Open tidalwaave opened 11 months ago
((EventCode="4688" OR EventCode="1")
(CommandLine="*vssadmin* *delete* *shadows*"
OR CommandLine="*wmic* *shadowcopy* *delete*"
OR CommandLine="*vssadmin* *resize* *shadowstorage*"))
OR (EventCode="5857" ProviderName="MSVSS__PROVIDER")
OR (EventCode="5858" Operation="*Win32_ShadowCopy*")
index=* ((EventCode="4688" OR EventCode="1")
(CommandLine="*vssadmin* *delete* *shadows*"
OR CommandLine="*wmic* *shadowcopy* *delete*"
OR CommandLine="*vssadmin* *resize* *shadowstorage*"))
OR (EventCode="5857" ProviderName="MSVSS__PROVIDER")
OR (EventCode="5858" Operation="*Win32_ShadowCopy*")
index=* ((EventCode="4688" OR EventCode="1")
(CommandLine="*vssadmin* *delete* *shadows*"
OR CommandLine="*wmic* *shadowcopy* *delete*"
OR CommandLine="*vssadmin* *resize* *shadowstorage*"))
Manual Volume Shadow Copy Deletion
Splunk Query
Alert Priority :
HIGH