shadow copies quietly, an inhibit recovery step in the FunkSec ransomware chain. Removing shadow copies prevents victims from restoring encrypted files. Detecting it exposes recovery sabotage that typically precedes encryption.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-09Malicious Shadow Copy and Backup Catalog Deletion (via process_creation)
This rule detects deletion of volume shadow copies or the backup catalog through vssadmin, wmic, or wbadmin, an inhibit-recovery action executed by the Rorschach ransomware. Removing shadow copies and backups prevents victims from restoring encrypted files and is a defining ransomware behaviour.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-09Suspicious Volume Shadow Copy Deletion via PowerShell WMI by Akira Ransomware
This rule detects PowerShell deleting Volume Shadow Copies through the Win32_ShadowCopy WMI class, an inhibit-recovery step used by Akira ransomware before encryption. Removing shadow copies prevents victims from restoring files without paying.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-08Malicious Inhibition of System Recovery via Shadow Copy or Backup Deletion (via process_creation)
This rule detects command lines that delete volume shadow copies or backups or disable boot-time recovery, using vssadmin, wmic shadowcopy, wbadmin or bcdedit. Inhibiting system recovery is a high-impact technique in the Red Canary Threat Detection Report and a hallmark of ransomware preparing to prevent victims from restoring encrypted data. Detecting these destructive commands provides a critical, high-fidelity signal immediately before or during encryption.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-09-02DragonForce Ransomware Volume Shadow Copy Deletion via WMIC ShadowCopy Where Delete (via process_creation)
This rule detects abuse of WMIC to enumerate and delete a specific volume shadow copy by ID, the inhibit-recovery behavior DragonForce ransomware performs through cmd.exe before file encryption. Adversaries delete shadow copies so victims cannot restore encrypted files, making early detection critical for interrupting the intrusion before data becomes unrecoverable.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-30Malicious Volume Shadow Copy Deletion via Vssadmin
This rule detects vssadmin deleting all volume shadow copies which the actors in the Sliver and PoshC2 toolkit intrusion ran to inhibit recovery ahead of impact and this matters because deleting every shadow copy removes the primary local restore path and is a defining pre encryption ransomware action rarely performed by legitimate administrators.
HuntRule TeamWindowsprocess_creationHigh236Premium2026-08-28Malicious Credential Hive Copy from Volume Shadow Copy
This rule detects a copy command referencing a HarddiskVolumeShadowCopy path together with a credential store name such as SAM, SYSTEM, or ntds.dit, a technique Huntress observed for extracting locked hives from a shadow copy. Attackers duplicate credential databases from the snapshot to bypass file locks before offline cracking. Copying hive files out of a shadow copy is a strong credential-access indicator.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-08-19Malicious Shadow Copy and Backup Deletion for Ransomware Recovery Inhibition
This rule detects deletion of volume shadow copies and backup catalogs through vssadmin wmic and wbadmin which Phobos ransomware runs before encryption to prevent victims from restoring their files. Inhibiting system recovery is a common precursor to file encryption and warrants immediate response.
HuntRule TeamWindowsprocess_creationHigh133Premium2026-08-18