BigHugger
sk Skill · mukul975

hunting-for-shadow-copy-deletion

Runs a hypothesis-driven threat hunt for Volume Shadow Copy deletion (T1490) by querying SIEM/EDR telemetry for vssadmin, wmic shadowcopy, and PowerShell shadow-copy-deletion commands. Use when hunting for ransomware preparation or anti-forensics activity, after threat intel flags active campaigns, or when alerts trigger on shadow-copy deletion commands.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonproactive-detectiont1490anti-forensicsshadow-copyransomwaremitre-attackthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python