Skip to content

Instantly share code, notes, and snippets.

@MHaggis
Last active May 15, 2017 22:13
Show Gist options
  • Save MHaggis/e479843a41a6390e3984558acab65e99 to your computer and use it in GitHub Desktop.
Save MHaggis/e479843a41a6390e3984558acab65e99 to your computer and use it in GitHub Desktop.
{
"wmic": {
"process_name": ["wmic.exe"],
"cmdline": ["wmic shadowcopy delete"]
},
"Vssadmin": {
"process_name": ["vssadmin.exe"],
"cmdline": ["vssadmin delete shadows /all /quiet"]
},
"bcdedit": {
"process_name": ["bcdedit.exe"],
"cmdline": ["bcdedit /set {default} bootstatuspolicy ignoreallfailures",
"bcdedit /set {default} recoveryenabled no"]
},
"wbadmin": {
"process_name": ["wbadmin.exe"],
"cmdline": ["wbadmin delete catalog -quiet"]
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment