ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™

  • ID: DT105
  • Created: 13th December 2024
  • Updated: 13th December 2024
  • Platform: Windows
  • Contributor: The ITM Team

vssadmin Shadow Copy Deletion

To identify events where shadow copies are being deleted on a Windows system, command-line arguments should be monitored for the string “vssadmin delete shadows,” which represents the initial syntax of a command to delete shadows with the vssadmin utility.