UC-L3-005
Shadow Copy Deletion
Windows Security / Sysmon Event ID 1
Use case development / Protect Against Ransomware / Detect Backup Tampering
sigma
Detection rule
title: Shadow Copy Deletion via Vssadmin
status: experimental
description: Detects deletion of shadow copies commonly done by ransomware
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith: '\vssadmin.exe'
CommandLine|contains:
- 'delete shadows'
- 'resize shadowstorage'
condition: selection
falsepositives:
- Legitimate administration
level: critical
tags:
- attack.impact
- attack.t1490Test cases
- Run vssadmin delete shadows command
False positive guidance
Whitelist backup administrator accounts if needed.