| name | hunting-for-shadow-copy-deletion |
| description | Hunt for Volume Shadow Copy deletion activity that indicates ransomware preparation or anti-forensics by monitoring vssadmin, wmic, and PowerShell shadow copy commands. Use when hunting for volume shadow copy deletion activity that indicates ransomware. |
| domain | cybersecurity |
| tags | ["threat-hunting","mitre-attack","shadow-copy","ransomware","anti-forensics","t1490","proactive-detection"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["Platform Hardening","Restore Object","Restore Configuration","Restore Software","Software Update"] |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Hunting For Shadow Copy Deletion
Overview
Cybersecurity skill for hunting for shadow copy deletion. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"hunting for shadow copy deletion"
-
"When proactively hunting for indicators of hunting for shadow copy deletion in t"
-
"After threat intelligence indicates active campaigns using these techniques"
-
"During incident response to scope compromise related to these techniques"
-
When proactively hunting for indicators of hunting for shadow copy deletion in the environment
-
After threat intelligence indicates active campaigns using these techniques
-
During incident response to scope compromise related to these techniques
-
When EDR or SIEM alerts trigger on related indicators
-
During periodic security assessments and purple team exercises
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) k, v IOC_PATTERNS.items()}