Delete Volume Shadow Copies via WMI with PowerShell - PS Script

 Original Source: [Sigma source]
Title: Delete Volume Shadow Copies via WMI with PowerShell - PS Script
Status: test
Description:Deletes Windows Volume Shadow Copies with PowerShell code and Get-WMIObject. This technique is used by numerous ransomware families such as Sodinokibi/REvil
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1490/T1490.md#atomic-test-5---windows---delete-volume-shadow-copies-via-wmi-with-powershell
Author: frack113
Date: 2021-12-26
modified:2022-12-02
Tags:
  • -'attack.impact'
  • -'attack.t1490'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains|all:
      -'Get-WmiObject'
      -'Win32_ShadowCopy'
      -'.Delete()'

  condition:selection
Falsepositives:
  -Unknown
Level: high