Shadow copy or backup catalog deletion from the command line
Detects the recovery-destruction commands that precede or accompany ransomware encryption on Windows — shadow copy deletion and resizing, backup catalog removal, and the boot configuration edits that suppress automatic repair. This rule does not detect encryption. The encryption itself appears in telemetry only as a burst of writes and renames whose volume is the signal, and MITRE's FileExtension, TargetFolder and TimeWindow knobs all describe counting across that burst, which Sigma cannot express; the CommandLine knob of AN0602 is the one element of the analytic that lands in a single event, so that is what is written here. Every selection matches on CommandLine alone, so the rule is a single-field OR that all backends render. The same commands are the core observable for Inhibit System Recovery (T1490), and a hit should be triaged as either. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0215, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full descriptionShow less
The detection
The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.
detection.yml
title: Shadow copy or backup catalog deletion from the command lineid: 31d883ab-4939-434d-b14c-de54513f2fd9status: experimentaldescription: | Detects the recovery-destruction commands that precede or accompany ransomware encryption on Windows — shadow copy deletion and resizing, backup catalog removal, and the boot configuration edits that suppress automatic repair. This rule does not detect encryption. The encryption itself appears in telemetry only as a burst of writes and renames whose volume is the signal, and MITRE's FileExtension, TargetFolder and TimeWindow knobs all describe counting across that burst, which Sigma cannot express; the CommandLine knob of AN0602 is the one element of the analytic that lands in a single event, so that is what is written here. Every selection matches on CommandLine alone, so the rule is a single-field OR that all backends render. The same commands are the core observable for Inhibit System Recovery (T1490), and a hit should be triaged as either. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0215, not hand-written and not tested by its author. Any lab result is on this rule's own page.references: - https://attack.mitre.org/techniques/T1486 - https://attack.mitre.org/detectionstrategies/DET0215author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags: - attack.impact - attack.t1486logsource: category: process_creation product: windowsdetection: selection_vss_delete: CommandLine|contains|all: - 'vssadmin' - 'delete shadows' selection_vss_resize: CommandLine|contains|all: - 'vssadmin' - 'resize shadowstorage' selection_shadowcopy_wmi: CommandLine|contains|all: - 'shadowcopy' - 'delete' selection_wbadmin: CommandLine|contains|all: - 'wbadmin' - 'delete' selection_bcdedit_recovery: CommandLine|contains|all: - 'bcdedit' - 'recoveryenabled' selection_bcdedit_failures: CommandLine|contains|all: - 'bcdedit' - 'ignoreallfailures' condition: 1 of selection*falsepositives: - "Backup and imaging agents pruning their own restore points. Several commercial products call vssadmin to resize shadow storage or to delete a snapshot they created, and one of them running on a schedule will match here every cycle. Scope by the parent process and the installation path of the agent rather than by dropping the resize selection, since resizing storage to a few megabytes is a documented way to purge every snapshot at once." - "Administrative recovery work. Freeing disk space with vssadmin, retiring an old system state backup with wbadmin, or disabling the automatic repair loop with bcdedit while troubleshooting a boot problem are all genuine tasks that produce exactly these command lines. Operator identity and a change record are what separate them, and neither is in this event." - "Build, lab and imaging pipelines that reset a golden image, which routinely clear shadow copies and boot recovery settings as part of sysprep-adjacent cleanup." - "Software installers and servicing routines that remove a restore point they took before a major upgrade."level: highSentinel · KQL
Run this as a search.
DeviceProcessEvents| where ((ProcessCommandLine contains "vssadmin" and ProcessCommandLine contains "delete shadows") or (ProcessCommandLine contains "vssadmin" and ProcessCommandLine contains "resize shadowstorage") or (ProcessCommandLine contains "shadowcopy" and ProcessCommandLine contains "delete") or (ProcessCommandLine contains "wbadmin" and ProcessCommandLine contains "delete") or (ProcessCommandLine contains "bcdedit" and ProcessCommandLine contains "recoveryenabled") or (ProcessCommandLine contains "bcdedit" and ProcessCommandLine contains "ignoreallfailures"))
Splunk · SPL
Run this as a search.
index=* ((CommandLine="*vssadmin*" AND CommandLine="*delete shadows*") OR (CommandLine="*vssadmin*" AND CommandLine="*resize shadowstorage*") OR (CommandLine="*shadowcopy*" AND CommandLine="*delete*") OR (CommandLine="*wbadmin*" AND CommandLine="*delete*") OR (CommandLine="*bcdedit*" AND CommandLine="*recoveryenabled*") OR (CommandLine="*bcdedit*" AND CommandLine="*ignoreallfailures*"))Elastic · ES|QL
Run this as a search.
FROM logs-*| WHERE ((TO_LOWER(process.command_line) LIKE "*vssadmin*" AND TO_LOWER(process.command_line) LIKE "*delete shadows*") OR (TO_LOWER(process.command_line) LIKE "*vssadmin*" AND TO_LOWER(process.command_line) LIKE "*resize shadowstorage*") OR (TO_LOWER(process.command_line) LIKE "*shadowcopy*" AND TO_LOWER(process.command_line) LIKE "*delete*") OR (TO_LOWER(process.command_line) LIKE "*wbadmin*" AND TO_LOWER(process.command_line) LIKE "*delete*") OR (TO_LOWER(process.command_line) LIKE "*bcdedit*" AND TO_LOWER(process.command_line) LIKE "*recoveryenabled*") OR (TO_LOWER(process.command_line) LIKE "*bcdedit*" AND TO_LOWER(process.command_line) LIKE "*ignoreallfailures*"))
Wazuh · XML rule
Deploy to your manager — this is a rule, not a search.
<group name="sigma,windows,process_creation,"> <!-- Rule ids must be unique on your manager; 100000+ is the user range. --> <rule id="100000" level="12"> <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. --> <field name="CommandLine" type="pcre2">(?i)((?=.*(?:vssadmin))(?=.*(?:delete shadows)).*|(?=.*(?:vssadmin))(?=.*(?:resize shadowstorage)).*|(?=.*(?:shadowcopy))(?=.*(?:delete)).*|(?=.*(?:wbadmin))(?=.*(?:delete)).*|(?=.*(?:bcdedit))(?=.*(?:recoveryenabled)).*|(?=.*(?:bcdedit))(?=.*(?:ignoreallfailures)).*)</field> <description>Shadow copy or backup catalog deletion from the command line</description> <mitre> <id>T1486</id> </mitre> </rule></group>
Verdicts · reactions · comments
Community
Verdicts from engineers who actually deployed it, and the conversation around it.
Nobody has run this in a real environment and said what happened.
Verdicts from engineers who deployed it
0 castNo verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.
Log in to report a verdict.
Log in to join the discussion.
No comments yet. Someone who deploys this will have something to say about it.