BIOC High

Process requests the deletion of Windows Shadowcopies

Ransomware and wipers may use the wmic.exe or vssadmin.exe utilities to delete or modify Shadowcopies (a Windows backup mechanism).

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490)
Indicator:

Process action type = execution AND target process cmd = *delete*shadows*all* , *shadowcopy*delete * AND target process name = vssadmin.exe , wmic.exe

Preventable: yes