1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1490 Inhibit System Recovery — Detection Rules

Detection workspace for T1490 Inhibit System Recovery: 23 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1490 Inhibit System Recovery

MATCH(backup_deleted OR snapshot_deleted OR recovery_setting_disabled OR known_recovery_disable_command) -> ALERT

Anomaly models

ATT&CK analytic guidance

DET0329 Behavioral Detection for T1490 - Inhibit System Recovery

AN0933 Analytic 0933

Process chains that use native utilities (vssadmin, wbadmin, diskshadow, bcdedit, REAgentC, wmic) with arguments to delete shadow copies, disable recovery, or remove backup catalogs

AN0934 Analytic 0934

Shell utilities or scripts deleting `/etc/systemd/system/rescue.target`, `/etc/fstab` backups, or `/boot/efi` partitions; chattr used to block snapshot auto-recovery

AN0935 Analytic 0935

ESXi shell or vim-cmd execution that deletes all VM snapshots using vmsvc/snapshot.removeall or rm on snapshot paths

AN0936 Analytic 0936

Execution of `erase`, `format`, and `reload` in immediate sequence from a privileged AAA session

AN0937 Analytic 0937

Cloud API calls disabling snapshot scheduling, backup policies, versioning, followed by DeleteSnapshot/DeleteVolume operations

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1490 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.