Open cardosec

Case 26BF2E · Blue team / DFIR · L4 Advanced

Shadow Copies Vanishing

Practise as: Incident drill · Interview

Live alertAt 03:05 on a Saturday, three servers run vssadmin delete shadows /all /quiet within 90 seconds, and a new GPO pushes a scheduled task to all domain hosts.

Interview questionIt is 3am on Saturday and shadow copies are being deleted across servers. What do you do in the first hour?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Shadow copy deletion (T1490) plus GPO deployment is imminent ransomware; act immediately, don't wait for encryption.
  2. Contain hard: isolate affected hosts, disable the account that edited the GPO, and cut egress at the firewall.
  3. Unlink or delete the malicious GPO and scheduled task; consider blocking SMB between workstations.
  4. Protect backups: verify offline/immutable copies are untouched and disconnect backup servers from the domain.
  5. Invoke IR plan: incident commander, legal, cyber insurer, out-of-band comms; check for data exfiltration.

If the interviewer pushes back

  • The attacker had domain admin for two weeks. How do you rebuild trust in the Active Directory forest?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.