BIOC
High
✕
Process requests the deletion of Windows Shadowcopies
Ransomware and wipers may use the wmic.exe or vssadmin.exe utilities to delete or modify Shadowcopies (a Windows backup mechanism).
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Tampering
- Status:
- Enabled
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490)
Indicator:
Process action type = execution AND target process cmd = *delete*shadows*all* , *shadowcopy*delete * AND target process name = vssadmin.exe , wmic.exe
Preventable: yes