Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Shadow Copy and Backup Deletion Pre-Encryption

Zawoo Shadow Copy Deletion Sentinel
MITRE ATT&CK
Inhibit System Recovery
Data Source
DeviceProcessEvents
Date Added
2026-09-18
Last Updated
2026-09-18
Source
SOCRadar (socradar.io/free-tools/ransomware-intelligence/groups/zawoo), WatchGuard ransomware tracker
What This Detects
ZaWoo traces to the Babuk lineage; Babuk-derived operators routinely delete shadow copies/backups before encryption.
Query
DeviceProcessEvents
| where FileName in~ ("vssadmin.exe","wbadmin.exe","bcdedit.exe","wmic.exe")
| where ProcessCommandLine has_any ("delete shadows","delete catalog","recoveryenabled no","shadowcopy delete","resize shadowstorage")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.