Inhibit System Recovery T1490

Tactic: Impact

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.

Events covered

19 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 115 rules share fields, values, and exclusions.

Fields filtered most (83 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine40contains 39, wildcard 4, ends_with 1, in 1, regex_match 1, starts_with 1delete, bootstatuspolicy, catalog, *delete*, backup
Image25ends_with 19, contains 5, starts_with 5, eq 4, is_null 4, is_not_null 1\wbadmin.exe, /tmutil, \powershell.exe, \pwsh.exe, \avira_system_speedup.tmp
EventType24eq 22, in 4start, rename, microsoft.compute/restorepointcollections/delete, DeleteDBClusterSnapshot, DeleteDBSnapshot
OriginalFileName22eq 22wbadmin.exe, bcdedit.exe, vssadmin.exe, powershell.exe, pwsh.dll
process_name19eq 18, wildcard 1bcdedit.exe, vssadmin.exe, wbadmin.exe, wmic.exe, cmd.exe
operationName14eq 14microsoft.storage/storageaccounts/blobservices/write, deleteblob, microsoft.authorization/locks/delete, microsoft.compute/disks/delete, microsoft.compute/restorepointcollections/delete
resultType13in 13Succeeded, Success
data_stream.dataset11eq 11aws.cloudtrail, azure.activitylogs
event.outcome10eq 10success
host.os.type9eq 9
file.extension8is_not_null 6, eq 1, wildcard 1bkf, hta, htm*, readme, vbk
TargetFilename7starts_with 3, ends_with 2, wildcard 2, contains 1c:\users\, .bac, .bak, .bkf, .dat
event.type7eq 6, in 1start, deletion, change
process.args7eq 6, contains 1, starts_with 1, wildcard 1delete, *backup*, .delete(), /set, DellDRLogSvc
file.Ext.entropy6ge 67, 6

Top indicator values (540 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLinecontains
delete
1731
CommandLinecontains
bootstatuspolicy
910
CommandLinecontains
catalog
912
CommandLinecontains
recoveryenabled
910
CommandLinecontains
resize
89
CommandLinecontains
shadowcopy
813
CommandLinecontains
shadows
811
CommandLinecontains
systemstatebackup
78
OriginalFileNameeq
wbadmin.exe
1419
OriginalFileNameeq
bcdedit.exe
1013
OriginalFileNameeq
vssadmin.exe
912
OriginalFileNameeq
wmic.exe
880
resultTypein
Succeeded
1351
resultTypein
Success
1351
EventTypeeq
start
10391
EventTypeeq
rename
722
event.outcomeeq
success
10369
data_stream.dataseteq
aws.cloudtrail
6169
file.Ext.original.nameends_with
.bmp
66
file.Ext.original.nameends_with
.doc
66
file.Ext.original.nameends_with
.docx
66
file.Ext.original.nameends_with
.jpg
66
file.Ext.original.nameends_with
.pdf
66
file.Ext.original.nameends_with
.png
66
file.Ext.original.nameends_with
.ppt
66
file.Ext.original.nameends_with
.pptx
66
file.Ext.original.nameends_with
.xls
66
file.Ext.original.nameends_with
.xlsx
66
process_nameeq
bcdedit.exe
69
Imageends_with
\wbadmin.exe
57

Exclusions (178 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
file.extensioneq
lnk
5
file.extensioneq
bak
4
file.extensioneq
bck
4
file.extensioneq
bmp
4
file.extensioneq
diff
4
file.extensioneq
doc
4
file.extensioneq
docx
4
file.extensioneq
download
4
file.extensioneq
gz
4
file.extensioneq
jpg
4
file.extensioneq
part
4
file.extensioneq
pdf
4
file.extensioneq
png
4
file.extensioneq
ppt
4
file.extensioneq
pptx
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 32 rules

Elastic 37 rules

Splunk 17 rules

Kusto 10 rules

YARA-L 1 rule

Panther 18 rules