← Back to SOC feed Coverage →

wadhrama-data-destruction

kql MEDIUM Azure-Sentinel
DeviceProcessEvents
backdoorcredential-thefthuntingmicrosoftofficialransomwarewmi
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Azure-Sentinel →
Retrieved: 2026-05-23T11:00:00Z · Confidence: medium

Hunt Hypothesis

The hypothesis is that the detection rule identifies potential data destruction activity associated with the Wadhrama ransomware, which adversaries may use to exfiltrate data or disrupt operations. SOC teams should proactively hunt for this behavior in Azure Sentinel to identify and mitigate ransomware attacks before significant data loss occurs.

KQL Query

// Find use of WMIC to delete backups before ransomware execution
DeviceProcessEvents
| where Timestamp > ago(7d)
| where FileName =~ "wmic.exe"
| where ProcessCommandLine has "shadowcopy" and ProcessCommandLine has "delete"
| project DeviceId, Timestamp, InitiatingProcessFileName, FileName,
ProcessCommandLine, InitiatingProcessIntegrityLevel, InitiatingProcessParentFileName

Analytic Rule Definition

id: 08502f9f-7a04-4608-b5ad-5cfa129c073b
name: wadhrama-data-destruction
description: |
  This query was originally published in the threat analytics report, RDP ransomware persists as Wadhrama.
  The ransomware known as Wadhrama has been used in human-operated attacks that follow a particular pattern. The attackers often use Remote Desktop Protocol (RDP) to gain initial access to a device or network, exfiltrate credentials, and maintain persistance.
  The following query checks for possible Wadhrama-related activity, by detecting any use of Windows Management Instrumentation command-line utility, or WMIC, to delete local backups. The attackers often delete all local backups on an infected device before actually running the ransomware.
  Other techniques used by the group associated with Wadhrama are listed under See also.
  Reference - https://www.microsoft.com/wdsi/threats/malware-encyclopedia-description?Name=Ransom:Win32/Wadhrama
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - DeviceProcessEvents
tactics:
- Impact
query: |
  // Find use of WMIC to delete backups before ransomware execution
  DeviceProcessEvents
  | where Timestamp > ago(7d)
  | where FileName =~ "wmic.exe"
  | where ProcessCommandLine has "shadowcopy" and ProcessCommandLine has "delete"
  | project DeviceId, Timestamp, InitiatingProcessFileName, FileName,
  ProcessCommandLine, InitiatingProcessIntegrityLevel, InitiatingProcessParentFileName

Required Data Sources

Sentinel TableNotes
DeviceProcessEventsEnsure this data connector is enabled

MITRE ATT&CK Context

References

False Positive Guidance

Original source: https://github.com/Azure/Azure-Sentinel/blob/main/Hunting Queries/Microsoft 365 Defender/Impact/wadhrama-data-destruction.yaml