Vssadmin.exe

type: OSBinaries
Volume Shadow Copy Service administrative command-line tool

Full path

C:\Windows\System32\vssadmin.exe

Commands

  1. TamperAdministrator T1490

    Destroy shadow copies to prevent file and system recovery, a technique commonly used by ransomware

    vssadmin delete shadows /all /quiet

    Delete all volume shadow copies on the host without prompting

    os: Windows 11, Windows 10, Windows Server

Detection

Resources