Technique.View on attack.mitre.org
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Operating systems may contain features that can help fix corrupted systems, such as a backup catalog, volume shadow copies, and automatic repair features. Adversaries may disable or delete system recovery features to augment the effects of Data Destruction and Data Encrypted for Impact. Furthermore, adversaries may disable recovery notifications, then corrupt backups.
A number of native Windows utilities have been used by adversaries to disable or delete system recovery features:
* vssadmin.exe can be used to delete all volume shadow copies on a system - vssadmin.exe delete shadows /all /quiet
* Windows Management Instrumentation can be used to delete volume shadow copies - wmic shadowcopy delete
* wbadmin.exe can be used to delete the Windows Backup Catalog - wbadmin.exe delete catalog -quiet
* bcdedit.exe can be used to disable automatic Windows recovery features by modifying boot configuration data - bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no
* REAgentC.exe can be used to disable Windows Recovery Environment (WinRE) repair/recovery options of an infected system
* diskshadow.exe can be used to delete all volume shadow copies on a system - diskshadow delete shadows all
On network devices, adversaries may leverage Disk Wipe to delete backup firmware images and reformat the file system, then System Shutdown/Reboot to reload the device. Together this activity may leave network devices completely inoperable and inhibit recovery operations.
On ESXi servers, adversaries may delete or encrypt snapshots of virtual machines to support Data Encrypted for Impact, preventing them from being leveraged as backups (e.g., via ` vim-cmd vmsvc/snapshot.removeall`).
Adversaries may also delete “online” backups that are connected to their network – whether via network storage media or through folders that sync to cloud services. In cloud environments, adversaries may disable versioning and backup policies and delete snapshots, database backups, machine images, and prior versions of objects designed to be used in disaster recovery scenarios.
Rules on DetectionCode tagged with T1490.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ASL AWS Disable Bucket Versioning | Anomaly | NULL | ASL AWS CloudTrail |
| AWS Disable Bucket Versioning | Anomaly | NULL | AWS CloudTrail PutBucketVersioning |
| Bcdedit Command Back To Normal Mode Boot | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| BCDEdit Failure Recovery Modification | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Change To Safe Mode With Network Config | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Delete ShadowCopy With PowerShell | TTP | NULL | Powershell Script Block Logging 4104 |
| Deleting Shadow Copies | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Disabling SystemRestore In Registry | TTP | NULL | Sysmon EventID 13 |
| Known Services Killed by Ransomware | TTP | NULL | Windows Event Log System 7036 |
| Prevent Automatic Repair Mode using Bcdedit | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Resize ShadowStorage volume | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| WBAdmin Delete System Backups | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows BitLocker Suspicious Command Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Cisco Secure Endpoint Related Service Stopped | Anomaly | NULL | Windows Event Log System 7036 |
| Windows Security And Backup Services Stop | TTP | NULL | Windows Event Log System 7036 |
| Windows Suspicious File in EFI Volume | TTP | NULL | Sysmon EventID 11 |
| Windows WBAdmin File Recovery From Backup | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows WMIC Shadowcopy Delete | Anomaly | NULL | Sysmon EventID 1 |
| Used by | Procedure example |
|---|---|
| GroupBlackByte | BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption. |
| GroupMedusa Group | Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| GroupSandworm Team | Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`. |
| GroupScattered Spider | Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts. |
| GroupStorm-0501 | Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`, |
| GroupVOID MANTICORE | VOID MANTICORE has deleted virtual machines directly from the virtualization platform. |
| GroupWizard Spider | Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin. |
| Used by | Procedure example |
|---|---|
| MalwareAkira | Akira will delete system volume shadow copies via PowerShell commands. |
| MalwareAvaddon | Avaddon deletes backups and shadow copies using native system tools. |
| MalwareBabuk | Babuk has the ability to delete shadow volumes using |
| MalwareBFG Agonizer | BFG Agonizer wipes the boot sector of infected machines to inhibit system recovery. |
| MalwareBitPaymer | BitPaymer attempts to remove the backup shadow files from the host using |
| MalwareBlack Basta | Black Basta can delete shadow copies using vssadmin.exe. Avertium Black Basta June 2022Check Point Black Basta October 2022Cyble Black Basta May 2022Deep Instinct Black Basta August 2022Minerva Labs Black Basta May 2022NCC Group Black Basta June 2022Palo Alto Networks Black Basta August 2022Trend Micro Black Basta May 2022Trend Micro Black Basta Spotlight September 2022 |
| MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies volume shadow copies during execution in a way that destroys them on the victim machine. |
| MalwareBlackByte Ransomware | BlackByte Ransomware deletes all volume shadow copies and restore points among other actions to inhibit system recovery following ransomware deployment. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries deleted Windows Volume Shadow Copies using `vssadmin delete shadows`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.