Deletion of Volume Shadow Copies via WMI with PowerShell

 Original Source: [Sigma source]
Title: Deletion of Volume Shadow Copies via WMI with PowerShell
Status: test
Description:Detects deletion of Windows Volume Shadow Copies with PowerShell code and Get-WMIObject. This technique is used by numerous ransomware families such as Sodinokibi/REvil
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1490/T1490.md#atomic-test-5---windows---delete-volume-shadow-copies-via-wmi-with-powershell
  -https://www.elastic.co/guide/en/security/current/volume-shadow-copy-deletion-via-powershell.html
Author: Tim Rauch, Elastic (idea)
Date: 2022-09-20
modified:2022-12-30
Tags:
  • -'attack.impact'
  • -'attack.t1490'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_get:
    CommandLine|contains:
      -'Get-WmiObject'
      -'gwmi'
      -'Get-CimInstance'
      -'gcim'

  selection_shadowcopy:
    CommandLine|contains: 'Win32_ShadowCopy'
  selection_delete:
    CommandLine|contains:
      -'.Delete()'
      -'Remove-WmiObject'
      -'rwmi'
      -'Remove-CimInstance'
      -'rcim'

  condition:all of selection*
Falsepositives:
  -Unknown
Level: high