Case 26BF2E · Blue team / DFIR · L4 Advanced
Shadow Copies Vanishing
Practise as: Incident drill · Interview
Live alertAt 03:05 on a Saturday, three servers run vssadmin delete shadows /all /quiet within 90 seconds, and a new GPO pushes a scheduled task to all domain hosts.
Interview questionIt is 3am on Saturday and shadow copies are being deleted across servers. What do you do in the first hour?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Shadow copy deletion (T1490) plus GPO deployment is imminent ransomware; act immediately, don't wait for encryption.
- Contain hard: isolate affected hosts, disable the account that edited the GPO, and cut egress at the firewall.
- Unlink or delete the malicious GPO and scheduled task; consider blocking SMB between workstations.
- Protect backups: verify offline/immutable copies are untouched and disconnect backup servers from the domain.
- Invoke IR plan: incident commander, legal, cyber insurer, out-of-band comms; check for data exfiltration.
If the interviewer pushes back
- The attacker had domain admin for two weeks. How do you rebuild trust in the Active Directory forest?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.