Elastic high stable eql
Volume Shadow Copy Deleted or Resized via VssAdmin
Identifies use of vssadmin.exe for shadow copy deletion or resizing on endpoints. This commonly occurs in tandem with ransomware or other destructive attacks.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
(process.name : "vssadmin.exe" or ?process.pe.original_file_name == "VSSADMIN.EXE") and
process.args : ("delete", "resize") and process.args : "shadows*" Field Validations
Loading…
Comments (0)
Loading comments...