Inhibit System Recovery

T1490

Technique.View on attack.mitre.org

About this technique

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.

Operating systems may contain features that can help fix corrupted systems, such as a backup catalog, volume shadow copies, and automatic repair features. Adversaries may disable or delete system recovery features to augment the effects of Data Destruction and Data Encrypted for Impact. Furthermore, adversaries may disable recovery notifications, then corrupt backups.

A number of native Windows utilities have been used by adversaries to disable or delete system recovery features:

* vssadmin.exe can be used to delete all volume shadow copies on a system - vssadmin.exe delete shadows /all /quiet
* Windows Management Instrumentation can be used to delete volume shadow copies - wmic shadowcopy delete
* wbadmin.exe can be used to delete the Windows Backup Catalog - wbadmin.exe delete catalog -quiet
* bcdedit.exe can be used to disable automatic Windows recovery features by modifying boot configuration data - bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no
* REAgentC.exe can be used to disable Windows Recovery Environment (WinRE) repair/recovery options of an infected system
* diskshadow.exe can be used to delete all volume shadow copies on a system - diskshadow delete shadows all

On network devices, adversaries may leverage Disk Wipe to delete backup firmware images and reformat the file system, then System Shutdown/Reboot to reload the device. Together this activity may leave network devices completely inoperable and inhibit recovery operations.

On ESXi servers, adversaries may delete or encrypt snapshots of virtual machines to support Data Encrypted for Impact, preventing them from being leveraged as backups (e.g., via ` vim-cmd vmsvc/snapshot.removeall`).

Adversaries may also delete “online” backups that are connected to their network – whether via network storage media or through folders that sync to cloud services. In cloud environments, adversaries may disable versioning and backup policies and delete snapshots, database backups, machine images, and prior versions of objects designed to be used in disaster recovery scenarios.

Detection rules42

Rules on DetectionCode tagged with T1490.

Sigma24

RuleLevelLog source
All Backups Deleted Via Wbadmin.EXEhighwindows / process_creation
Boot Configuration Tampering Via Bcdedit.EXEhighwindows / process_creation
Copy From VolumeShadowCopy Via Cmd.EXEhighwindows / process_creation
Delete Volume Shadow Copies Via WMI With PowerShellhighwindows / ps_classic_start
Delete Volume Shadow Copies via WMI with PowerShell - PS Scripthighwindows / ps_script
Deletion of Volume Shadow Copies via WMI with PowerShellhighwindows / process_creation
Deletion of Volume Shadow Copies via WMI with PowerShell - PS Scripthighwindows / ps_script
Registry Disable System Restorehighwindows / registry_set
Sensitive File Access Via Volume Shadow Copy Backuphighwindows / process_creation
Shadow Copies Deletion Using Operating Systems Utilitieshighwindows / process_creation
Suspicious Volume Shadow Copy VSS_PS.dll Loadhighwindows / image_load
Suspicious Volume Shadow Copy Vssapi.dll Loadhighwindows / image_load
System Restore Registry Modification via CommandLinehighwindows / process_creation
AWS S3 Bucket Versioning Disablemediumaws / NULL
Backup Files Deletedmediumwindows / file_delete

Splunk18

RuleTypeRiskData source
ASL AWS Disable Bucket VersioningAnomalyNULLASL AWS CloudTrail
AWS Disable Bucket VersioningAnomalyNULLAWS CloudTrail PutBucketVersioning
Bcdedit Command Back To Normal Mode BootTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
BCDEdit Failure Recovery ModificationTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Change To Safe Mode With Network ConfigTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Delete ShadowCopy With PowerShellTTPNULLPowershell Script Block Logging 4104
Deleting Shadow CopiesTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Disabling SystemRestore In RegistryTTPNULLSysmon EventID 13
Known Services Killed by RansomwareTTPNULLWindows Event Log System 7036
Prevent Automatic Repair Mode using BcdeditTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Resize ShadowStorage volumeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
WBAdmin Delete System BackupsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows BitLocker Suspicious Command UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Cisco Secure Endpoint Related Service StoppedAnomalyNULLWindows Event Log System 7036
Windows Security And Backup Services StopTTPNULLWindows Event Log System 7036

Groups7

Software48

Show 24 more

Campaigns1

Procedure examples56

Groups7

Used byProcedure example
GroupBlackByte

BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption.

GroupMedusa Group

Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.

GroupSandworm Team

Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`.

GroupScattered Spider

Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts.

GroupStorm-0501

Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`,
`Microsoft.Compute/restorePointCollections/delete`,
`Microsoft.Storage/storageAccounts/delete`, and
`Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete`.

GroupVOID MANTICORE

VOID MANTICORE has deleted virtual machines directly from the virtualization platform.

GroupWizard Spider

Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin.

Software48

Used byProcedure example
MalwareAkira

Akira will delete system volume shadow copies via PowerShell commands.

MalwareAvaddon

Avaddon deletes backups and shadow copies using native system tools.

MalwareBabuk

Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet.

MalwareBFG Agonizer

BFG Agonizer wipes the boot sector of infected machines to inhibit system recovery.

MalwareBitPaymer

BitPaymer attempts to remove the backup shadow files from the host using vssadmin.exe Delete Shadows /All /Quiet.

MalwareBlack Basta

Black Basta can delete shadow copies using vssadmin.exe.

MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies volume shadow copies during execution in a way that destroys them on the victim machine.

MalwareBlackByte Ransomware

BlackByte Ransomware deletes all volume shadow copies and restore points among other actions to inhibit system recovery following ransomware deployment.

View all 48 software examples

Campaigns1

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries deleted Windows Volume Shadow Copies using `vssadmin delete shadows`.

References9

  1. Crytox Ransomware Open source
    Romain Dumont . (2022, September 21). Technical Analysis of Crytox Ransomware. Retrieved November 22, 2023.
  2. Cybereason Open source
    Cybereason Nocturnus. (n.d.). Cybereason vs. BlackCat Ransomware. Retrieved March 26, 2025.
  3. Dark Reading Code Spaces Cyber Attack Open source
    Brian Prince. (2014, June 20). Code Hosting Service Shuts Down After Cyber Attack. Retrieved March 21, 2023.
  4. Diskshadow Open source
    Microsoft Windows Server. (2023, February 3). Diskshadow. Retrieved November 21, 2023.
  5. FireEye WannaCry 2017 Open source
    Berry, A., Homan, J., and Eitzman, R. (2017, May 23). WannaCry Malware Profile. Retrieved March 15, 2019.
  6. Rhino Security Labs AWS S3 Ransomware Open source
    Spencer Gietzen. (n.d.). AWS Simple Storage Service S3 Ransomware Part 2: Prevention and Defense. Retrieved March 21, 2023.
  7. Talos Olympic Destroyer 2018 Open source
    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.
  8. ZDNet Ransomware Backups 2020 Open source
    Steve Ranger. (2020, February 27). Ransomware victims thought their backups were safe. They were wrong. Retrieved March 21, 2023.
  9. disable_notif_synology_ransom Open source
    TheDFIRReport. (2022, March 1). Disabling notifications on Synology servers before ransom. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.