BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

8 BIOCs match the current filters. technique: T1490 ✕

Download CSV Show ATT&CK heatmap
  • Manipulation of Volume Shadow Copy configuration Informational Tampering

    Modifying this key might remove VSS privileges from user accounts, possibly disabling Volume Shadow Copy.

    Indicator:

    Registry action type = delete_registry_key , rename_registry_key , set_registry_value , delete_registry_value AND registry key name = *\Services\VSS\VssAccessControl Host host os = windows

    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Inhibit System Recovery (T1490)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Manipulation of Windows Safe Boot configuration Medium Tampering

    Safe-boot Registry settings deletion.

    Indicator:

    Registry registry key name = *Control\SafeBoot AND action type = delete_registry_value Host host os = windows

    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Inhibit System Recovery (T1490)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Manipulation of permissions for the Application Event Log Informational Tampering

    Removing read/write permissions from this key may result in errors in the Application event log, and may cause certain VSS diagnostic tools to not function correctly. https://technet.microsoft.com/en-us/library/cc734219(v=ws.10).aspx.

    Indicator:

    Registry action type = delete_registry_key , rename_registry_key , set_registry_value , delete_registry_value AND registry key name = *\Services\VSS\Diag Host host os = windows

    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Inhibit System Recovery (T1490)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Modification of Windows boot configuration using bcdedit.exe Informational Tampering

    BCDEdit is a Microsoft Windows utility that can modify boot parameters. It is usually used as part of an attack to prevent repair of the affected system by disabling booting in recovery mode. It can also be used to stop Windows' Patchguard from objecting to the unsigned and insecure nature of a driver being loaded.

    Indicator:

    Process action type = execution AND target process cmd = *set* AND target process name = bcdedit.exe

    ATT&CK tactics: Defense Evasion (TA0005) Impact (TA0040)
    ATT&CK techniques: Rootkit (T1014) Inhibit System Recovery (T1490)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Process requests the deletion of Windows Shadowcopies High Tampering

    Ransomware and wipers may use the wmic.exe or vssadmin.exe utilities to delete or modify Shadowcopies (a Windows backup mechanism).

    Indicator:

    Process action type = execution AND target process cmd = *delete*shadows*all* , *shadowcopy*delete * AND target process name = vssadmin.exe , wmic.exe

    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Inhibit System Recovery (T1490)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Tampering with the Windows System Restore configuration Low Tampering

    System Restore was disabled on the endpoint. In such a case, one may not be able to recover files in case of disaster. This may be initiated by the IT department, but also may indicate malicious activity such as ransomware.

    Indicator:

    Registry action type = set_registry_value , create_registry_key , delete_registry_value AND registry data = 1 AND registry key name = *Software\Microsoft\Windows Nt\SystemRestore\DisableSR Host host os = windows

    ATT&CK tactics: Defense Evasion (TA0005) Impact (TA0040)
    ATT&CK techniques: Rootkit (T1014) Inhibit System Recovery (T1490)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • WMI access to shadow copy interface Informational Credential Access

    An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit.

    Indicator:

    Process action type = execution AND target process cmd = *win32_shadowcopy*

    ATT&CK tactics: Credential Access (TA0006) Impact (TA0040)
    ATT&CK techniques: OS Credential Dumping (T1003) Inhibit System Recovery (T1490)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Windows File Protection being disabled via Registry Low Tampering

    Windows File Protection (WFP) prevents programs from replacing critical Windows system files. Programs must not overwrite these files because they are used by the operating system and by other programs. Protecting these files prevents problems with programs and the operating system.

    Indicator:

    Registry action type = all AND registry data = 1 AND registry key name = *SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SFCDisable Host host os = windows

    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Inhibit System Recovery (T1490)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11