Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / THREAT HUNT / WINDOWS / DOMINATION

Ransomware

This note documents detection patterns and forensic indicators related to ransomware-style impact.

Direct Indicators

LogEvent IDMeaningForensic ValueNotes
Security4663File modificationHighMass file access
Security4688vssadmin delete shadowsCriticalRecovery prevention

Indirect Indicators

IndicatorWhat To Look ForForensic ValueNotes
Burst file writesRapid encryptionCriticalRansomware
Shadow deletionvssadmin usageCriticalRecovery blocked

Common Clearing Commands

MethodExample
vssadminvssadmin delete shadows /all

Hunting Filters (Object-Based)

Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4663}

MITRE ATT&CK References

  • T1486 – Data Encrypted for Impact

Decision Tree

  1. Was shadow copy removed?
  2. Are many files modified rapidly?
  3. Trace initial access.