T1490 Inhibit System Recovery — ATT&CK Technique
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options. Operating systems may contain features that can help fix corrupted systems, such as a backup catalog, volume shadow copies, and automatic repair features. Adversaries may disable or delete system recovery features to augment the effects of Data Destruction and Data Encrypted for Impact. Furthermore, adversaries may disable recovery notifications, then corrupt backups. A number of native Windows utilities have been used by adversaries to disable or delete system recovery features: * vssadmin.exe can be used to delete all volume shadow copies on a system - vssadmin.exe delete shadows /all /quiet * Windows Management Instrumentation can be used to delete volume shadow copies - wmic shadowcopy delete * wbadmin.exe can be used to delete the Windows Backup Catalog - wbadmin.exe delete catalog -quiet * bcdedit.exe can be used to disable automatic Windows recovery features by modifying boot configuration data - bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no * REAgentC.exe can be used to disable Windows Recovery Environment (WinRE) repair/recovery options of an infected system * diskshadow.exe can be used to delete all volume shadow copies on a system - diskshadow delete shadows all On network devices, adversaries may leverage Disk Wipe to delete backup firmware images and reformat the file system, then System Shutdown/Reboot to reload the device. Together this activity may leave network devices completely inoperable and inhibit recovery operations. On ESXi servers, adversaries may delete or encrypt snapshots of virtual machines to support Data Encrypted for Impact, preventing them from being leveraged as backups (e.g., via ` vim-cmd vmsvc/snapshot.removeall`). Adversaries may also delete “online” backups that are connected to their network – whether via network storage media or through folders that sync to cloud services. In cloud environments, adversaries may disable versioning and backup policies and delete snapshots, database backups, machine images, and prior versions of objects designed to be used in disaster recovery scenarios.
Detection coverage (44)
- WannaCry Ransomware Activity critical
- Potential Dtrack RAT Activity critical
- Potential Maze Ransomware Activity critical
- Amsi.DLL Load By Uncommon Process low
- AWS S3 Bucket Versioning Disable medium
- Time Machine Backup Disabled Via Tmutil - MacOS medium
- Deletion of Volume Shadow Copies via WMI with PowerShell high
- Time Machine Backup Deletion Attempt Via Tmutil - MacOS medium
- New File Exclusion Added To Time Machine Via Tmutil - MacOS medium
- Cisco Modify Configuration medium
- Windows Recovery Environment Disabled Via Reagentc medium
- System Restore Registry Modification via CommandLine high
- Suspicious Volume Shadow Copy Vssapi.dll Load high
- Backup Files Deleted medium
- Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load medium
- Suspicious Volume Shadow Copy VSS_PS.dll Load high
- Delete Volume Shadow Copies Via WMI With PowerShell high
- Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script high
- Boot Configuration Tampering Via Bcdedit.EXE high
- Copy From VolumeShadowCopy Via Cmd.EXE high
- Sensitive File Access Via Volume Shadow Copy Backup high
- Shadow Copies Deletion Using Operating Systems Utilities high
- Registry Disable System Restore high
- Windows Backup Deleted Via Wbadmin.EXE medium
- File Recovery From Backup Via Wbadmin.EXE medium
- All Backups Deleted Via Wbadmin.EXE high
- New Root or CA or AuthRoot Certificate to Store medium
- ASL AWS Disable Bucket Versioning
- AWS Disable Bucket Versioning
- Change To Safe Mode With Network Config
- Bcdedit Command Back To Normal Mode Boot
- BCDEdit Failure Recovery Modification
- Delete ShadowCopy With PowerShell
- Deleting Shadow Copies
- Disabling SystemRestore In Registry
- Prevent Automatic Repair Mode using Bcdedit
- Resize ShadowStorage volume
- WBAdmin Delete System Backups
- Windows BitLocker Suspicious Command Usage
- Windows Cisco Secure Endpoint Related Service Stopped
- Windows Security And Backup Services Stop
- Windows Suspicious File in EFI Volume
- Windows WBAdmin File Recovery From Backup
- Windows WMIC Shadowcopy Delete
Malware using this technique
- Black Basta
- Ragnar Locker
- InvisiMole
- Playcrypt
- WastedLocker
- H1N1
- RobbinHood
- Ryuk
- DarkWatchman
- Avaddon
- Medusa Ransomware
- EKANS
- INC Ransomware
- MegaCortex
- DEATHRANSOM
- Royal
- BlackByte 2.0 Ransomware
- Prestige
- DarkGate
- HermeticWiper
- WannaCry
- Embargo
- Babuk
- BitPaymer
- BlackByte Ransomware
- HELLOKITTY
- Netwalker
- RansomHub
- FIVEHANDS
- Conti
- Meteor
- Akira
- Clop
- MultiLayer Wiper
- Qilin
- Pysa
- Conficker
- Olympic Destroyer
- REvil
- Maze
- Diavol
- LockBit 3.0
- JCry
- BFG Agonizer
- ROADSWEEP
- ProLock
- BlackCat
- LockBit 2.0