Detections
- Home
- - Detections
- -DT105
- ID: DT105
- Created: 13th December 2024
- Updated: 13th December 2024
- Platform: Windows
- Contributor: The ITM Team
vssadmin Shadow Copy Deletion
To identify events where shadow copies are being deleted on a Windows system, command-line arguments should be monitored for the string “vssadmin delete shadows,” which represents the initial syntax of a command to delete shadows with the vssadmin utility.