Windows shadow copies deleted
Set up the sentinelone integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when vssadmin is used to delete shadow copies.
Strategy
Threat actors are known to use tools found natively in a victim’s environment to accomplish their objectives. Vssadmin.exe
, a native Windows utility, can be used to delete all shadow copies on a system.
Triage and response
- Identify the user or service account deleting shadow copies, and confirm if this is authorized or expected.
- If it’s not authorized, isolate the host from the network.
- Follow your organization’s internal processes for investigating and remediating compromised systems.