Most Popular ShinyHunters 2026: ShinySp1d3r Ransomware Precursor - Mass Backup Deletion and Shadow Copy Removal
Detects the use of native Windows administration utilities (vssadmin, wbadmin, bcdedit, wmic) to delete volume shadow copies, backup catalogs, or disable system recovery configurations. The rule specifically monitors for patterns where these commands are executed across multiple hosts or in rapid succession by the same account, behavior frequently observed during the precursor stages of ransomware deployment, such as the ShinyHunters ShinySp1d3r campaign.
Microsoft Sentinel (KQL)

