• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Play Ransomware VSS Inhibition Chain, Hash IOC, and Grixba Public\Music Staging

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated Jun 28, 2026•0•0•3

    This rule detects potential ransomware activity by monitoring for the deliberate inhibition of Windows system recovery features (via vssadmin, wmic, or bcdedit) and the subsequent staging of archived data in public user directories.

    SentinelOne

    Tags

    T1490 - Inhibit System RecoveryT1047 - Windows Management InstrumentationT1059 - Command and Scripting InterpreterTA0040 - ImpactTA0002 - ExecutionProcess CreationFile CreationCommand ExecutionWindowsWindows SysmonWindows Eventlog Security

    Found in

    • Evolution Analysis of Grixba Infostealer ToolLast updated Jun 8, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?