Elastic high stable eql
Volume Shadow Copy Deletion via WMIC
Identifies use of wmic.exe for shadow copy deletion on endpoints. This commonly occurs in tandem with ransomware or other destructive attacks.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
(process.name : "WMIC.exe" or ?process.pe.original_file_name == "wmic.exe") and
process.args : "delete" and process.args : "shadowcopy" Field Validations
Loading…
Comments (0)
Loading comments...