hunting-for-shadow-copy-deletion
Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands. Use when hunting for ransomware preparation or anti-forensics activity, after threat intel flags active campaigns, or when alerts trigger on shadow-copy deletion commands.
来源信息
- 仓库
- mukul975/Anthropic-Cybersecurity-Skills
- 最近来源活动
- 2026年8月2日 16:32
- 检测到的 SKILL.md 语言
- 英语
- 星标
- 27,732
- 分支
- 3,366
安装方式
默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。
检查来源文件
决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。