Is this host protected from LockBit?

/static/assets/windows-logo.svg
LockBit 2.0 is an affiliate-based Ransomware-as-a-Service (RaaS) that was first observed in June 2021. This chain simulates post-exploitation activity of LockBit, including deleting Volume Shadow Copies, performing a UAC bypass, creating a named pipe, and writing a ransom note to the user's desktop. Endpoint detection should identify LockBit 2.0 ransomware activity and respond before it can cause damage. This chain must be run as Administrator.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
Is this host protected from LockBit?

2022-12-06

/static/assets/windows-logo.svg
Is this host protected from LockBit?