WannaCry delete Volume Shadow Copies

WannaCry deletes the Volume Shadow Copies after encrypting files. This technique uses the commands found in WannaCry to achieve that effect.
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.


Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
APT38 WannaCry


Perform lateral movement using EternalBlue and DoublePulsar exploits.